> For the complete documentation index, see [llms.txt](https://docs.theo.xyz/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.theo.xyz/security-and-transparency/bridge-security.md).

# Bridge security

How thUSD and sthUSD move across chains, and how to read the live configuration.

thUSD and sthUSD move between chains as LayerZero v2 OFTs. Every value on this page was read from chain on August 28, 2026, and the commands to reproduce it are below.

## Message verification

A cross-chain message is delivered only when both conditions hold, after 15 block confirmations:

* All 3 required DVNs attest.
* At least 1 of the 2 optional DVNs attests.

So a message needs at least 4 attestations from a set of 5 independent verifiers. There is no threshold path on the required set, which means a single required DVN going offline halts the lane rather than weakening the security. The optional set works the other way: its threshold is 1 of 2, so one optional DVN can go offline without stopping delivery.

That combination is a deliberate choice of safety over liveness on the required set, with a small amount of liveness bought back on the optional set.

## The verifier set

| Operator         | Address                                                                                                                 | Role                       |
| ---------------- | ----------------------------------------------------------------------------------------------------------------------- | -------------------------- |
| Deutsche Telekom | [`0x373a6e5c0c4e89e24819f00aa37ea370917aaff4`](https://etherscan.io/address/0x373a6e5c0c4e89e24819f00aa37ea370917aaff4) | Required                   |
| Horizen          | [`0x380275805876Ff19055EA900CDb2B46a94ecF20D`](https://etherscan.io/address/0x380275805876ff19055ea900cdb2b46a94ecf20d) | Required                   |
| Canary           | [`0xa4fE5A5B9A846458a70Cd0748228aED3bF65c2cd`](https://etherscan.io/address/0xa4fe5a5b9a846458a70cd0748228aed3bf65c2cd) | Required                   |
| P2P              | [`0x06559EE34D85a88317Bf0bFE307444116c631b67`](https://etherscan.io/address/0x06559ee34d85a88317bf0bfe307444116c631b67) | Optional, 1 of 2 threshold |
| Nethermind       | [`0xa59BA433ac34D2927232918Ef5B2eaAfcF130BA5`](https://etherscan.io/address/0xa59ba433ac34d2927232918ef5b2eaafcf130ba5) | Optional, 1 of 2 threshold |

Operator names come from [LayerZero's DVN metadata](https://metadata.layerzero-api.com/v1/metadata/dvns), so the address-to-operator mapping is verifiable against LayerZero rather than asserted by us.

None of the five is LayerZero Labs' own DVN. Every verifier in the set is an independent third party, which means no single organisation both operates the messaging protocol and sits in the verifier set.

The same configuration applies to both tokens on both lanes. thUSD and sthUSD, to Arbitrum and to Stable, all return identical DVN sets, thresholds, and confirmation counts.

## Reading the live configuration yourself

The configuration lives on the LayerZero EndpointV2 contract, not on anything we host. Confirm the send library first, then read the `UlnConfig`:

```bash
RPC=https://ethereum-rpc.publicnode.com
ENDPOINT=0x1a44076050125825900e736c501f859c50fE728c
OAPP=0x9AA9Aa0530a6AF70EE7BC47cF1240100f514b065   # thUSD adapter
EID=30110                                          # Arbitrum. Stable is 30396

# Which send library is in use for this lane
cast call $ENDPOINT 'getSendLibrary(address,uint32)(address)' \
  $OAPP $EID --rpc-url $RPC
# Returns: 0xbb2ea70c9e858123480642cf96acbcce1372dce1

# ULN config for that lane (configType 2)
cast abi-decode 'f()((uint64,uint8,uint8,uint8,address[],address[]))' \
  "$(cast call $ENDPOINT 'getConfig(address,address,uint32,uint32)(bytes)' \
      $OAPP 0xbB2Ea70C9E858123480642Cf96acbcCE1372dCe1 $EID 2 \
      --rpc-url $RPC)"
```

The decoded tuple is `(confirmations, requiredDVNCount, optionalDVNCount, optionalDVNThreshold, requiredDVNs[], optionalDVNs[])`. Expect `15, 3, 2, 1` followed by the two address arrays in the table above.

Substitute `OAPP=0xd1db209087516883ec705cfeb99e80bb6032d540` for sthUSD, and `EID=30396` for the Stable lane.

|                |                                                                                                                                      |
| -------------- | ------------------------------------------------------------------------------------------------------------------------------------ |
| EndpointV2     | [`0x1a44076050125825900e736c501f859c50fE728c`](https://etherscan.io/address/0x1a44076050125825900e736c501f859c50fE728c#readContract) |
| Send library   | `0xbB2Ea70C9E858123480642Cf96acbcCE1372dCe1`                                                                                         |
| thUSD adapter  | `0x9AA9Aa0530a6AF70EE7BC47cF1240100f514b065`                                                                                         |
| sthUSD adapter | `0xd1db209087516883ec705cfeb99e80bb6032d540`                                                                                         |
| Arbitrum eid   | `30110`                                                                                                                              |
| Stable eid     | `30396`                                                                                                                              |

## Rate limits

sthUSD transfers are capped onchain at 2 million sthUSD per hour per outbound lane, enforced on a rolling window. Raising a cap goes through a 48-hour delay. The thUSD adapter on Ethereum has no onchain rate limit.

The caps and current usage are readable from the sthUSD adapter at `0xd1db209087516883ec705cfeb99e80bb6032d540`.

## Who can change the configuration

DVN stack and peer configuration on the Ethereum adapters is owned by the timelock, so changes carry the 2-day delay. On Arbitrum and Stable, the chain-local timelock owns the OFTs with an 18-hour delay. See Privileged roles & access control for the ownership checks.
