Skip to content
All work
SHobby · 2026

stellar-dvn

Could one person build a LayerZero verifier for Stellar? I built one for fun to find out. It works end to end on testnet.

contracts/dvn/src/multisig.rs
pub fn verify_quorum(
env: &Env,
digest: &Hash<32>,
signatures: &Vec<BytesN<65>>,
signers: &Vec<BytesN<20>>,
threshold: u32,
) -> Result<(), DvnError> {
if threshold == 0 {
return Err(DvnError::InvalidThreshold);
}
if signatures.len() < threshold {
return Err(DvnError::QuorumNotMet);
}
// Bound the work an unauthenticated caller can induce.
if signatures.len() > signers.len() {
return Err(DvnError::TooManySignatures);
}

A cross-chain message on LayerZero is only as trustworthy as the verifiers who sign off on it. Apps on Stellar can pick several. I wanted to know whether one person could build one.

Turns out you can. It's a Soroban contract plus the off-chain service that feeds it, working end to end against LayerZero's real Stellar testnet contracts. It's a hobby project: unaudited and not on mainnet.

85
Tests across the contracts and the verifier
2 of 3
Signatures needed to verify a message
~7 XLM
Fee quoted for a real message sent from Stellar

What I built

  • Signing off on a message

    An app names this DVN as its required verifier. A 2-of-3 quorum signs, LayerZero's ULN302 marks the packet verifiable, the endpoint emits PacketVerified, and the app gets its message.

  • Knowing when to say no

    A repeat delivery is rejected. One signature against a 2-of-3 threshold is rejected on chain. More signatures than signers is refused before any expensive signature recovery runs.

  • One real message, sent

    A message left Stellar through LayerZero's endpoint with this DVN in the send stack, paying its fee through the real DvnFeeLib. The verifier then picked that packet up from Stellar RPC and attested it.