Wormhole Review
A named quorum: 13 of 19 guardians
of 10
Wormhole publishes the exact shape of its trust assumption — 19 guardians, of whom 13 must sign to produce a valid message — and releases under Apache 2.0. It publishes neither a fee nor a total chain count.
No money changes hands. This is a non-commercial project: no advertising, no sponsored placements, and no affiliate or referral links. Links to the services below earn us nothing. Every overall score is the plain average of the criteria shown on the page, so you can check the arithmetic yourself — see our rating methodology and how the site is funded.
Trust model
19 guardians; 13 signatures required for a valid message
Validator basis
Established validator companies, not token incentives
Licence
Apache License 2.0 (short-form notice)
Fees
Not stated
Auditors
Neodyme, Kudelski, Trail of Bits
Scores
Each criterion carries equal weight. The overall score is the average of these 5 scores — (3.0 + 10.0 + 9.0 + 3.0 + 9.0) ÷ 5 = 6.8.
Pros
- Guardian set size and quorum published exactly: 13 of 19 signatures required
- States it relies on established validator companies rather than token-based incentives
- Apache License 2.0
- Audits published in-repo from Neodyme, Kudelski and Trail of Bits, plus per-chain folders
Cons
- No fee is stated on the protocol introduction page
- No total chain count is published; coverage is split across six separate product tables
- GitHub classifies the licence as NOASSERTION because the file uses a short-form notice
A quorum you can count
Wormhole states that a set of 19 participants offers a balance of decentralisation and efficiency, and that 13 signatures are required to produce a valid message. Publishing both numbers means a reader can reason about the assumption directly: thirteen of nineteen named operators would have to collude or be compromised.
The protocol also states it relies on established validator companies rather than token-based incentives — a design choice with real trade-offs, stated rather than obscured.
What is missing
The introduction page carries no fee information, and the supported-networks page splits coverage across six product tables without consolidating a total, so there is no published answer to how many chains the bridge connects.
A note on what we have not written
We found no incident report or postmortem on Wormhole's own pages, and we do not publish security history for a protocol from memory. Absence here means we could not verify, not that nothing occurred.
How it compares
Synapse
MIT-licensed, and little else readable
Chainflip
Apache-licensed, with documentation gaps
Squid
Charges nothing, documents little
deBridge
Per-chain flat fees, published in full
Hop Protocol
Every fee component published as a range
Stargate / LayerZero
Exact fee split, and a licence that expired unresolved
Celer cBridge
GPL-3.0 with a published fee ceiling
Across
Optimistic security explained in one sentence
Axelar
Apache-licensed with the deepest audit archive
Sources
Scored from published primary sources rather than hands-on use. Every figure above comes from one of the pages below, on the date shown. Manufacturers change prices and specifications without notice — if something here no longer matches the source, tell us and we will correct it.
- 1.Wormhole — protocol introduction — checked
- 2.Wormhole — guardians and quorum — checked
- 3.Wormhole — LICENSE — checked
- 4.Wormhole — audits — checked
Frequently asked questions
How many guardians secure Wormhole?
Wormhole states a set of 19 guardians, of which 13 signatures are required to produce a valid message.
What does Wormhole charge?
No fee is stated on the protocol introduction page as checked on 24 July 2026.
Nothing here is financial advice. Editorial policy · How we score · How we're funded.