Multi-User Staking with Additional Yield via Lido EarnETH
Product value propositionβ
An end-user staking product with a higher risk/yield profile achieved by depositing stETH minted from the stVault into the Lido EarnETH strategy, with a user-friendly interface that can be embedded into your own or a partnerβs distribution channel.
Product characteristicsβ
| Parameter | Value |
|---|---|
| Number of stakers | Multiple |
| stETH minting capability | Yes, to deposit into Lido EarnETH and generate additional yield |
Building blocksβ
| Building block | Solution | Implementation |
|---|---|---|
| Basis | stVault | Out-of-the-box |
| Pooling Wrapper | DeFi Wrapper | Out-of-the-box |
| Connector to DeFi Strategy | Connector to Lido EarnETH | Out-of-the-box |
| User Interface | DeFi Wrapper Embeddable Widget / Custom | Out-of-the-box / Custom |
What is DeFi Wrapper?β
The DeFi Wrapper is a no-/low-code toolkit that lets builders, Node Operators, and platforms launch customized user-facing staking products powered by stVaults β with optional automated APR-boosting strategies such as leverage loops or any custom stETH-based yield module.
This guide walks through the concepts and practical steps to launch such a product without deep protocol knowledge.
Architectureβ

Stepsβ
β‘οΈ URLs and Smart Contract addresses are listed on Environments
1. Create a tokenized staking vault (pool)β
The easiest way to create a tokenized staking vault (pool) is to use the stVaults CLI.
It's a command-line tool for managing both staking vaults and DeFi Wrapper pools. It deploys a pool plus its underlying staking vault via the Factory contract.
The CLI performs the deployment in two transactions to stay within the current 16M transaction gas limit.
To start:
- Set up the CLI according to the README.
- Prepare a valid CLI configuration β see the configuration tutorial.
The deployer must have at least 1 ETH available. This is the CONNECT_DEPOSIT required to be locked on the stVault upon connection to Lido VaultHub.
The newly created staking vault is automatically connected to Lido VaultHub and placed into the default tier. Placement into non-default tiers right upon deployment is not supported.
To list the available pool types and creation commands, run:
yarn start defi-wrapper contracts factory write -h
For each pool type, the CLI prints the environment variables required for the UI setup. Keep this output if you plan to set up the UI.
Deployment of StvStrategyPool with the Lido Earn ETH strategyβ
The pool with the Lido Earn ETH strategy: ETH is deposited to validators and generates staking rewards, stETH is minted, wrapped into wstETH and automatically deposited to the Earn ETH strategy to earn additional rewards. Deposited wstETH is distributed across a curated set of high-performing DeFi strategies, including lending markets and LP positions. The Earn ETH strategy is built on Mellow architecture, so the strategy connector is called "MellowStrategy", and the factory is called "MellowStrategyFactory".
To deploy this pool, use the create-strategy-pool-lido-earn-eth. The factory addresses for each network are listed in the Environments section. The full parameter reference is available below.
Start the deployment like:
yarn start defi-wrapper contracts factory w create-strategy-pool-lido-earn-eth <DEFI_WRAPPER_FACTORY> <STRATEGY_FACTORY_ADDRESS> \
--nodeOperator <NODE_OPERATOR_ADDRESS> \
--nodeOperatorManager <NODE_OPERATOR_MANAGER_ADDRESS> \
--nodeOperatorFeeRateBP 10 \
--confirmExpiry 86400 \
--minDelaySeconds 3600 \
--minWithdrawalDelayTime 3600 \
--name "Earn ETH Pool" \
--symbol STV \
--proposer <PROPOSER_ADDRESS> \
--executor <EXECUTOR_ADDRESS> \
--emergencyCommittee <EMERGENCY_COMMITTEE_ADDRESS> \
--reserveRatioGapBP 250
You can use --allowList true to enable the deposit allowlist for this strategy. AllowList Manager role on Strategy must be set separately by TimeLock governance.
AllowList will be always enabled on the StvStETHPool contract. This allowlist ensures only the strategy contract can deposit into the pool, and minting is required to produce wstETH for the Earn ETH Vault. Strategy contract has its own allow list.
