Skip to content

Latest commit

 

History

History
682 lines (468 loc) · 23.7 KB

README.md

File metadata and controls

682 lines (468 loc) · 23.7 KB

Lido Protocol Audits

Lido on Ethereum

12-2020 Sigma Prime Security Assessment

The testing team identified a total of eighteen (18) issues during this assessment, of which:

  • Five (5) are classified as medium risk (4 resolved, 1 closed),
  • Eight (8) are classified as low risk (4 resolved, 3 closed, 1 open),
  • Five (5) are classified as informational (2 resolved, 3 closed).

See full report for more details.

12-2020 Quantstamp Audit

  • Total Issues: 14 (7 Resolved)
  • High Risk Issues: 0 (0 Resolved)
  • Medium Risk Issues: 1 (0 Resolved)
  • Low Risk Issues: 4 (3 Resolved)
  • Informational Risk Issues: 2 (2 Resolved)
  • Undetermined Risk Issues: 7 (2 Resolved)

See full report for more details.

04-2021 MixBytes Audit: ETH2 Oracle

  • Total Issues: 7 (1 Fixed, 6 No issue)
  • Critical Issues: 0
  • Major Issues: 0
  • Warning Issues: 4 (4 No issue)
  • Comment Risk Issues: 3 (1 Fixed, 2 No issue)

See full report for more details.

05-2021 MixBytes Audit: stETH price oracle

  • Total Issues: 7 (4 Fixed, 1 No issue, 2 Acknowledged)
  • Critical Issues: 0
  • Major Issues: 0
  • Warning Issues: 2 (1 Fixed, 1 Acknowledged)
  • Comment Risk Issues: 5 (3 Fixed, 1 No issue, 1 Acknowledged)

See full report for more details.

05-2021 MixBytes Audit: Withdrawals Manager Proxy and Stub

  • Total Issues: 1 (1 Fixed)
  • Critical Issues: 0
  • Major Issues: 0
  • Warning Issues: 0
  • Comment Risk Issues: 1 (1 Fixed)

See full report for more details.

06-2021 MixBytes stETH Price Feed Security Audit

  • Total Issues: 10 (3 Fixed, 6 No issue, 1 Acknowledged)
  • Critical Issues: 0
  • Major Issues: 0
  • Warning Issues: 4 (1 Fixed, 2 No issue, 1 Acknowledged)
  • Comment Risk Issues: 6 (2 Fixed, 4 No issue)

See full report for more details.

07-2021 MixBytes bETH Vault Security Audit

  • Total Issues: 5 (3 Fixed, 2 Acknowledged)
  • Critical Issues: 0
  • Major Issues: 0
  • Warning Issues: 1 (1 Acknowledged)
  • Comment Risk Issues: 4 (3 Fixed, 1 Acknowledged)

See full report for more details.

08-2021 MixBytes bETH Vault Security Audit

bETH Vault was re-audited by MixBytes to incorporate the changes made since the previous audit.

  • Total Issues: 0
  • Critical Issues: 0
  • Major Issues: 0
  • Warning Issues: 0
  • Comment Risk Issues: 0

See full report for more details.

09-2021 MixBytes wstETH Security Audit

  • Total Issues: 5 (3 Acknowledged, 2 No Issue)
  • Critical Issues: 0
  • Major Issues: 0
  • Warning Issues: 5 (3 Acknowledged, 2 No Issue)
  • Comment Risk Issues: 0

See full report for more details.

09-2021 MixBytes Easy Track Security Audit

  • Total Issues: 3 (2 Fixed, 1 No Issue)
  • Critical Issues: 0
  • Major Issues: 0
  • Warning Issues: 2 (2 Fixed)
  • Comment Risk Issues: 1 (1 No Issue)

See full report for more details.

09-2021 MixBytes 1inch Rewards Manager Security Audit

  • Total Issues: 4 (4 Acknowledged)
  • Critical Issues: 0
  • Major Issues: 0
  • Warning Issues: 2 (2 Acknowledged)
  • Comment Risk Issues: 2 (2 Acknowledged)

See full report for more details.

10-2021 MixBytes Aragon Voting Security Audit

The version of the Aragon Voting smart contract with support of the voting time change.

  • Total Issues: 9 (9 Acknowledged)
  • Critical Issues: 0 (0 Fixed)
  • Major Issues: 1 (1 Acknowledged)
  • Warning Issues: 4 (4 Acknowledged)
  • Comment Risk Issues: 4 (4 Acknowledged)

See full report for more details.

