Skip to main content

Security Disclosures

A reverse-chronological (most recent first) record of security-related disclosures and post-mortem reports published by Lido. For details on impact, root cause, and resolution, refer to the linked reports. Dates reflect when the report was published. Disclosures and outage reports related to node operators can be found on research.lido.fi.

DateTypeSeverityTitleLinks
2026-03-23Bug BountyLowBatched Immunefi-reported Weakness DisclosureForum
2025-08-01Bug BountyHighCSVerifier Weak Validation of Historical Block GIndexForum
2025-07-21Bug BountyModerateDG Weakness Reported Through ImmunefiForum
2025-07-01Bug BountyLowNOR / SDVT Recovery-Lever WeaknessForum
2025-05-11IncidentHighChorus One Oracle Compromise (Emergency Rotation)Forum
2023-07-05IncidentLowDelayed Oracle ReportBlog
2023-01-24IncidentHighbETH Anchor Integration IncidentBlog ยท Forum
2023-01-03IncidentLowMissed Oracle Reports / Rewards DelayBlog
2022-03-01Bug BountyCriticalUI Code Injection VulnerabilityBlog
2021-10-06Bug BountyHighDeposit Contract VulnerabilityBlog ยท Forum ยท Medium

Severity levels: Critical โ€” potential loss of staker funds or critical system compromise. High โ€” significant impact, may affect funds under specific conditions. Moderate โ€” limited impact, staker funds not at risk. Low โ€” minimal impact, informational or theoretical.

Last updated: 24 Mar 2026