Bridge Dependencies

Mints native bridge can mint the native token, unbacked supply dilutes every holderBridged token is locked at source chain, only a bridged copy exists on remote chainsTransport protocol token is not bridged, only the underlying asset is bridged (e.g. USDC)

AggLayer (LxLy)

Unified canonical bridge (Polygon CDK / AggLayer)
1 direct · 2 indirect

The AggLayer LxLy unified bridge (PolygonZkEVMBridgeV2) links Ethereum to AggLayer chains such as Katana. Assets are escrowed in the L1 bridge and a wrapped representation is minted on the destination. Katana additionally uses "Vault Bridge" tokens (e.g. vbUSDC) that deposit the escrowed asset into yield vaults, so a bridge exploit or a fault in that vault can strand or impair the remote backing — holders are exposed to both.

Finality Ethereum→Katana deposits arrive in ~3–7 min (canonical AggLayer bridge up to ~20 min). Katana→Ethereum withdrawals finalize in about an hour: Katana proves state with OP-Succinct SP1 validity proofs settled on L1 roughly hourly.Admin PolygonZkEVMBridgeV2 is an upgradeable proxy: its implementation is swappable by a ProxyAdmin (0x0f99…CC4a) owned by a 3-day TimelockController (0xEf14…A4EF), under the Polygon Protocol Council (13 members, 7/13 for standard changes). Because the bridge holds the escrowed L1 funds, a malicious or compromised upgrade could reach them — the timelock is the normal-path warning window, but the Council's emergency route (10/13) can bypass the delay.
Protocol
Token
TypeModelIntegrationDetails
Yearn yvUSDdirectTransportAggLayer LxLy + Vault Bridge USDC (vbUSDC)

Katana yvUSDC Compounder wraps USDC into vbUSDC 0x53E8…a765e and bridges to Katana

FlexindirectTransportCollateral is yvUSD

yvUSD has strategy that bridges funds to Katana. Protocol doesn't use bridges

Spectra FinanceindirectTransportvbUSDC MetaVault on Katana

A live MetaVault on Katana holds Vault Bridge USDC, the MetaVault share itself is not bridged, but its backing sits behind the AggLayer bridge

Chainlink CCIP

Cross-chain interoperability protocol
3 direct · 1 indirect

Chainlink's cross-chain interoperability protocol. Two layers: message verification is Chainlink-operated and not protocol-configurable (a committing DON plus an independent Risk Management Network that can halt a lane), comparable to Circle's CCTP attesters. Token movement runs through a token pool the protocol itself deploys and owns — burn/mint or lock/release — where the per-protocol risk lives: the owner sets per-lane rate limits, supported lanes, and who can change them. So the model column reflects the pool mechanism, and the real protocol knobs are rate limits and pool ownership rather than a verifier quorum.

Finality ~15–25 min: waits for source-chain finality, then a DON commit + execute.Admin Router and the Risk Management Network are Chainlink-governed; each token pool is owned by the protocol (see per-row owners).
Protocol
Token
TypeModelIntegrationDetails
Apyx apxUSDdirectBridgedChainlink CCIP (LockReleaseTokenPool; Base + BNB Chain)

TokenAdminRegistry maps apxUSD to pool 0x0e9c…5BB5 (LockReleaseTokenPool 1.6.1). Canonical apxUSD is escrowed on Ethereum; getRemoteToken maps the configured Base route to 0xd993…7228 and the BNB Chain route to 0x6b37…d4af

Pool and remote-token CCIP admin: 3-of-6 Safe 0xf986…3cE2.
Centrifuge JAAAdirectMints nativeChainlink CCIP (2-of-2 MultiAdapter)

MultiAdapter forwards a message only after matching delivery through both LayerZero V2 and Chainlink CCIP. Compromising either messaging path alone cannot forge a JAAA mint, although MultiAdapter/admin or Spoke vulnerabilities could bypass the quorum.