10-2021 Sigma Prime Easy Track Smart Contract Security Review

The testing team identified a total of nine (9) issues during this assessment, of which:

  • One (1) is classified as high risk (1 resolved),
  • Three (3) are classified as low risk (3 resolved),
  • Five (5) are classified as informational (3 resolved, 2 closed).

See full report for more details.

01-2022 MixBytes bETH Vault Security Audit Report

bETH Vault was re-audited by MixBytes to incorporate the changes made for the vault to work with Wormhole bridge instead of the Shuttle bridge.

  • Total Issues: 5 (3 Fixed, 2 Acknowledged)
  • Critical Issues: 0
  • Major Issues: 1 (1 Acknowledged)
  • Warning Issues: 4 (4 Acknowledged)
  • Comment Risk Issues: 2 (2 Acknowledged)

See full report for more details.

02-2022 MixBytes AAVE stETH integration Security Audit Report

  • Total Issues: 11 (3 Fixed, 2 Acknowledged)
  • Critical Issues: 0
  • Major Issues: 1 (1 Fixed)
  • Warning Issues: 5 (2 Acknowledged, 3 Fixed)
  • Comment Risk Issues: 5 (1 Acknowledged, 4 Fixed)

See full report for more details.

02-2022 MixBytes In-protocol Coverage Security Audit Report

  • Total Issues: 3 (3 Fixed)
  • Critical Issues: 1 (1 Fixed)
  • Major Issues: 0
  • Warning Issues: 1 (1 Fixed)
  • Comment Risk Issues: 1 (1 Fixed)

See full report for more details.

02-2022 MixBytes Deposit Security Module Security Audit Report

  • Total Issues: 22 (17 Fixed, 5 Acknowledged)
  • Critical Issues: 0
  • Major Issues: 2 (2 Fixed)
  • Warning Issues: 13 (5 Acknowledged, 8 Fixed)
  • Comment Risk Issues: 7 (7 Fixed)

See full report for more details.

05-2022 Oxorio Jumpgate Smart Contracts Security Audit Report

  • Total Issues: 12 (11 Fixed, 1 Acknowledged)
  • Critical Issues: 0
  • Major Issues: 1 (1 Fixed)
  • Warning Issues: 2 (2 Fixed)
  • Comment Risk Issues: 9 (8 Fixed, 1 Acknowledged)

See full report for more details.

05-2022 MixBytes Lido Protocol Security Audit Report

  • Total Issues: 15 (13 Fixed, 2 Acknowledged)
  • Critical Issues: 0
  • High Issues: 1 (1 Fixed)
  • Medium Issues: 7 (6 Fixed, 1 Acknowledged)
  • Low Issues: 7 (6 Fixed, 1 Acknowledged)

See full report for more details.

06-2022 MixBytes Lido Two-Phase Voting Security Audit Report

  • Total Issues: 10 (7 Fixed, 3 Acknowledged)
  • Critical Issues: 0
  • High Issues: 0
  • Medium Issues: 1 (1 Acknowledged)
  • Low Issues: 9 (7 Fixed, 2 Acknowledged)

See full report for more details.

08-2022 ChainSecurity Code Assessment of the Lido Smart Contracts Audit Report

  • Total Issues: 9 (4 Risk accepted, 5 Acknowledged)
  • Critical Issues: 0
  • High Issues: 0
  • Medium Issues: 0
  • Low Issues: 9 (4 Risk accepted, 5 Acknowledged)
  • Notes: 2 (Highlights)

See full report for more details.

08-2022 MixBytes Lido Protocol Security Auditor's Note On The Deployed Code Compliance

See note contents for more details

09-2022 Statemind MEV-Boost relay allowlist Security Audit Report

  • Total Issues: 7 (5 Fixed, 2 Acknowledged)
  • Critical Issues: 0
  • High Issues: 0
  • Medium Issues: 0
  • Informational Issues: 7 (5 Fixed, 2 Acknowledged)

See full report for more details.

09-2022 Statemind Insurance Fund Audit Report

  • Total Issues: 4 (1 Fixed, 3 Acknowledged)
  • Critical Issues: 0
  • High Issues: 0
  • Medium Issues: 0
  • Informational Issues: 4 (1 Fixed, 3 Acknowledged)

See full report for more details.

09-2022 Statemind Easy Track Payment Processor with limits

  • Total Issues: 9 (9 Acknowledged)
  • Critical Issues: 0
  • High Issues: 1 (1 Acknowledged)
  • Medium Issues: 0
  • Informational Issues: 8 (8 Acknowledged)

See full report for more details.