Parameter reference
| Parameter | Description |
|---|---|
<DEFI_WRAPPER_FACTORY> | DeFi Wrapper Factory contract address (see Environments) |
<STRATEGY_FACTORY_ADDRESS> | Lido Earn ETH Strategy Factory contract address (see Environments) |
--nodeOperator | Address of the Node Operator managing validators |
--nodeOperatorManager | Address authorized to manage Node Operator settings |
--nodeOperatorFeeRateBP | Node Operator fee in basis points (10 = 0.1%) |
--confirmExpiry | Confirmation timeout in seconds (whole hours; min 24 hours on Mainnet, 1 hour on testnets, max 30 days) |
--minDelaySeconds | TimeLock minimum delay before execution (whole hours, max 30 days) |
--minWithdrawalDelayTime | Minimum delay before withdrawals can be finalized (whole hours, min 1 hour, max 30 days) |
--name | ERC-20 pool share token name (3β14 characters) |
--symbol | ERC-20 pool share token symbol (3β8 characters) |
--proposer | Address authorized to propose TimeLock operations |
--executor | Address authorized to execute TimeLock operations |
--emergencyCommittee | Address that can pause pool operations |
--reserveRatioGapBP | Reserve ratio gap in basis points (recommended min: 250) |
Managing AllowList for StvStrategyPool with Lido Earn ETH strategyβ
Due to design the allow list for StvStrategyPool is always on and is limited only to the strategies contracts attached to the pool. The strategy contract(if enabled by --allowList true) has its own allow list. To manage the Strategy allow list, use the following CLI commands:
yarn start defi-wrapper use-cases wrapper-operations read info <poolAddress>to check the current strategy address attached to the poolyarn start defi-wrapper use-cases timelock-governance common read get-timelock-address <poolAddress>to get the timelock address for the poolyarn start defi-wrapper use-cases wrapper-operations read allow-list <strategyAddress>to check the current allow list state for the strategyyarn start defi-wrapper use-cases timelock-governance strategy write propose-grant-role <timelockAddress> <strategyAddress> ALLOW_LIST_MANAGER_ROLE <managerAddress>AS PROPOSER to propose adding a manager to the strategy allow listyarn start defi-wrapper use-cases timelock-governance strategy write execute-grant-role <timelockAddress> <strategyAddress> ALLOW_LIST_MANAGER_ROLE <managerAddress>AS EXECUTOR to execute adding a manager to the strategy allow list after the timelock delay has passedyarn start defi-wrapper use-cases wrapper-operations read allow-list <strategyAddress>to verify that state was updatedyarn start defi-wrapper use-cases wrapper-operations write allow-list-add/allow-list-remove <strategyAddress> <addressesToAddOrRemove>as holder of ALLOW_LIST_MANAGER_ROLE to add or remove an address from the strategy allow list
2. Create Web UIβ
Follow this guide to:
- Clone the provided repository
- Use addresses outputted by CLI to fill up
.env - Adjust titles, logos, texts, and color scheme to your liking
- Deploy the dApp
Adjust stETH minting parametersβ
By default, a newly created stVault is connected to the Default tier with a Reserve Ratio of 50%. If the Node Operator has passed identification and been granted individual tiers, the stVault can be moved from the Default tier to one of the Node Operatorβs tiers to access better stETH minting conditions.
For more information about how this process works for the Basic stVault, please follow Adjust stETH minting parameters.
For stVaults with DeFi Wrapper the process of changing tier is a bit different because the Vault Owner role is assigned to the Timelock contract. The Timelock contract itself implements a two-step process for performing an on-chain action. First, the holder of its proposer role creates a proposed on-chain action; second, after a time period, the holder of the executor role executes it.
Thus, changing tier for a pooled vault is a three-step process:
- Holder of the Timelock's proposer role calls
TimelockController.scheduleto propose theDashboard.changeTiercall - After the timelock period, the holder of the Timelock's executor role calls
TimelockController.executefor the scheduled proposal - Within the
OperatorGridconfirmation expiry (currently 24 hours), the Node Operator confirms from their side by callingOperatorGrid.changeTier(vault, tierId, requestedShareLimit)β the same tier and share limit, but through a different contract and with the stVault as an extra argument
Confirming tier change request requires applying fresh report to vault. Read more about applying reports
Parameters needed for this step:
VaultAddress: the address of theVaultcontract.TierID: the ID of the tier to which the stVault will be connected.RequestedShareLimit: the requested absolute stETH minting limit for the stVault, expressed in shares. This value cannot exceed the tier's stETH limit.TimelockAddress: the address of theTimelockControllercontract (deployed together with the pool).OperatorGridAddress: the address of theOperatorGridcontract (available in the stVaults contract addresses list, see Environments).
How to determine available tier IDs for your Node Operator
To find out which tier IDs are available for your Node Operator, you can use:
CLI:
# Get group information for your Node Operator (shows all available tier IDs)
yarn start contracts operator-grid r group <nodeOperatorAddress>
# Get information about a specific tier
yarn start contracts operator-grid r tier <tierId>
Contract call (Etherscan):
- Navigate to the
OperatorGridcontract address - Go to Contract β Read Contract
- Call
group(nodeOperatorAddress)to get theGroupstruct, which includes thetierIdsarray - Call
tier(tierId)to get details about a specific tier
The group method returns a struct containing:
operator: Node operator addressshareLimit: Maximum liability shares across all group vaultsliabilityShares: Current liability shares in the grouptierIds: Array of tier IDs belonging to this Node Operator
Step 1: Schedule the tier change (Proposer)
CLIβ
Use --wallet-connect option for all commands or provide private key to CLI .env
- Get address of your timelock contract:
yarn start defi-wrapper use-cases timelock-governance common read get-timelock-address <poolAddress> - Connect wallet that holds the proposer role to CLI
- Propose change tier
yarn start defi-wrapper use-cases timelock-governance dashboard write propose-change-tier <timelockAddress> <dashboard> <tierId> <shareLimit>
Etherscanβ
- Open Etherscan and navigate to the TimelockController contract β find its address on the Per-setup addresses page.