Mint authority: Spoke 0xEC35…25aB, governed by Centrifuge Root — 48h timelock 0x7Ed4…368f.
Maple (syrupUSDC)directBridgedChainlink CCIP (LockReleaseTokenPool)

LockReleaseTokenPool holds ~13% of supply on mainnet, backing bridged syrupUSDC on Base/Arbitrum/Solana

Pool owner: Maple governance contract 0x4483…9449.
Fluid (PST)indirectMints nativePST collateral (Chainlink CCIP BurnMintTokenPool)

Fluid accepts Huma PST as collateral. Ethereum PST 0x22ae…d4c7 is minted by CCIP pool 0xBE77…0D3d, whose only configured remote chain is Solana; a CCIP compromise could mint unbacked PST against Fluid positions

Circle CCTP

Native USDC burn-and-mint bridge
3 direct · 1 indirect

Circle's Cross-Chain Transfer Protocol moves native USDC by burning on the source chain and minting on the destination, gated by Circle's attestation service — a 2-of-2 signature quorum whose attesters are both Circle-operated and swappable by Circle. Canonical CCTP removes third-party lock-and-mint bridge risk, but the trust assumption reduces to Circle's availability and attestation finality.

Finality ~13–19 min standard (source hard finality); CCTP V2 Fast Transfer ~8–20 s.Admin Circle — MessageTransmitter owner 0xB43a…9F65 and attesterManager 0xc16b…95a.
Protocol
Token
TypeModelIntegrationDetails
Gauntlet gtUSDadirectTransportCCTP V2

Bridges USDC across Base/Arbitrum/Optimism to Morpho

Origin OUSDdirectTransportCCTP V2

Cross-chain strategies bridge ~42% of TVL to Base and HyperEVM

Yearn yvUSDdirectTransportCCTP V2

Bridges USDC to Arbitrum and Base; Katana uses AggLayer separately

FlexindirectTransportCollateral is yvUSD

yvUSD has strategy that bridges funds to Base. Protocol doesn't use bridges

LayerZero

Omnichain messaging (OFT / OApp)
8 direct · 3 indirect

Generic cross-chain messaging. Tokens bridge via the OFT / OFT-Adapter standard; security depends on the configured DVN (Decentralized Verifier Network) set and the token's mint/burn authority on each chain. The Route Security column shows the DVN quorum for the specific route named below the badge — how many independent verifiers must attest a message before it executes — where a 1-of-1 is a single point of failure (the configuration behind the April 2026 rsETH incident). LayerZero configuration is directional and can differ by route; a badge must not be read as protocol-wide coverage. Values are read onchain from the named route's receive-side ULN config, and the badge links to that receive-side OApp.

Finality Seconds to ~15 min — set per route by the DVN block-confirmations (see Route Security).Admin EndpointV2 is immutable; each OFT adapter is owned by the protocol (see per-row owners).
Protocol
Token
TypeModelDVNIntegrationDetails
Across ProtocoldirectTransport3-of-3Ethereum→Arbitrum (USDT0 reserve transport)LayerZero OFT (USDT0 route)

Across's deployed Arbitrum adapter maps Ethereum USDT to the USDT0 OFT messenger for HubPool→SpokePool rebalancing; the assessed V2 LP token is not itself bridged, and other assets use separate transports

Cap stcUSDdirectBridged3-of-3Ethereum→Katana (mint side)LayerZero OFT Adapter ("LayerZero vault")

Adapter 0x983a…4137 escrows ~26.1M stcUSD (~38% of the ~68.3M supply). Katana runs a native OFT at the same vanity address 0x8888…8888

Adapter owner: 24h Timelock 0xD823…29ab.
Centrifuge JAAAdirectMints native4-of-56 chains→Ethereum (native-mint side)LayerZero V2 (2-of-2 MultiAdapter)

Spoke 0xEC35…25aB holds mint authority on JAAA; MultiAdapter requires both LayerZero and CCIP, while the LayerZero leg requires Deutsche Telekom + Canary and 2-of-3 P2P/Nansen/Nethermind

Mint authority: Spoke 0xEC35…25aB, governed by Centrifuge Root — 48h timelock 0x7Ed4…368f.
InfiniFidirectBridged4-of-4Ethereum→Katana (siUSD mint side; iUSD verified separately with the same quorum)LayerZero OFT Adapters (siUSD + iUSD)

siUSD adapter 0x5f21…c3c0 escrows siUSD and iUSD adapter 0xdd1c…3005 escrows iUSD; both mint native OFTs on Katana. Neither adapter holds RECEIPT_TOKEN_MINTER, so they cannot mint native supply

Adapter owner: 4-of-8 Safe 0x8060…400c.
Midas mHYPERdirectMints native4-of-4Katana→Ethereum (native-mint side)LayerZero OFT Adapter (MidasLzMintBurnOFTAdapter)

