Lido assures LDO, stETH tokens remain safe despite flaw in token contract

Share This Post

The “fake deposit” attack enables bad actors to execute a transfer where the requested value is larger than what the user actually owns.

Ethereum staking protocol Lido Finance has assured both Lido DAO (LDO) and staked-Ether (stETH) tokens remain safe despite hackers allegedly exploiting a known security flaw in LDO’s token contract.

Lido didn’t confirm any exploits, but acknowledged the security flaw was known and reassured LDO and stETH funds remain safe in response to a Sept. 10 post by blockchain security firm SlowMist.

SlowMist said LDO’s flawed token contract allows bad actors to facilitate “fake deposit” attacks on exchanges because LDO’s token contract enables users to execute transactions even where they don’t have sufficient funds. This code deviates from the Ethereum Request for Comment 20 (ERC-20) token standard, according to SlowMist.

However, Lido Finance argued the flaw is built into all ERC-20 tokens — not just Lido’s LDO token:

SlowMist said the “fake deposit” attacks came from LDO’s token contract executing transfers where the value is larger than what the user actually owns, triggering a false return as opposed to reverting the transaction. While the firm said Lido’s token contract has recently been exploited via this attack, no on-chain evidence was provided.

Cointelegraph reached out to SlowMist for comment but did not receive an immediate response.

Meanwhile, on-chain analyst “Hercules” explained on Sept. 10 that the security flaw may not be picked up by cryptocurrency exchanges.

SlowMist recommends LDO holders to also check the return values of the token contract transfers in addition to the success or failure of a transaction.

The blockchain security firm concluded that token contract implementations and behaviors vary by project and to conduct comprehensive testing before integrating any new tokens.

Related: Ethereum staking services agree to 22% limit of all validators

However, Lido highlighted in the official Ethereum Improvement Proposal document — co-authored by Vitalik Buterin in November 2015 — that both the “transfer” and “transferFrom” functions must return the transfer status and are only recommended to revert a transaction in exceptional cases.

To resolve the security flaw, Lido confirmed the LDO token integration guides will soon be updated.

Magazine: DeFi Dad, Hall of Flame: Ethereum is ‘woefully undervalued’ but growing more powerful

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Californian Investor Sues Olympus Peak Over FTX Deal, Alleges Millions Lost

The post Californian Investor Sues Olympus Peak Over FTX Deal, Alleges Millions Lost appeared first on Coinpedia Fintech News A lawsuit has been filed against popular hedge fund Olympus Peak by a

Crypto Whale’s $36 Million Loss Triggers dETH Market Collapse After Phishing Attack

The post Crypto Whale’s $36 Million Loss Triggers dETH Market Collapse After Phishing Attack appeared first on Coinpedia Fintech News In a massive crypto heist, a whale accidentally lost $36

‘XRP Is Not A Security’: Bitnomial Files Lawsuit Against SEC

Bitnomial Exchange, LLC has filed a lawsuit against the US Securities and Exchange Commission (SEC) and its commissioners on October 10, contesting the SEC’s claim that XRP is a security The

Nigerian Fintech Okra Launches Cloud Unit to Boost Revenue

Nigerian fintech startup Okra has entered the cloud infrastructure market in West Africa with its new subsidiary, Nebula The move aims to diversify revenue and mitigate economic risks Nebula offers a

Crypto whale loses $36M in major phishing scam causing DETH depeg

Blockchain security firm Scam Sniffer reported that a crypto whale’s address was drained of 15,079 fwDETH, worth approximately $36 million, in a phishing scam Data from Arkham Intelligence

Fed Uncertainty and Whale Moves Crush Bitcoin Support-Is $57k Next?

The post Fed Uncertainty and Whale Moves Crush Bitcoin Support-Is $57k Next appeared first on Coinpedia Fintech News Bitcoin is again in a tough zone and the whole crypto market is feeling the heat