CoinInsight360.com logo CoinInsight360.com logo
America's Social Casino

CoinDesk 2025-05-12 05:53:22

Ethereum Staking Giant Lido Loses Just 1.4 ETH in Hacking Attempt

Lido, Ethereum’s largest liquid staking protocol, avoided a major security incident after one of its nine oracle keys was compromised in what appears to be a low-impact but serious breach involving validator operator Chorus One. Lido secures over 25% of all ETH staked on Ethereum, making it one of the most systemically important protocols in the Ethereum ecosystem. The compromised key was tied to a hot wallet used for oracle reporting, leading to the theft of just 1.46 ETH ($4,200) in gas fees. No user funds were affected, and no broader compromise was detected, per X posts from both Lido and Chorus One Lido’s oracle system is a blockchain-based tool that supplies Ethereum consensus data to Lido’s smart contracts using a 5-of-9 quorum mechanism. This means that even if one or two keys are compromised, the system can function securely. Contributors first detected the suspicious activity early Sunday after a low-balance alert triggered a closer look at the address. It revealed unauthorized access to an oracle private key used by Chorus One that was originally created in 2021 and not secured to the same standards as newer keys, the firm said in an X post . In response, Lido has launched an emergency DAO vote to rotate the compromised oracle key across three contracts: the Accounting Oracle, the Validators Exit Bus Oracle, and the CS Fee Oracle. The new key has been generated using better security controls to avoid any repeat. The hack occurred just as several other oracle operators were experiencing unrelated node issues, including a minor Prysm bug introduced by Ethereum’s recent Pectra upgrade, briefly delaying oracle reports on May 10. The compromised address (0x140B) is being replaced by a new secure address (0x285f), with the on-chain vote already approved and in its 48-hour objection period as of Asian morning hours Monday.

Read the Disclaimer : All content provided herein our website, hyperlinked sites, associated applications, forums, blogs, social media accounts and other platforms (“Site”) is for your general information only, procured from third party sources. We make no warranties of any kind in relation to our content, including but not limited to accuracy and updatedness. No part of the content that we provide constitutes financial advice, legal advice or any other form of advice meant for your specific reliance for any purpose. Any use or reliance on our content is solely at your own risk and discretion. You should conduct your own research, review, analyse and verify our content before relying on them. Trading is a highly risky activity that can lead to major losses, please therefore consult your financial advisor before making any decision. No content on our Site is meant to be a solicitation or offer.