Lido Launches DAO Vote After Oracle Key Compromise
By: tronweekly|2025/05/12 08:15:06
0
Share
Key Takeaways:One Chorus One Lido oracle key compromised; DAO vote launched for emergency rotation.eProtocol security remains intact; all other oracles verified uncompromised.Oracle operations resumed after minor delays; root cause investigation underway.An emergency DAO vote has been announced by Lido contributors following the detection of a compromised oracle key operated by Chorus One. The affected key, responsible for critical data reporting functions, was flagged after an alert showed a sudden depletion in its ETH balance.Investigation is ongoing.Incident details, root cause updates, vote details — all in the forum post: https://t.co/vn4gq8W82gOnce the investigation is complete, we’ll share the full results here and on the research forum.— Lido (@LidoFinance) May 11, 2025Subsequent investigation traced the issue to a probable private key leak, possibly from a previously used hot wallet. The incident does not indicate a broader breach of Chorus One’s infrastructure or oracle system integrity.This prompted immediate action, including isolation of the compromised key and preparation for replacement on three Oracle contracts: AccountingOracle, ValidatorsExitBusOracle, and CSFeeOracle.The affected address (0x140B.) will be substituted with a fresh, secure key (0x285f.). Inasmuch as the incident is severe, there is no loss of staker funds or integrity of staking protocol for Lido. The 5-of-9 quorum model for the system has inherent redundancy and robustness, inherently avoiding single points of failure.Lido Demonstrates Strong Layered Security ResponseLabs emphasizes Lido’s multi-layered incident response and security strategy throughout its reply. The rapid collaboration of the team with Chorus One and a full audit of all other oracles prevented wider disruption within the system.All eight remaining oracle operators were verified as being secure, with no irregularities within the reporting infrastructure or software layers.On May 10th, Lido’s Oracle system experienced minor reporting delays due to unrelated issues affecting four other Oracle participants.Two of those were linked to a post-Spectra Prism bug, which is expected to be resolved in a future update. Despite this coincidence, all delayed reports were eventually delivered, and quorum functionality has since returned to normal.During the same day, Lido contributors and Chorus One’s security teams conducted detailed reviews of their systems to pinpoint the breach’s vector.No indication has been seen of a deeper exploitation or software-level breach. The problem seems limited to the key itself, potentially from previous use and handling, and not a current intrusion.Lido Promises Detailed Post-Mortem ReportThe emergency DAO voting for rotating the hacked oracle key is scheduled for two phases: a 72-hour main voting period and a subsequent 48-hour objection period.This change will update all affected contracts so they incorporate the fresh, un-hacked key. The hacked address will be excluded from quorum activities until voting is over.As a matter of transparency and future reliability, Lido has pledged to release a thorough post-mortem once the ongoing investigation is complete.The report will include, among other things, the sequence of events, root cause, and any protocol improvements implemented in consequence.Related Reading | XRP Price Performance Lags Other Top Cryptos, But Payment Rivals XLM and RTX Are Both Soaring
You may also like

a16z Crypto: What We See Behind the $2.2 Billion New Fund
After the noise subsides, what remains is often more useful than it appeared at its peak and more enduring than it seemed at its lowest point.

Web3 is dead, Web2+3 should rise
We are not aiming to hold a self-indulgent party for Web3 practitioners, but rather to build a bridge for rational connection between Web2 and Web3.

Stablecoins and Latin American Remittances: The Misunderstood $174 Billion Market
In the Latin American remittance market, the real protagonists have never been the young people speculating on cryptocurrencies, but rather the 50-year-old workers who send money to their mothers every month. They don't care about blockchain; they only care about whether the money has arrived.

The arrival of the Web 3.0 era: A review of Hong Kong court rulings on digital assets
Hong Kong judiciary landmark: The court officially recognizes cryptocurrency as legal property and introduces the "tokenized injunction" to track and freeze involved funds, comprehensively upgrading the protection of digital asset investors.

Track Markets At a Glance: New WEEX Price Widgets for iOS & Android
To streamline your market data access, WEEX has officially launched "Market Watchlist" desktop widgets

The billion-dollar lesson: The focus of DeFi security is shifting from code to operational governance
Warning of nearly $1 billion loss in DeFi: Security pain points have shifted from code vulnerabilities to permissions and operations. Introducing TradFi bank-level risk control and AI defenses is the way to balance openness and security.

