Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Lido Says Funds Safe After Oracle Incident Triggers Emergency Response

Lido Says Funds Safe After Oracle Incident Triggers Emergency Response

CryptoNewsCryptoNews2025/05/12 11:11
By:Shalini Nagarajan

Lido launched an emergency DAO vote to replace the compromised oracle key, with the new key already secured under enhanced protocols.

Ethereum staking protocol Lido moved over the weekend to neutralize a threat after one of its oracle keys, managed by validator operator Chorus One, was compromised.

Although 1.46 ETH ($3,675) was drained from a hot wallet used for oracle voting, Lido confirmed that the protocol remains secure and fully operational .

The breach came to light on May 10 when a contributor noticed a low balance alert on the affected wallet.

Further checks revealed the key had been accessed by an unauthorized party, prompting immediate coordination between Lido contributors and Chorus One to contain the situation.

The compromised wallet, created in 2021, was used to sign oracle reports but was not protected under the same strict standards as other infrastructure, Chorus One later clarified .

On May 10, a hot wallet managed by Chorus One that was used to vote in the Lido Oracle was accessed by an unauthorized entity, leading to the transfer of 1.46 ETH. Our team has been working tirelessly, in collaboration with @LidoFinance , to investigate the incident. As a result,… https://t.co/IIAGdBe1pQ pic.twitter.com/ZWpSFJ43VX

— Chorus One (@ChorusOne) May 11, 2025

Lido’s Quorum Model Limits Impact of Oracle Key Breach

Although the incident affected one of nine oracle participants, Lido’s oracle system is designed with resilience in mind. Its 5-of-9 quorum mechanism ensures no single operator can jeopardize the integrity of the oracle network. All remaining oracle addresses and the software infrastructure passed integrity checks with no signs of further compromise.

In response, Lido initiated an emergency DAO vote to rotate the affected oracle key across three contracts: the Accounting Oracle, Validators Exit Bus Oracle, and CS Fee Oracle.

The vote, launched immediately after the breach was confirmed, will run for 72 hours with a subsequent 48-hour objection window. The replacement key has already been generated and securely stored using updated security protocols.

Minor Node Issues Briefly Disrupted Oracle Reports, Now Resolved

Lido’s infrastructure faced additional oracle reporting delays on May 10. These delays were caused by unrelated technical issues affecting four other oracle operators. Specifically, the problems stemmed from node-level bugs. However, they were resolved quickly and had no impact on user funds or staking operations.

Meanwhile, Chorus One, which runs validator services across multiple networks, addressed concerns about the compromised wallet. The company explained that the wallet had always held low balances and was never used to store client assets. Therefore, no customer funds were at risk.

Chorus One added that the incident does not reflect its current security standards. Today, the firm secures oracle keys using HashiCorp Vault and enforces strict role-based access controls.

Lido has promised a full post-mortem once its ongoing investigation concludes. In the meantime, a review of oracle infrastructure and security practices is underway to prevent recurrence.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

What major moves have mainstream Perp DEXs been making recently?

Perp DEXs are all unveiling major new features.

BlockBeats2025/11/22 18:13
What major moves have mainstream Perp DEXs been making recently?

After a 1460% surge, re-examining the value foundation of ZEC

History has repeatedly shown that extremely short payback periods (super high ROI) are often precursors to mining disasters and sharp declines in coin prices.

BlockBeats2025/11/22 18:12
After a 1460% surge, re-examining the value foundation of ZEC

Tom Lee reveals: The crash was caused by the 1011 liquidity crunch, with market makers selling off to fill a "financial black hole"

Lee stated directly: Market makers are essentially like the central banks of crypto. When their balance sheets are damaged, liquidity tightens and the market becomes fragile.

BlockBeats2025/11/22 18:11
Tom Lee reveals: The crash was caused by the 1011 liquidity crunch, with market makers selling off to fill a "financial black hole"

Boxing champion Andrew Tate's "Going to Zero": How did he lose $720,000 on Hyperliquid?

Andrew Tate hardly engages in risk management and tends to re-enter losing trades with higher leverage.

ForesightNews 速递2025/11/22 17:53
Boxing champion Andrew Tate's "Going to Zero": How did he lose $720,000 on Hyperliquid?