LayerZero is messaging infrastructure rather than a bridge per se: applications use it to send arbitrary messages between chains, and token bridges are one use case among many. Its coverage — well over a hundred chains — is unmatched.
The configurable security model
In v2, each application chooses its Decentralised Verifier Networks: which parties must independently confirm a message before it is accepted. An application can require several reputable DVNs, which is a strong setup, or it can accept the cheapest default, which is not. That choice is invisible to end users, who assume the protocol's brand implies a security level it does not guarantee.
What has actually gone wrong
The core messaging layer has not been compromised. Applications built on it have been exploited, usually through their own contract logic or through inadequate verifier configuration. From a user's perspective the distinction is academic — funds are gone either way — which is why understanding the specific application's configuration matters more than the underlying protocol's reputation.
Costs
Set by each application on top of gas. Bridging costs therefore vary substantially depending on which product you use, not on LayerZero itself.
Who should use it
Users of specific applications built on it, having checked how that application configures verification where possible. Builders wanting the broadest chain reach available.