Adapter holds M_HYPER_MINT_OPERATOR_ROLE (mint has no onchain backing check) and the burn role

Adapter owner: 1-of-3 Safe 0xB608…7E89.
Paxos USDGdirectMints native3-of-3Solana→Ethereum (inbound mint path)LayerZero V2 OFT (OFTWrapper)

OFTWrapper is Supply Controller SC3 with 45M USDG mint capacity (~521 USDG/sec refill) — the bridge can mint native USDG. Configured peers: Solana, X Layer, Ink, Arbitrum, and Robinhood Chain (added ~July 2026, now 9.5% of supply)

Adapter owner: Paxos Operations MPC wallet 0x3Af3…024B.
Re (reUSD)directMints native2-of-2Arbitrum→Ethereum (inbound)LayerZero OFT (ReMintBurnAdapter)

ReMintBurnAdapter holds a live cross-chain mint path on reUSD; active on Avalanche, Arbitrum, Base, BNB; 2.5M/24h rate limit

Adapter owner: 3-of-5 Safe 0x8eec…fBaD.
Sky USDSdirectBridged2-of-2Avalanche→Ethereum (inbound; Solana route also 2-of-2)LayerZero V2 OFT Adapter (Solana + Avalanche only)

Minor route: LayerZero handles only Solana + Avalanche (~48.7M locked, <0.7% of mainnet USDS supply) and does not hold wards on USDS. The bulk of USDS/sUSDS bridges via native rollup bridges — see the Native Rollup Bridges row

Adapter owner: Sky PauseProxy 0xBE8E…98FB (Chief + 48h GSM).
Fluid (rsETH)indirectBridged4-of-4via rsETH OFT Adapter (Arbitrum↔Ethereum)rsETH market exposure

Inherits rsETH's LayerZero OFT Adapter model

rsETH adapter owner: 3-of-6 Safe 0xCbcd…29A1.
Fluid (sUSDai)indirectMints native3-of-3Ethereum→Arbitrum (canonical sUSDai mint side)sUSDai collateral (USD.AI OAdapter)

OAdapter 0xffB2…7f24 burns and mints sUSDai on both chains; its authenticated receive path can mint canonical Arbitrum sUSDai. Fluid held ~96% of the Ethereum OToken supply at the Jul 22 check. The 10M/hour limiter is outbound-only and does not cap _credit on a forged inbound message

Adapter owner: 3-of-3 Safe 0x5F0B…841F.
KernelDAO hgETHindirectBridged4-of-4rsETH OFT Adapter (Arbitrum↔Ethereum); Kelp docs confirm 4-of-4 on the L2 mint pathWraps rsETH (Kelp DAO)

rsETH bridges via OFT Adapter 0x85d4…8Ef3, which escrows 46,254 rsETH (~9.6% of supply) — it cannot mint native rsETH

rsETH adapter owner: 3-of-6 Safe 0xCbcd…29A1.

Native Rollup Bridges

Canonical L2 bridges (OP Stack / Arbitrum Nitro)
1 direct

Each rollup's own canonical bridge — the OP Stack StandardBridge (Base, Optimism, Unichain), the Arbitrum Nitro gateway, and equivalents. L1 tokens are escrowed and minted 1:1 on the L2, secured by the rollup's proof system and Ethereum rather than an external validator set or attestation service. That makes it the lowest added third-party trust of any bridge class here — no separate verifier network to trust. The main residual risk is upgradeability: the bridge contracts can be upgraded, so a malicious or faulty upgrade by their admin is the primary path by which escrowed funds could be moved or minted.

Finality L1→L2 in minutes; L2→L1 withdrawals ~7 days (optimistic-rollup fraud-proof window).Admin Each rollup's bridge is a proxy controlled by that chain's ProxyAdmin / Security Council.
Protocol
Token
TypeModelIntegrationDetails
Sky USDSdirectBridgedOP Stack + Arbitrum Nitro canonical bridges (SkyLink)

Primary USDS/sUSDS cross-chain route: ~$0.45B USDS + ~812M sUSDS escrowed on L1 and minted 1:1 on Base, Optimism, Unichain (OP Stack) and Arbitrum (Nitro). No bridge holds wards on USDS. LayerZero carries only Solana + Avalanche (<0.7% of mainnet USDS supply)