- Go to the Contract tab β Write Contract.
- Click Connect to Web3 and connect the wallet that holds the proposer role.
- Find the
schedulemethod in the list and fill out the fields:target: theDashboardcontract address.value:0(no ETH is sent with this call).data: the ABI-encoded call tochangeTier(uint256 tierId, uint256 requestedShareLimit). You can generate this using tools like ABI Encoder or cast from Foundry:cast calldata "changeTier(uint256,uint256)" <TierID> <RequestedShareLimit>predecessor:0x0000000000000000000000000000000000000000000000000000000000000000(no predecessor required).salt:0x0000000000000000000000000000000000000000000000000000000000000000(or any unique value if you need to differentiate identical operations).delay: the delay in seconds (must be at least theminDelaySecondsconfigured during pool deployment).
- Click Write and sign the transaction in your wallet.
- Click View your transaction and wait for it to be executed.
- Note down the operation ID from the
CallScheduledevent in the transaction logs β you will need it to verify the operation status before execution.
Step 2: Execute the scheduled tier change (Executor)
CLIβ
-
Check the timelock delay period:
# Get timelock address
yarn start defi-wrapper use-cases timelock-governance common read get-timelock-address <poolAddress>
# Then get the minimum delay (replace <timelockAddress> with the address from previous command)
yarn start defi-wrapper use-cases timelock-governance common read get-min-delay <timelockAddress> -
Wait for the timelock delay period to pass. You can verify the operation is ready by calling
yarn start defi-wrapper use-cases timelock-governance common read get-last-operations <timelockAddress> -
Connect wallet that holds the executor role to CLI
-
Execute change tier
yarn start defi-wrapper use-cases timelock-governance dashboard write execute-change-tier <timelockAddress> <dashboard> <tierId> <shareLimit>
Etherscanβ
-
Check the timelock delay period:
- Open Etherscan and navigate to the TimelockController contract β find its address on the Per-setup addresses page.
- Go to the Contract tab β Read Contract.
- Find the
getMinDelaymethod and click Query to see the minimum delay in seconds.
-
Wait for the timelock delay period to pass. You can verify the operation is ready by calling
isOperationReady(operationId)on the TimelockController contract (in Read Contract tab). -
Execute change tier, connect the wallet:
- Open Etherscan and navigate to the TimelockController contract β find its address on the Per-setup addresses page.
- Go to the Contract tab β Write Contract.
- Click Connect to Web3 and connect the wallet that holds the executor role.
-
Find the
executemethod in the list and fill out the fields with the same values used in theschedulecall:target: theDashboardcontract address.value:0.payload: the same ABI-encoded call data used in step 1.predecessor:0x0000000000000000000000000000000000000000000000000000000000000000.salt: the same salt value used in step 1.
-
Click Write and sign the transaction in your wallet.
-
Click View your transaction and wait for it to be executed.
Step 3: Confirm the tier change (Node Operator)
Within the OperatorGrid confirmation expiry (currently 24 hours) after step 2, the Node Operator must confirm the tier change:
stVaults UIβ
- Go to
https://stvaults.lido.fi/vaults/[vaultAddress]/settings/tier - Connect wallet that has Node operator address
- Follow UI to confirm tier change
CLIβ
- Connect wallet that has Node operator address to CLI
yarn start vo w change-tier-by-no -v <vaultAddress> -r <requestedShareLimit> <tierId>
Etherscanβ
- Open Etherscan and navigate to the OperatorGrid contract by its address (available in the stVaults contract addresses list, see Environments).
- Since this contract is a proxy, complete the verification steps once (if not done before):
- Go to Contract β Code.
- Click More options.
- Select Is this a proxy?.
- Click Verify in the dialog.
- Return to the contract details page.
- Open the Contract tab β Write as Proxy.
- Click Connect to Web3 and connect the wallet registered as the Node Operator.
- Find the
changeTiermethod in the list and fill out the fields with the same values used in steps 1 and 2:vault: theVaultcontract address.tierId: the tier ID.requestedShareLimit: the requested share limit.
- Click Write and sign the transaction in your wallet.
- Click View your transaction and wait for it to be executed.