A Brief Analysis of Stablecoin Licenses and On-Chain Funding
Hong Kong accelerates the layout of digital finance, providing a panoramic analysis of the evolution of three major on-chain financial forms: central bank digital currency, deposit tokens, and stablecoins, along with future opportunities.

BVNK Founder: Three Stages of Stablecoin Development
Once payments become faster, cheaper, and globally interconnected, stablecoins will not just open up a new market, but a new realm with boundaries that are not yet visible today.

The truth about Trump's son's Bitcoin game: he made a staggering $100 million while retail investors lost $500 million
The Trump family has a family skill: to exaggerate and make something sound bigger than it actually is.

What Is Futures Trading? Hours, Platforms, and How to Start Trade Futures(2026 Guide)
Learn how to start futures trading, understand trading hours, and choose the best futures trading platform. Includes real data, strategies, and ways to maximize returns with rebates.

The Rise of Composable RWA
27 billion RWA funds are undergoing a major reshuffle: U.S. Treasury bonds are "cooling off," while high-yield credit assets are quietly dominating the DeFi lending market with permissionless designs. This article reveals the explosive logic behind composable RWA.

MAGA Up 350% in 24 Hours, PEPE Up 46% in One Day: Which Memecoins Are Next in 2026?
MAGA +350% in 24hrs. PEPE +46% in one day. RAVE +4,500% then -90%. In 2026's memecoin market, the gains are real. So are the traps? Here's how to tell the difference before you buy.

RCD Espanyol vs Real Madrid: Can the Pericos Delay the Inevitable?
RCD Espanyol vs Real Madrid lineups, standings, and stats for May 3, 2026. Real Madrid visits RCDE Stadium as Barcelona closes in on the LALIGA title. Full preview inside.

MegaETH goes live with an FDV exceeding 2 billion USD. Which ecological projects are worth paying attention to?
The financing and team backgrounds of many projects in the MegaETH ecosystem are rich, making it the most prosperous ecosystem among unlaunched public chains, and it is currently the focus of attention for profit-seekers.

Dialogue with "Wood Sister" Cathie Wood: The next bull market is about to arrive
The correlation coefficient between gold and Bitcoin is only 0.14. In the past two cycles, gold started before Bitcoin, and this time is no different.

Can prediction markets win the competition for perpetual contracts?
Polymarket and Kalshi have entered the perpetual contract arena. In the face of Hyperliquid's "cross-margin" dimensional reduction attack, can the prediction market break the curse of loss and turn the tide?

Who is trading on Trade.xyz?
A Polymarket user supported nearly half of Trade.xyz's "active addresses" with 34,000 wallets, yet contributed less than 1% of the trading volume. The real support for the market comes from market-making institutions like Jump, Selini, and Wintermute, as well as a group of directional traders crossi...

Binance quietly placed a bet on a leading large model company
In the past year, YZi Labs has significantly accelerated its investments in the AI field, from educational agents to physical robots, and then to large models, with crypto capital and AI technology rapidly integrating.
a16z Crypto: What We See Behind the $2.2 Billion New Fund
After the noise subsides, what remains is often more useful than it appeared at its peak and more enduring than it seemed at its lowest point.
Web3 is dead, Web2+3 should rise
We are not aiming to hold a self-indulgent party for Web3 practitioners, but rather to build a bridge for rational connection between Web2 and Web3.
Stablecoins and Latin American Remittances: The Misunderstood $174 Billion Market
In the Latin American remittance market, the real protagonists have never been the young people speculating on cryptocurrencies, but rather the 50-year-old workers who send money to their mothers every month. They don't care about blockchain; they only care about whether the money has arrived.
The arrival of the Web 3.0 era: A review of Hong Kong court rulings on digital assets
Hong Kong judiciary landmark: The court officially recognizes cryptocurrency as legal property and introduces the "tokenized injunction" to track and freeze involved funds, comprehensively upgrading the protection of digital asset investors.
Track Markets At a Glance: New WEEX Price Widgets for iOS & Android
To streamline your market data access, WEEX has officially launched "Market Watchlist" desktop widgets
The billion-dollar lesson: The focus of DeFi security is shifting from code to operational governance
Warning of nearly $1 billion loss in DeFi: Security pain points have shifted from code vulnerabilities to permissions and operations. Introducing TradFi bank-level risk control and AI defenses is the way to balance openness and security.
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com