01-2023 Statemind TRP Vesting Escrow Audit Report

  • Total Issues: 5 (4 Fixed, 1 Acknowledged)
  • Critical Issues: 0
  • High Issues: 0
  • Medium Issues: 0
  • Informational Issues: (4 Fixed, 1 Acknowledged)

See full report for more details.

02-2023 ChainSecurity Lido Staking Router Audit Report

  • Total Issues: 13 (10 Fixed, 3 Acknowledged)
  • Critical Issues: 0
  • High Issues: 1 (1 Fixed)
  • Medium Issues: 2 (2 Fixed)
  • Informational Issues: 10 (7 Fixed, 3 Acknowledged)

See full report for more details.

03-2023 Sigma Prime dc4bc Security Audit

  • Total Issues: 8 (8 Fixed)
  • Critical Issues: 0
  • High Issues: 0
  • Medium Issues: 3 (3 Fixed)
  • Low Issues: 2 (2 Fixed)
  • Informational Issues: 3 (3 Fixed)

See full report for more details. The report had been updated on 14 March 2023 with the build hashes of 4.1.0 release.

04-2023 Hexens Lido V2 Smart Contract Audit

  • Total Issues: 25 (16 Fixed, 9 Acknowledged)
  • Critical Issues: 1 (1 Fixed)
  • High Issues: 3 (3 Fixed)
  • Medium Issues: 5 (4 Fixed, 1 Acknowledged)
  • Low Issues: 11 (6 Fixed, 5 Acknowledged)
  • Informational Issues: 5 (2 Fixed, 3 Acknowledged)

See full report for more details.

04-2023 MixBytes Camp Lido V2 Contest

  • Total Issues: 17 (8 Fixed, 9 Acknowledged)
  • Critical Issues: 0
  • High Issues: 1 (1 Acknowledged)
  • Medium Issues: 3 (1 Fixed, 2 Acknowledged)
  • Low Issues: 13 (7 Fixed, 6 Acknowledged)

See full report for more details.

04-2023 Statemind GateSeals Audit

  • Total Issues: 4 (3 Fixed, 1 Acknowledged)
  • Critical Issues: 0
  • High Issues: 1 (1 Fixed)
  • Medium Issues: 0
  • Low Issues: 0
  • Informational Issues: 3 (2 Fixed, 1 Acknowledged)

See full report for more details.

04-2023 Certora Lido V2 Audit

  • Total Issues: 23 (14 Fixed, 9 Acknowledged)
  • Critical Issues: 2 (2 Fixed)
  • High Issues: 5 (1 Fixed, 4 Acknowledged)
  • Medium Issues: 10 (7 Fixed, 3 Acknowledged)
  • Low Issues: 5 (3 Fixed, 2 Acknowledged)
  • Informational Issues: 1 (1 Fixed)

See full report for more details.

04-2023 Statemind Lido V2 Audit

  • Total Issues: 120 (75 Fixed, 45 Acknowledged)
  • Critical Issues: 2 (1 Fixed, 1 Acknowledged)
  • High Issues: 8 (6 Fixed, 2 Acknowledged)
  • Medium Issues: 17 (9 Fixed, 8 Acknowledged)
  • Informational Issues: 93 (59 Fixed, 34 Acknowledged)

See full report for more details.

05-2023 Statemind Lido V2 Upgrade Template Audit

  • Total Issues: 14 (7 Fixed, 7 Acknowledged)
  • Critical Issues: 0
  • High Issues: 0
  • Medium Issues: 0
  • Informational Issues: 14 (7 Fixed, 7 Acknowledged)

See full report for more details.

05-2023 Statemind Lido V2 Deployment Validation Note

See note contents for more details.

05-2023 Hexens Lido V2 Oracle Security Review

  • Total Issues: 2 (2 Fixed)
  • Critical Issues: 0
  • High Issues: 0
  • Medium Issues: 0
  • Low Issues: 1 (1 Fixed)
  • Informational Issues: 1 (1 Fixed)

See full report for more details.

05-2023 Oxorio Lido V2 On-chain Audit

  • Total Issues: 43 (4 Fixed, 37 Acknowledged, 2 No Issue)
  • Critical: 0
  • Major: 7 (7 Acknowledged)
  • Warning: 17 (16 Acknowledged, 1 No Issue)
  • Info: 19 (4 Fixed, 14 Acknowledged, 1 No Issue)

See full report for more details.

05-2023 Oxorio Lido V2 Off-chain Audit

  • Total Issues: 11 (1 Fixed, 10 Acknowledged)
  • Critical: 0
  • Major: 5 (5 Acknowledged)
  • Warning: 2 (1 Fixed, 1 Acknowledged)
  • Info: 4 (4 Acknowledged)

See full report for more details.

