Lido Swiftly Secures Its Network After Critical Oracle Breach
By: cointurk|2025/05/12 23:15:05
0
Share
Lido, one of the largest liquid staking protocols in the Ethereum $ 2,551 ecosystem, swiftly managed a significant security incident over the weekend. As a protocol that secures over 25% of all staked ETH on Ethereum, it plays a vital systemic role. The incident began with the compromise of one of the nine oracle keys within the protocol. Incident Development The breach resulted from unauthorized access to an oracle key linked to a validator operator managed by Chorus One. This key, created in 2021, had less protection compared to current security standards. It was reported to be part of a hot wallet associated with an oracle reporting process, with only 1.46 ETH (approximately $4,200) in gas fees stolen. Chorus One revealed in a post that a “low balance alert prompted closer inspection, uncovering unauthorized access to an oracle private key created in 2021.” User Funds Remain Safe No user assets were affected following the incident, and no large-scale security breach was detected. Lido employs a 5-out-of-9 voting majority mechanism within its oracle system. This mechanism ensures the overall security of the system, even if one or two keys are compromised. Lido and Chorus One announced on platform X that the incident did not threaten users or the overall security of the protocol. Timely detection of the breach prevented any potential larger damage. Swift Actions and Technical Details Following the breach, Lido promptly initiated an emergency DAO vote to replace the compromised oracle key. The key was used in three different contracts – the Accounting Oracle, the Validators Exit Bus Oracle, and the CS Fee Oracle. The vote ensured the implementation of a new, more secure key across these contracts. During the incident, other oracle operators also faced unexpected node issues due to a minor Prysm bug related to Ethereum’s recent Pectra update, causing brief delays in oracle reports. The compromised address 0x140B was replaced with the newly created 0x285f address. The on-chain vote was approved, entering a 48-hour contestation period. The Lido team stated that post-incident, security protocols will be revisited, with additional measures implemented especially on older keys, and security standards will be elevated further. This incident at Lido highlights the constant testing of security vulnerabilities in decentralized finance protocols. The quick detection by technical teams and the effectiveness of security processes limited the extent of the damage. The multi-signature mechanism, while some oracle keys were endangered, significantly contributed to the safety of user assets. Such incidents remind protocols of the necessity to continuously enhance their security structures.
You may also like

Just now, Sam Altman was attacked again, this time by gunfire
Sam Altman's residence was shot at again, reflecting the deep anxiety and crisis of trust among the public regarding the accelerated evolution of AI into a "quasi-political force" and the lack of social checks and balances behind the extreme violence.

Straits Blockade, Stablecoin Recap | Rewire News Morning Edition
Oil Price Surges

From High Expectations to Controversial Turnaround, Genius Airdrop Triggers Community Backlash
The deadline for immediate claim is 7 days after TGE. If the user chooses immediate claim, 70% of the tokens will be automatically burned.

The Xiaomi electric vehicle factory in Beijing's Daxing district has become the new Jerusalem for the American elite
What exactly turns an automotive assembly line into a hot spot?

Lean Harness, Fat Skill: The Real Source of 100x AI Productivity
error

Ultraman is not afraid of his mansion being attacked; he has a fortress.
Publicly Betting AI Will Succeed, Secretly Preparing for AI to Go Rogue

US-Iran Negotiations Collapse, Bitcoin Faces Battle to Defend $70,000 Level
Polymarket's latest data shows that the market probability of the Fed standing pat this year has risen to 44%.

Reflections and Confusions of a Crypto VC
As the tide recedes, crypto VCs face a life-and-death test. The bubble of blind token overvaluation has been burst, and the industry's valuation logic is returning to real revenue. In the face of increasingly savvy retail investors and dried-up liquidity, VCs that can only throw money around are des...

Morning News | Ether Machine terminates $1.6 billion SPAC deal; SpaceX holds approximately $603 million in Bitcoin; Michael Saylor releases Bitcoin Tracker information again
Overview of Important Market Events on April 12

Crypto ETF Weekly | Last week, the net inflow for Bitcoin spot ETFs in the U.S. was $816 million; the net inflow for Ethereum spot ETFs in the U.S. was $187 million
Bitwise updates Hyperliquid ETF application documents, with the trading code set as BHYP.

This week's news preview | The U.S. will release March PPI data; French President Macron will give a speech at Paris Blockchain Week
Highlights of the week from April 13 to April 19.

How Do Digital Assets Self-Custody? OpenAI Cofounder's 15-Step Checklist
It's time to outsource our memory to AI

Circle Product Management Director: The Future of Cross-Chain: Building an Interoperability Technology Stack for Internet Financial Systems
Building on the foundation laid by CCTP, Circle is increasing its investment in three main areas: settlement acceleration, broader asset interoperability, and orchestration, making cross-chain value flow more seamless and efficient, and achieving internet-level usability.
UCL Fan Tokens 2026 Guide: How to Trade UEFA Champions League Crypto with Zero Fees on WEEX
Discover UCL fan tokens like PSG, Barcelona, and Man City. Learn how to trade UEFA Champions League crypto with zero fees and earn rewards on WEEX.
WEEX Poker Party Season 2: Check How to Earn Crypto Rewards Now!
Learn how WEEX Poker Party Season 2 (Joker Card Event) works. Discover rules, scoring, rewards, and strategies to earn crypto rewards through gamified trading.

Yu Weiwen: Steady Development of Hong Kong's Compliant Stablecoin Ecosystem
The President of the Hong Kong Monetary Authority, Eddie Yue, published an article titled "Steady Development of Hong Kong's Compliant Stablecoin Ecosystem" in the official column "Hui Si," in which he pointed out that this licensing marks a new stage in the regulation of stablecoins in Hong Kong.

After TACO Ceasefire, Iran War is Just on Pause
Ceasefire Eased Market Sentiment but Did Not Address Core Conflict

The 17-Year Mystery Will Be Solved, Who is Satoshi Nakamoto?
The New York Times Traces the Mystery of Satoshi Nakamoto, with Clues Pointing to Adam Back
Just now, Sam Altman was attacked again, this time by gunfire
Sam Altman's residence was shot at again, reflecting the deep anxiety and crisis of trust among the public regarding the accelerated evolution of AI into a "quasi-political force" and the lack of social checks and balances behind the extreme violence.
Straits Blockade, Stablecoin Recap | Rewire News Morning Edition
Oil Price Surges
From High Expectations to Controversial Turnaround, Genius Airdrop Triggers Community Backlash
The deadline for immediate claim is 7 days after TGE. If the user chooses immediate claim, 70% of the tokens will be automatically burned.
The Xiaomi electric vehicle factory in Beijing's Daxing district has become the new Jerusalem for the American elite
What exactly turns an automotive assembly line into a hot spot?
Lean Harness, Fat Skill: The Real Source of 100x AI Productivity
error
Ultraman is not afraid of his mansion being attacked; he has a fortress.
Publicly Betting AI Will Succeed, Secretly Preparing for AI to Go Rogue
