By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
KriptotekaKriptoteka
  • Home
  • News
    • Web3
    • Crypto News
    • Market Analysis
  • Market
    • AI
    • Altcoins
    • Bitcoin
    • Blockchain
    • CEX
    • Defi
    • DePIN
    • DEX
    • ETFs
    • Ethereum
    • Gaming
    • ICO/IDO
    • Institutions
    • L1&L2
    • Meme
    • NFT tech
    • RWA
    • Stable coins
  • Data
  • Events
  • Learn
  • Reports
  • Podcasts
  • Pro membership
Reading: Lido stETH Audit Summary by Ackee Blockchain on Optimism
Share
Notification Show More
Font ResizerAa
Font ResizerAa
KriptotekaKriptoteka
  • Home
  • News
  • Market
  • Data
  • Events
  • Learn
  • Reports
  • Podcasts
  • Pro membership
  • Home
  • News
    • Web3
    • Crypto News
    • Market Analysis
  • Market
    • AI
    • Altcoins
    • Bitcoin
    • Blockchain
    • CEX
    • Defi
    • DePIN
    • DEX
    • ETFs
    • Ethereum
    • Gaming
    • ICO/IDO
    • Institutions
    • L1&L2
    • Meme
    • NFT tech
    • RWA
    • Stable coins
  • Data
  • Events
  • Learn
  • Reports
  • Podcasts
  • Pro membership
Have an existing account? Sign In
Follow US
  • Advertise
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Kriptoteka > Market > Blockchain > Lido stETH Audit Summary by Ackee Blockchain on Optimism
Blockchain

Lido stETH Audit Summary by Ackee Blockchain on Optimism

marcel.mihalic@gmail.com
Last updated: September 15, 2024 9:19 am
By marcel.mihalic@gmail.com 3 Min Read
Share
SHARE

Lido Finance collaborated with Ackee Blockchain to conduct a security assessment of the stETH smart contracts, utilizing a total of 15 engineering days of time donated between May 6 and May 17, 2024.

Additionally, Lido Finance broadened the review scope to encompass all contracts in the repository and any modifications that had not been examined in earlier assessments. Ackee further received 1.5 engineering days as an additional time donation to review the security of revision 1.3 from June 17 to June 18, 2024.

METHODOLOGY

Our review commenced with static analysis utilizing tools such as Wake. We also delved deeply into the contracts’ logic and employed the Wake testing framework for cross-chain fuzz testing of the protocol.

A comprehensive manual analysis of the codebase was also performed, emphasizing the contracts’ logic. During the evaluation, we focused particularly on:

  • ensuring access controls are neither overly permissive nor excessively stringent,
  • verifying integration within the Optimism stack,
  • securing the cross-chain architecture and operations effectively,
  • confirming that deposits and withdrawals to and from L2 don’t allow double spending,
  • ensuring the token rate is immune to manipulation,
  • verifying the accuracy of the system’s arithmetic,
  • and identifying common issues such as data validation problems.

SCOPE

The audit was conducted on the commit 9d6f66c, encompassing the following files:

  • contracts/lido/TokenRateNotifier.sol
  • contracts/optimism/CrossDomainEnabled.sol
  • contracts/optimism/L1ERC20ExtendedTokensBridge.sol
  • contracts/optimism/L1LidoTokensBridge.sol
  • contracts/optimism/L2ERC20ExtendedTokensBridge.sol
  • contracts/optimism/OpStackTokenRatePusher.sol
  • contracts/optimism/RebasableAndNonRebasableTokens.sol
  • contracts/optimism/TokenRateOracle.sol
  • contracts/token/ERC20Bridged.sol
  • contracts/token/ERC20BridgedPermit.sol
  • contracts/token/ERC20Core.sol
  • contracts/token/ERC20Metadata.sol
  • contracts/token/ERC20RebasableBridged.sol
  • contracts/token/ERC20RebasableBridgedPermit.sol
  • contracts/token/PermitExtension.sol

FINDINGS

Below are our findings from the audit.

Critical severity

No critical severity issues were identified.

High severity

No high severity issues were identified.

Medium severity

No medium severity issues were identified.

Low severity

L1: Token rate precision is insufficient

L2: unwrap tokens amount in event is inconsistent

Warning severity

W1: Implementation of solc optimizer

W2: ERC-20 transferFrom triggers Approval

W3: Incorrect comments

W4: Limited use case for ERC-2612 with ERC-1271

W5: Use of deprecated function

W6: Initializers are vulnerable to front-running

W7: Linear calculation of allowed token rate deviation

W8: Inadequate data validation

Information severity

I1: Uncached .length in for loop

I2: Inconsistent order of modifiers

I3: Redundant code

I4: Typographical errors

I5: _mintShares can return tokensAmount to reduce gas usage

CONCLUSION

Our audit yielded 15 findings, ranging from Information to Low severity, with L1 being the most severe.

 

Ackee Blockchain advises Lido Finance to:

  • verify the arithmetic to minimize rounding errors
  • ensure that permits are compatible with smart accounts
  • carry out thorough data validation
  • correct minor issues with documentation, adhering to best practices and improving overall code quality

 

The complete Lido Finance audit report by Ackee Blockchain, including a detailed overview of all findings and recommendations, is available here.

 

We were pleased to conduct the audit for Lido Finance and look forward to future collaborations.

You Might Also Like

Coinbase CEO Proposes Crypto Wallet for AI Behind GOAT Meme Coin

Honduras & Colombia Local Grants Overview and Highlights

Rhinestone ERC-7579 Adapter Audit Summary and Findings Report

Victims file $235M class-action suit against WazirX for hack

Tether and Lugano Reveal Satoshi Nakamoto Statue at Forum

Share This Article
Facebook Twitter Email Print
Previous Article Top Crypto Gainers – Theta Fuel, Oasis Network, ArcBlock, Unizen[embed]https://www.youtube.com/watch?v=FKeI_9oNu84[/embed]
Next Article Bitcoin Rally Expected as Price Eyes Break Above $69,500
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

FacebookLike
TwitterFollow
YoutubeSubscribe
TelegramFollow
- Advertisement -
Ad image

Latest News

4 Cryptos to Challenge Solana: Potential Growth for Investors
Defi
Bitcoin ETF Inflows Exceed $3B, Demand Reaches 6-Month Peak
ETFs
Japan’s Push for Bitcoin and Ethereum ETFs Gains Momentum
Institutions
Ripple Appeals Court Ruling on XRP’s Institutional Sales
Meme
//

We influence millions of users and is the number one Crypto and Web3 news network on the planet

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
nl Dutchen Englishfr Frenchde Germanel Greekit Italianpt Portugueseru Russianes Spanish
en en
Join Us!

Subscribe to our newsletter and never miss our latest news, podcasts etc..

Zero spam, Unsubscribe at any time.
Welcome Back!

Sign in to your account

Lost your password?