10-2023 Statemind Lido roles analysis

Impact severity \ Attack feasibility Low Medium High
Critical 56 5 0
High 71 1 1
Medium 33 12 0
Low 0 6 0
No impact 2 0 0

See full report for more details.

10-2023 Oxorio Lido Easy Track Smart Contracts Security Audit (Easy Track Factories for Stablecoins)

  • Total Issues: 9 (5 Fixed, 4 Acknowledged)
  • Critical: 0
  • Major: 0
  • Warning: 2 (1 Fixed, 1 Acknowledged)
  • Info: 7 (4 Fixed, 3 Acknowledged)

See full report for more details.

12-2023 Pessimistic Lido Stonks Audit

This audit report covers the code up to commit ad6a9e83c095f5052e404bc13585ad2c752f242f. For release version audit please go to 03-2024 Ackee Blockchain Lido Stonks Audit.

  • Total Issues: 8 (4 Fixed, 4 Acknowledged)
  • Critical: 0
  • Medium: 2 (1 Fixed, 1 Acknowledged)
  • Low: 3 (3 Fixed)
  • Notes: 3 (3 Acknowledged)

See full report for more details.

01-2024 Statemind Lido Simple DVT Easy Track Factories Audit

  • Total Issues: 10 (7 Fixed, 3 Acknowledged)
  • Critical: 0
  • High: 0
  • Medium: 0
  • Informational: 10 (7 Fixed, 3 Acknowledged)

See full report for more details.

03-2024 Ackee Blockchain Lido Stonks Audit

  • Total Issues: 9 (7 Fixed, 2 Acknowledged)
  • Critical: 0
  • High: 0
  • Medium: 1 (1 Fixed)
  • Warning 4 (2 Fixed, 2 Acknowledged)
  • Informational: 4 (4 Fixed)

See full report for more details.

04-2024 Statemind GateSeal Deployment Validation Note

See note contents for more details.

06-2024 ChainSecurity Code Assessment of the LIP-23: Rebase Check Smart Contracts

  • Total Issues: 3 (3 Fixed)
  • Critical Issues: 0
  • High Issues: 0
  • Medium Issues: 0
  • Low Issues: 2 (2 Fixed)
  • Info Issues: 1 (1 Fixed)

See full report for more details.

07-2024 Ackee Blockchain Audit of the Simple Delegation

  • Total Issues: 14 (6 Fixed, 8 Acknowledged)
  • High Issues: 0
  • Medium Issues: 0
  • Warning Issues: 10 (3 Fixed, 7 Acknowledged)
  • Info Issues: 4 (3 Fixed, 1 Acknowledged)

See full report for more details.

07-2024 Statemind Audit of the Simple Delegation

  • Total Issues: 6 (2 Fixed, 4 Acknowledged)
  • Critical Issues: 0
  • High Issues: 0
  • Medium Issues: 0
  • Info Issues: 6 (2 Fixed, 4 Acknowledged)

See full report for more details.

07-2024 MixBytes Sanity Checker Security Audit (LIP-23)

  • Total Issues: 8 (4 Fixed, 4 Acknowledged)
  • Critical Issues: 0
  • High Issues: 0
  • Medium Issues: 0
  • Low Issues: 8 (4 Fixed, 4 Acknowledged)

See full report for more details.

10-2024 Ackee Blockchain Audit of Staking Router v2 (LIP-25)

  • Total Issues: 7 (5 Fixed, 2 Acknowledged)
  • Critical Issues: 0
  • High Issues: 0
  • Medium Issues: 0
  • Low Issues: 3 (3 Fixed)
  • Warning Issues: 2 (2 Acknowledged)
  • Info Issues: 2 (2 Fixed)

See full report for more details.

10-2024 Ackee Blockchain Audit of Community Staking Module (LIP-26)

  • Total Issues: 39 (25 Fixed, 2 Partially fixed, 12 Acknowledged)
  • Critical Issues: 0
  • High Issues: 0
  • Medium Issues: 1 (1 Fixed)
  • Low Issues: 8 (5 Fixed, 3 Acknowledged)
  • Warning Issues: 16 (10 Fixed, 1 Partially fixed, 5 Acknowledged)
  • Info Issues: 14 (9 Fixed, 1 Partially fixed, 4 Acknowledged)

See full report for more details.

