A Key Ethereum Validator for Lido Finance to Temporarily Exit and Rotate Key Due to Vulnerability Disclosure

A Key Ethereum Validator for Lido Finance to Temporarily Exit and Rotate Key Due to Vulnerability Disclosure

Reported by The Block, one of the key node operators for Lido Finance, InfStones, will temporarily withdraw its Ethereum validators from the liquid staking protocol and implement key rotations in response to a significant vulnerability revealed by dWallet Labs' security researchers.

The vulnerability, linked to the open-source library Tailon, was reported to InfStones in July 2023 and has since been resolved. Nonetheless, this event has led to the adoption of preventative security measures.

Lido Finance confirmed the vulnerability was related to potential root-level access that impacted 25 of InfStones’ validator servers. Lido clarified, however, that there’s no evidence of any key leakage or exploitation as a result of this issue.

"To clarify: There is currently no indication of key leakage or compromise, and the vulnerability may not affect validators related the Lido protocol," it said.

In its security report, dWallet Labs alleged the vulnerability could have potentially triggered a security breach impacting the ETH staked through InfStones’ nodes on Lido. Consequently, the firm recommended the rotation of validator keys for all nodes that were possibly exposed to the vulnerability.

InfStones said the issue flagged by dWallet only affected a small part of its infrastructure, with less than 0.1% of its systems via a specific network port on its network that had the issue. As such it implied the affected validator nodes was a small number.

Source

Ethereum

Staking

In This Article

Related News
Ethereum community plans onchain ‘time capsule’ to mark 10th anniversary of network’s genesis block Ethereum community plans onchain ‘time capsule’ to mark 10th anniversary of network’s genesis block
Vitalik Buterin suggests implementing ‘partially stateless nodes’ to help scale Ethereum Vitalik Buterin suggests implementing ‘partially stateless nodes’ to help scale Ethereum
Ethereum developers activate Pectra upgrade with 11 changes to improve UX, validator ops and Layer 2 scaling Ethereum developers activate Pectra upgrade with 11 changes to improve UX, validator ops and Layer 2 scaling
Interchain Labs launches IBC Eureka to connect Ethereum to the Cosmos ecosystem Interchain Labs launches IBC Eureka to connect Ethereum to the Cosmos ecosystem
Ethereum edges closer to deploying Pectra on mainnet with successful upgrade on Hoodi testnet Ethereum edges closer to deploying Pectra on mainnet with successful upgrade on Hoodi testnet
Latest News More More
1 Day Ago Tether plans further Bitcoin mining expansion in South America with Adecoagro tie up
2 Days Ago North Korean hackers use fake Zoom updates to deliver ‘NimDoor’ macOS malware targeting crypto firms
2 Days Ago JPMorgan's blockchain unit tests new carbon credit tokenization application with S&P Global
June 25 Circle's post-IPO stock surge pushes market cap near Coinbase and USDC
June 20 Kraken offers bitcoin ‘staking’ yield via Babylon without wrapping or lending
delate
Use TokenInsight App All Crypto Insights Are In Your Hands
Open