Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • ADOPTION
  • TRADING
  • HACKING
  • SLOT
  • TRADE
Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • ADOPTION
  • TRADING
  • HACKING
  • SLOT
  • TRADE
Crypto Flexs
Home»HACKING NEWS»Lido stETH on Optimism Audit Summary
HACKING NEWS

Lido stETH on Optimism Audit Summary

By Crypto FlexsJuly 30, 20243 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Lido stETH on Optimism Audit Summary
Share
Facebook Twitter LinkedIn Pinterest Email

Lido Finance, in collaboration with Ackee Blockchain, conducted a security review of the Lido Finance stETH smart contract over a period of 15 engineering days from May 6 to May 17, 2024.

Lido Finance has also expanded the scope to include all contracts in the repository and any changes not reviewed in the previous revision, and Ackee has been awarded an additional time donation of 1.5 engineering days to perform a security review of revision 1.3 between June 17 and June 18, 2024.

methodology

We started our review using the static analysis tool Wake. We then delved deeper into the logic of the contract and used the Wake testing framework for cross-chain fuzzing of the protocol.

We also performed a thorough manual review of the codebase and delved deeply into the logic of the contract. During the review, we paid special attention to:

  • Ensure that access control is neither too lax nor too strict.
  • Integrated validation for the Optimism stack,
  • Ensures that cross-chain architecture and operations are properly secured.
  • Ensures that deposits and withdrawals to L2 do not result in double spending.
  • Ensures that token prices cannot be manipulated.
  • Verify that the system’s arithmetic is correct;
  • I’m looking for general issues like data validation.

range

An audit was performed on the commit. 9d6f66c The exact scope is the following files:

  • contract/lido/TokenRateNotifier.sol
  • Contract/Optimism/CrossDomainEnabled.sol
  • Contract/Optimism/L1ERC20ExtendedTokensBridge.sol
  • Contract/Optimism/L1LidoTokensBridge.sol
  • Contract/Optimism/L2ERC20ExtendedTokensBridge.sol
  • Contract/Optimism/OpStackTokenRatePusher.sol
  • Contract/Optimism/RebasableAndNonRebasableTokens.sol
  • Contract/Optimism/TokenRateOracle.sol
  • Contract/Token/ERC20Bridged.sol
  • Contract/Token/ERC20BridgedPermit.sol
  • Contract/Token/ERC20Core.sol
  • Contract/Token/ERC20Metadata.sol
  • Contract/Token/ERC20RebasableBridged.sol
  • Contract/Token/ERC20RebasableBridgedPermit.sol
  • Contract/Token/PermitExtension.sol

result

Here we present our research findings.

Critical severity

No serious problems were found.

High severity

No high severity issues were found.

Medium severity

No medium severity issues were found.

Low severity

L1: Lack of token ratio precision.

L2: unwrap Inconsistent token amounts across events

Warning Severity

W1: How to use solc Optimizer

W2: ERC-20 transferFrom Release Approval

W3: False comments

W4: Limited ERC-2612 Use Cases with ERC-1271

W5: Use of deprecated functions

W6: Initialization programs can be front-run.

W7: Linear calculation of the deviation of the allowed token ratio

W8: Data validation is lacking

Information Severity

I1: Not cached .length In a for loop

I2: Inconsistent modifier order

I3: Unused code

I4: Typo

I5: _mintShares can go back tokensAmount To save gas

conclusion

Our review yielded 15 findings ranging from low to high severity, the most severe being L1.

Ackee Blockchain recommends Lido Finance as follows:

  • Validates the system’s arithmetic to limit rounding errors.
  • Make sure you have authorization ready for your smart account
  • Implement proper data validation
  • Fix minor issues with documentation and follow best practices and overall code quality.

The full Lido Finance audit report, which includes a more detailed explanation of all findings and recommendations from Ackee Blockchain, can be found here.

We are very pleased to acknowledge Lido Finance and look forward to working with them again in the future.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Encryption Inheritance: Industrial Round Up -January 20125

July 15, 2025

Floki Eyes 120% Rally Valhalla launches $ 10K prizes after explosive weekly growth

July 13, 2025

Watt protocol audit summary -ACKEE blockchain

July 11, 2025
Add A Comment

Comments are closed.

Recent Posts

Encryption Inheritance: Industrial Round Up -January 20125

July 15, 2025

$TAC Token Debuts In TVL As TAC Mainnet Goes Live With Leading DeFi Protocols

July 15, 2025

MultiBank Group Announces 7 Million $MBG Tokens Sold Out In Under One Hour During Initial Pre-Sale

July 15, 2025

Allnodes Among First To Launch Bare Metal Servers Powered By AMD Threadripper 9000 Series

July 15, 2025

Global Cryptocurrency Investors Flock To DNSBTC After Bitcoin Surges

July 15, 2025

The BTC price is withdrawn at almost $ 123K height. XRP approaches the highest resistance ever at $ 3.00.

July 15, 2025

Easily Invest In DL Mining Cloud Mining And Earn $6,000 In Passive Income Every Day

July 15, 2025

Crypto Company is a bank license in the US during Ripple, Circle and Bito Target

July 14, 2025

HeraldEX Defines The Future With Its One-Stop Crypto Platform For Businesses

July 14, 2025

BSGM Engages CXG To Acquire FINRA/SEC-Registered Broker-Dealer To Expand Publicly Traded RWA Tokenization Operations

July 14, 2025

Tornado cash Roman storms insist on Doj Botched Key Telegram evidence.

July 14, 2025

Crypto Flexs is a Professional Cryptocurrency News Platform. Here we will provide you only interesting content, which you will like very much. We’re dedicated to providing you the best of Cryptocurrency. We hope you enjoy our Cryptocurrency News as much as we enjoy offering them to you.

Contact Us : Partner(@)Cryptoflexs.com

Top Insights

Encryption Inheritance: Industrial Round Up -January 20125

July 15, 2025

$TAC Token Debuts In TVL As TAC Mainnet Goes Live With Leading DeFi Protocols

July 15, 2025

MultiBank Group Announces 7 Million $MBG Tokens Sold Out In Under One Hour During Initial Pre-Sale

July 15, 2025
Most Popular

New AI Tokens Maximize Profits with Smart Trading Strategies – Michael Wrubel Video Review

December 27, 2023

AIXA Miner 2025 | AI-Driven Dogecoin Cloud Mining For Stable Daily Passive Income

June 24, 2025

Web3 gaming solution Immutable zkEVM has been released on the QuickNode platform.

January 29, 2024
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
© 2025 Crypto Flexs

Type above and press Enter to search. Press Esc to cancel.