InfStones, the Lido node operator, withdraws Ethereum validation node and updates keys to prevent security vulnerabilities.
Lido Finance, the main node operator of Lido Finance, recently faced a security issue. After a major vulnerability was disclosed by dWallet Labs, the company decided to take decisive actions: temporarily withdrawing its Ethereum validation nodes and implementing key rotation to address the security threat.
Table of Contents
Toggle
Disclosure of Lido Node Vulnerability and Initial Response
Vulnerabilities and Solutions in the Open Source Repository Tailon
Lido Finance Clarifies: SAFU
Actively Ensuring User Asset Security
InfStones’ Response and Follow-up Actions
In July 2023, dWallet Labs alerted InfStones of a vulnerability in the open-source code repository Tailon. This vulnerability was quickly resolved, leading to a series of preventive security measures being implemented.
Lido Finance is the largest staking protocol on Ethereum, managing over $19 billion worth of ETH. Users participate in the validation nodes managed by the operator network by depositing ETH and receive corresponding derivative tokens.
Lido Finance confirmed that the vulnerability may be related to root-level access and affected 25 verification node servers operated by InfStones. However, Lido emphasized that there are currently no signs of key leakage or abuse. To further safeguard user assets, dWallet Labs recommended key rotation for all potentially affected nodes due to the vulnerability.
InfStones has ensured network integrity and stability. The affected system accounts for less than 0.1% of its overall infrastructure. The company has agreed to voluntarily withdraw its validation nodes and transition to new keys, pending governance approval from Lido Finance. This action aims to ensure the continuous and stable operation of the Ethereum network and protect user assets.
InfStones
Lido
Tailon
Further Reading
Explaining Blur’s Yielding L2 Network Blast: On-chain Native Interest Rates, NFT Perpetual Contracts, etc.
Insufficient Revenue + Development Uncertainty! Lido Proposal to Halt Polygon Mainnet Staking Service.