Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
Home»HACKING NEWS»Everstake lump sum deposit contract audit
HACKING NEWS

Everstake lump sum deposit contract audit

By Crypto FlexsJanuary 23, 20264 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Everstake lump sum deposit contract audit
Share
Facebook Twitter LinkedIn Pinterest Email

Everstake is a blockchain infrastructure provider that operates validators across multiple networks. The ETH2 Block Deposit Contract allows multiple validator deposits to be consolidated into a single transaction and atomically delivered to the official ETH2 Deposit Contract.

Everstake partnered with Ackee Blockchain Security and donated a total of 2 days of engineering time between November 11 and November 14, 2025 to conduct a security review of the Everstake ETH2 Block Deposit Contract.

Everstake then worked with Ackee Blockchain Security to conduct a revision review of the results of previous revisions.

methodology

  1. Technical specifications verification
    The scope of the audit is confirmed with the client and the auditor joins the project. Review the provided documentation and compare it to your audit system.
  2. Tool-based analysis
    In-depth scanning using the Solidity static analysis tool Wake, along with the Solidity (Wake) extension, is performed to flag potential vulnerabilities for further analysis early in the process.
  3. Manual code review
    Auditors manually check code line by line to identify vulnerabilities and code quality issues. The main focus is recognizing potential edge cases and project-specific risks.
  4. Local deployment and hacking
    The contract is deployed to the local Wake environment where targeted attempts to exploit the vulnerability are made. The resilience of the contract against various attack vectors is evaluated.
  5. Unit and fuzzy testing
    Unit tests are run to verify expected system behavior. Once coverage gaps are identified, you can write additional unit or fuzz tests using the Wake framework. The goal is to verify the stability of the system under real-world conditions and ensure robustness to expected and unexpected inputs.
  6. Wake-AI support vulnerability discovered
    The final step involves checking coverage against Wake AI, an LLM-based audit tool, to identify potentially missed vulnerabilities. This step is executed at the end of the audit process to avoid interfering with the auditor’s own review.

We began our review using static analysis tools, including Wake. We then performed a thorough manual review of the code, focusing particularly on integration with the canonical ETH2 deposit contract. During the review process, we paid special attention to the following:

  • Ensures that gripping or forward attacks are impossible.
  • Ensures interactions with external contracts are implemented correctly.
  • Ensures compatibility with the latest Ethereum protocol updates.
  • Verify that the system’s calculations are correct.
  • I’m looking for common problems like data validation.

At the end of our review, we discovered issue I2 using Wake AI.

range

An audit has been performed on the commit. c2c12ba(1) In the contract repository, the scope is:

  • contracts/ETH2BatchDepositConsolidation.sol

In-scope agreements were also distributed. 0x4ff41fa0f4e77129c4c0607994050473c2067e6d Mainnet address.

Findings

The classification of security findings is determined by two subscales: Impact and Probability. This two-dimensional rating provides a more noise-free view of the severity of the problem without loss of information. The probability factor reduces the severity of intermediate issues that the team typically recognizes as information and warnings.

Here are the results of our review: 2 items found Information Severity:

critical severity

No critical severity issues were found.

Severity High

No high severity issues were found.

medium severity

No medium severity issues were found.

low severity

No low-severity issues were found.

warning severity

Warning Severity No issues were found.

Information Severity

I1: Limited deposit verification

I2: Missing confirmation of accumulated deposit amount

trust model

This contract is permissionless and does not introduce any additional trust assumptions beyond the official ETH2 deposit contract.

conclusion

Ackee Blockchain Security recommended Everstake:

    • Investigate the findings and severity of the problem.
    • Read and review the entire audit report. and
    • Address any identified issues.

Ackee Blockchain Security’s full Everstake ETH2 Block Deposit Contract audit report can be found here.

We were delighted to appreciate Everstake and look forward to working with them again.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

The fake MetaMask 2FA phishing scam uses a sophisticated design to steal your wallet seed phrase.

February 12, 2026

Altcoin of the Day: Grayscale’s LINK ETF Debuts. HYPE and ASTER soar up to 13%

February 10, 2026

Kamino Lend Fuzz Test Summary

February 8, 2026
Add A Comment

Comments are closed.

Recent Posts

Zerion Opens Enterprise Wallet Data API To All Developers

February 13, 2026

transaction – How to programmatically determine which Tx consumed an OutPoint

February 12, 2026

The fake MetaMask 2FA phishing scam uses a sophisticated design to steal your wallet seed phrase.

February 12, 2026

Dogecoin (DOGE) downtrend, market awaits signal of trend change

February 12, 2026

Phemex Astral Trading League (PATL) Goes Live, Building A Sustainable Seasonal Trading Progression System

February 12, 2026

Cango Inc. Closed The US$10.5 Million Equity Investment And Secured US$65 Million Additional Equity Investments

February 12, 2026

Best Cryptocurrency Marketing Agency: Outset PR Earns Industry Recognition for Data-Driven Approach

February 12, 2026

Flipster FZE Secures In-Principle Approval From VARA, Reinforcing Commitment To Regulated Crypto Access

February 12, 2026

BYDFi Joins Solana Accelerate APAC At Consensus Hong Kong, Expanding Solana Ecosystem Engagement

February 12, 2026

Why the on-chain AI agent economy hasn’t taken off yet

February 12, 2026

P2P Bitcoin marketplace Paxful sentenced for promoting illegal prostitution and money laundering

February 12, 2026

Crypto Flexs is a Professional Cryptocurrency News Platform. Here we will provide you only interesting content, which you will like very much. We’re dedicated to providing you the best of Cryptocurrency. We hope you enjoy our Cryptocurrency News as much as we enjoy offering them to you.

Contact Us : Partner(@)Cryptoflexs.com

Top Insights

Zerion Opens Enterprise Wallet Data API To All Developers

February 13, 2026

transaction – How to programmatically determine which Tx consumed an OutPoint

February 12, 2026

The fake MetaMask 2FA phishing scam uses a sophisticated design to steal your wallet seed phrase.

February 12, 2026
Most Popular

The FTX cleared $ 1.5B with 3AC assets two weeks before the collapse of the hedge fund.

March 14, 2025

Is It Too Late To Buy GROK?: Grok Price Soars 10% As This 2.0 Meme Coin Offers Last Opportunity To Buy

May 2, 2024

Bitcoin’s booming ‘permanent holder demand’ position BTC price $ 116K.

February 10, 2025
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
© 2026 Crypto Flexs

Type above and press Enter to search. Press Esc to cancel.