HomeÚltimas NoticiasAltcoinsLido assures LDO, stETH tokens remain safe despite flaw in token contract

Lido assures LDO, stETH tokens remain safe despite flaw in token contract


Ethereum staking protocol Lido Finance has assured that both Lido DAO (LDO) and staked-Ether (stETH) tokens remain safe despite hackers allegedly exploiting a known security flaw in LDO’s token contract.

Lido didn’t confirm any exploits but acknowledged the security flaw was known and reassured that LDO and stETH funds remain safe in response to a Sept. 10 post by blockchain security firm SlowMist.

SlowMist said LDO’s flawed token contract allows bad actors to facilitate “fake deposit” attacks on exchanges because LDO’s token contract enables users to execute transactions even where they don’t have sufficient funds. This code deviates from the Ethereum Request for Comment 20 (ERC-20) token standard, according to SlowMist.

However, Lido Finance argued the flaw is built into all ERC-20 tokens — not just Lido’s LDO token:

SlowMist said the “fake deposit” attacks came from LDO’s token contract executing transfers where the value is larger than what the user actually owns, triggering a false return as opposed to reverting the transaction. While the firm said Lido’s token contract has recently been exploited via this attack, no on-chain evidence was provided.

Cointelegraph reached out to SlowMist for comment but did not receive an immediate response.

Meanwhile, on-chain analyst “Hercules” explained on Sept. 10 that the security flaw may not be picked up by cryptocurrency exchanges.

SlowMist recommends LDO holders to also check the return values of the token contract transfers in addition to the success or failure of a transaction.

The blockchain security firm concluded that token contract implementations and behaviors vary by project and to conduct comprehensive testing before integrating any new tokens.

Related: Ethereum staking services agree to 22% limit of all validators

However, Lido highlighted in the official Ethereum Improvement Proposal document — co-authored by Vitalik Buterin in November 2015 — that both the “transfer” and “transferFrom” functions must return the transfer status and are only recommended to revert a transaction in exceptional cases.

To resolve the security flaw, Lido confirmed that the LDO token integration guides will soon be updated.

Collect this article as an NFT to preserve this moment in history and show your support for independent journalism in the crypto space.

Magazine: DeFi Dad, Hall of Flame: Ethereum is ‘woefully undervalued’ but growing more powerful


Reciba noticias de Vimilin desde Google news


Please enter your comment!
Please enter your name here


BTC price shows ‘textbook’ Wyckoff moves as Bitcoin bulls defend $25K

Bitcoin (BTC) consolidated higher on Sept. 15 as analysis described recent BTC price behavior as “textbook.”Collect this article as an NFT to preserve this moment...

Magic Eden integrates Solana’s compressed NFTs into marketplace

Nonfungible token (NFT) marketplace Magic Eden has announced that it will support Solana’s compressed NFTs (cNFTs) to provide a cost-efficient and scalable alternative to owning...

House Democrats back Biden candidacy as calls for president to drop out intensify on the left

FIRST ON FOX: House Democrats appear to be behind another Biden-Harris ticket, even as President Biden is being discouraged against running by some on the...

3 Standout Stocks to Buy as Worse-Than-Expected CPI Numbers Revive Inflation Fears

The August CPI report showed headline annual inflation rising 3.7% compared to the 3.2% reading seen in July and a 3.0% increase in June. As inflation...

Más popular