icon
icon
icon
icon
Upgrade
Upgrade

News /

Articles /

Lido Rotates Oracle Key After 1.46 ETH Breach

Coin WorldMonday, May 12, 2025 12:34 am ET
1min read

Lido, an Ethereum staking protocol, took immediate action over the weekend to address a security threat after one of its oracle keys, managed by validator operator Chorus One, was compromised. The incident, which involved the unauthorized access to a hot wallet used for oracle voting, resulted in the transfer of 1.46 ETH. Despite this breach, Lido assured users that the protocol remains secure and fully operational.

The breach was discovered on May 10 when a contributor noticed a low balance alert on the affected wallet. Subsequent investigations revealed that the key had been accessed by an unauthorized party. This prompted a swift response from Lido contributors and Chorus One to contain the situation. The compromised wallet, created in 2021, was used to sign oracle reports but was not protected under the same strict standards as other infrastructure, as clarified by Chorus One.

Lido’s oracle system is designed with resilience in mind, featuring a 5-of-9 quorum mechanism that ensures no single operator can jeopardize the integrity of the oracle network. All remaining oracle addresses and the software infrastructure passed integrity checks with no signs of further compromise. In response to the incident, Lido initiated an emergency DAO vote to rotate the affected oracle key across three contracts: the Accounting Oracle, Validators Exit Bus Oracle, and CS Fee Oracle. The vote, launched immediately after the breach was confirmed, will run for 72 hours with a subsequent 48-hour objection window. The replacement key has already been generated and securely stored using updated security protocols.

Ask Aime: "Was Lido's security breach a significant risk to users?"

In addition to the oracle key breach, Lido’s infrastructure faced minor node issues on May 10 that briefly disrupted oracle reports. These delays were caused by unrelated technical issues affecting four other oracle operators, specifically stemming from node-level bugs. However, these issues were resolved quickly and had no impact on user funds or staking operations. Chorus One, which runs validator services across multiple networks, addressed concerns about the compromised wallet, explaining that it had always held low balances and was never used to store client assets. Therefore, no customer funds were at risk. Chorus One also noted that the incident does not reflect its current security standards, as the firm now secures oracle keys using HashiCorp Vault and enforces strict role-based access controls.

Lido has promised a full post-mortem once its ongoing investigation concludes. In the meantime, a review of oracle infrastructure and security practices is underway to prevent recurrence. The protocol’s swift response and robust security measures have ensured that user funds remain safe, and the protocol continues to operate smoothly despite the incident.

Comments

Add a public comment...
Post
Refresh
Disclaimer: the above is a summary showing certain market information. AInvest is not responsible for any data errors, omissions or other information that may be displayed incorrectly as the data is derived from a third party source. Communications displaying market prices, data and other information available in this post are meant for informational purposes only and are not intended as an offer or solicitation for the purchase or sale of any security. Please do your own research when investing. All investments involve risk and the past performance of a security, or financial product does not guarantee future results or returns. Keep in mind that while diversification may help spread risk, it does not assure a profit, or protect against loss in a down market.
You Can Understand News Better with AI.
Whats the News impact on stock market?
Its impact is
fork
logo
AInvest
Aime Coplilot
Invest Smarter With AI Power.
Open App