Hyperlane is an interoperability protocol that lets anyone spin up cross-chain connectivity without gatekeeping. Launched in 2022, it is live on 100+ chains including Ethereum, Arbitrum, Solana, and BNB. The protocol stands out with Interchain Security Modules (ISMs) — pluggable security frameworks where each application chooses its own trust assumptions, from multisigs to ZK proofs. No TVL metric exists because Hyperlane is a messaging layer, not a value-locking protocol. Audits from multiple firms including Trail of Bits, Zellic, Hacken, and Sec3 provide security assurance, and governance is steered by the Hyperlane DAO and HYPER token.
What it is
Hyperlane is a permissionless cross-chain messaging protocol. It solves interoperability fragmentation by allowing any developer to deploy its messaging contracts to a new chain without going through a central approval process. The protocol operates as a smart contract layer that passes arbitrary messages between blockchains. Applications built on Hyperlane — bridges, interchain DAOs, multi-chain wallets — can customize security models via Interchain Security Modules. Hyperlane does not custody funds or reserve value; it transmits data and instructions. As of 2026, it supports over 100 chains, making it one of the most widely deployed interop layers.
How it works
Hyperlane’s architecture revolves around three components: the Mailbox (on-chain smart contract), the relayer (off-chain agent), and Interchain Security Modules. When a user initiates a cross-chain action, the source chain’s Mailbox emits an event. Relayers pick up the event and deliver it to the destination Mailbox. Before acceptance, the destination’s ISM verifies the message’s validity. Applications select their ISM config — options include multisig committees, zero-knowledge proofs, optimistic fraud windows, or restaking-backed security from protocols like EigenLayer EigenLayer or Symbiotic Symbiotic. By decoupling security from the transport layer, Hyperlane avoids the monoculture risk that has caused bridge exploits on other networks. No single set of validators controls the whole system; each app picks its own guardians. This modular design also enables permissionless chain support, as anyone can deploy the Mailbox and ISM contracts to a new EVM or non-EVM chain without Hyperlane governance approval.
Key numbers
- Chains supported: 100+, including Ethereum, Arbitrum, Optimism, Base, Polygon, BNB, and Solana.
- Launch year: 2022.
- Audits: Trail of Bits, Zellic, Hacken, Sec3.
- TVL: Not applicable — Hyperlane is a messaging layer that does not lock user deposits.
- Governance token: HYPER, used in the Hyperlane DAO.
Security and audits
Hyperlane has undergone multiple public audits — including from Trail of Bits, Zellic, Hacken, and Sec3 — covering its core Mailbox and ISM implementations. No major exploits or incidents have been publicly reported as of the review date. The protocol’s security posture depends heavily on the ISM configuration chosen by each application. A multisig ISM offers familiar security but introduces trust assumptions in those signers, while a ZK or restaking ISM reduces trust at the cost of higher technical complexity and potential liveness risks. The Hyperlane DAO governs protocol upgrades and treasury, relying on HYPER token holders. Smart contract upgradability details are not uniformly disclosed across all deployments; some core contracts may be upgradeable by the DAO. Users should investigate the specific ISM setup of any Hyperlane-enabled application they use.
Strengths
- Chain coverage: With 100+ integrated chains, Hyperlane offers the broadest cross-chain network among major interop protocols. No direct competitor approaches this coverage.
- Permissionless deployment: Any developer can extend Hyperlane to a new chain without governance approval, enabling rapid ecosystem growth and reducing centralization risk.
- Modular security: Interchain Security Modules let apps choose from multisig, ZK, optimistic, or restaking models — a flexible design that avoids a single point of failure seen in many bridges.
Weaknesses and risks
- No TVL metric: Because Hyperlane does not hold assets, it lacks a direct measure of economic throughput or adoption, making benchmarking against value-locking protocols difficult.
- Broad attack surface: Although audited by multiple firms (Trail of Bits, Zellic, Hacken, Sec3), Hyperlane spans a large attack surface across 100+ chains and many ISM types, so per-application security still varies and further formal verification would help.
- Security fragmentation: An app’s safety hinges on its ISM choice. Users must independently assess the security of each Hyperlane-connected application, as a misconfigured ISM could lead to message forgery or loss.
How it compares
Among the peer set in this review, Hyperlane’s permissionless interop model contrasts sharply with EigenLayer EigenLayer and Symbiotic Symbiotic, which focus on restaking security for Ethereum AVSs, and Aave Aave, a lending protocol. Hyperlane’s 100+ chain deployment vastly exceeds Aave’s 9-chain presence and EigenLayer’s or Symbiotic’s single-chain (Ethereum) footprint. However, EigenLayer (TVL ~$5.1B), Aave (TVL ~$14B), and Symbiotic (TVL ~$0.3B) all lock significant value, providing clear adoption signals that Hyperlane cannot replicate. On audit coverage, Hyperlane is competitive: it has been reviewed by Trail of Bits, Zellic, Hacken, and Sec3, comparable to Aave (Trail of Bits, OpenZeppelin, Certora), EigenLayer (Sigma Prime, Consensys Diligence, Cantina), and Symbiotic (Cantina, OpenZeppelin). Governance varies: Hyperlane and Aave rely on DAO/token models, while EigenLayer and Symbiotic are more foundation-led. For builders needing wide chain reach and customizable security, Hyperlane is compelling; for users seeking deep liquidity or restaking yields, the value-locking peers remain dominant.
Verdict
Hyperlane advances interoperability with a genuinely permissionless, modular design that supports over 100 chains — a scale no other messaging protocol offers. The absence of TVL makes economic impact hard to quantify, and its security heterogeneity demands diligence from users and developers. Audits from several reputable firms (Trail of Bits, Zellic, Hacken, Sec3) are a strength, though broader formal verification would further reduce risk. Hyperlane earns a 7.5/10 for technical ambition and chain coverage, tempered by transparency gaps and early-stage risk profile.
Reviewed 2026-05-27 by DeFi Intel Research Desk.
DeFi Intel publishes editorial research, not financial advice. Do your own research and consult a licensed advisor for your situation.