10-2024 MixBytes On-chain Audit of Community Staking Module (LIP-23, LIP-25, LIP-26)

  • Total Issues: 41 (18 Fixed, 23 Acknowledged)
  • Critical Issues: 0
  • High Issues: 0
  • Medium Issues: 10 (4 Fixed, 6 Acknowledged)
  • Low Issues: 31 (14 Fixed, 17 Acknowledged)

See full report for more details.

10-2024 MixBytes Off-chain Audit of Lido Oracle v4

  • Total Issues: 3 (2 Fixed, 1 Acknowledged)
  • Critical Issues: 0
  • High Issues: 0
  • Medium Issues: 0
  • Low Issues: 3 (2 Fixed, 1 Acknowledged)

See full report for more details.

Lido Multichain audit reports

07-2022 Oxorio Lido L2 Smart Contracts Security Audit Report

  • Total Issues: 9 (6 Fixed, 2 Acknowledged, 1 No Issue)
  • Critical Issues: 1 (1 Acknowledged)
  • Major Issues: 1 (1 Fixed)
  • Warning Issues: 1 (1 Fixed)
  • Info Issues: 6 (4 Fixed, 1 Acknowledged, 1 No Issue)

See full report for more details.

08-2022 Oxorio Governance Crosschain Bridges Smart Contracts Security Audit Report

  • Total Issues: 8 (8 Acknowledged)
  • Critical Issues: 0
  • Major Issues: 0
  • Warning Issues: 2 (2 Acknowledged)
  • Info Issues: 6 (6 Acknowledged)

See full report for more details.

09-2023 Verilog Mantle L2 ERC20 Token Bridge Audit Report

  • Total Issues: 5 (3 Fixed, 2 Acknowledged)
  • High: 0
  • Medium: 0
  • Low: 2 (2 Acknowledged)
  • Informational: 3 (3 Fixed)

See full report for more details.

10-2023 Cantina zkSync Lido Bridge Audit Report

  • Total Issues: 22 (15 Fixed, 3 Acknowledged, 4 No issue)
  • Critical Issues: 1 (1 Fixed)
  • High Issues: 0
  • Medium Issues: 5 (3 Fixed, 2 No Issue)
  • Low Issues: 8 (4 Fixed, 2 No Issue, 2 Acknowledged)
  • Info Issues: 8 (7 Fixed, 1 Acknowledged)

See full report for more details.

10-2023 Diligence Linea Cross‐Chain Governance Executor Audit Report

  • Total Issues: 1 (1 Fixed)
  • Informational: 1 (1 Fixed)

See full report for more details.

12-2023 Diligence Linea Custom Bridged Token Audit Report

  • Total Issues: 0

See full report for more details.

12-2023 OpenZeppelin Linea Bridge Audit Report

NB: the most of the contracts and issues are related not to wstETH bridge but to the entire Linea L2 system.

  • Total Issues: 33 (20 Fixed, 3 Partially fixed)
  • Critical Issues: 1 (1 Fixed)
  • High Issues: 3 (1 Fixed, 2 Acknowledged)
  • Medium Issues: 1 (1 Resolved)
  • Low Issues: 9 (4 Fixed, 1 Partially fixed, 4 Acknowledged)
  • Info Issues: 19 (13 Fixed, 2 Partially fixed, 4 Acknowledged)

See full report for more details.

01-2024 Zellic Scroll Lido Gateway Audit Report

  • Total Issues: 1 (1 No Issue)
  • Info Issues: 1 (1 No Issue)

See full report for more details.

06-2024 Ackee Blockchain stETH on Optimism Audit Report

  • Total Issues: 15 (10 Fixed, 5 Acknowledged)
  • Critical Issues: 0
  • High Issues: 0
  • Medium Issues: 0
  • Low Issues: 2 (2 Fixed)
  • Warning Issues: 8 (4 Fixed, 4 Acknowledged)
  • Info Issues: 5 (4 Fixed, 1 Acknowledged)

See full report for more details.

06-2024 MixBytes stETH on Optimism Audit Report

  • Total Issues: 20 (15 Fixed, 5 Acknowledged)
  • Critical Issues: 0
  • High Issues: 1 (1 Fixed)
  • Medium Issues: 1 (1 Fixed)
  • Low Issues: 18 (13 Fixed, 5 Acknowledged)

See full report for more details.

07-2024 Cantina wstETH on Mode Verification Report

The deployed contracts are verified against the wstETH on Base deployment.

See full report for more details.

07-2024 MixBytes Lido a.DI Audit

  • Total Issues: 13 (13 Acknowledged)
  • Critical Issues: 0
  • High Issues: 0
  • Medium Issues: 2 (2 Acknowledged)
  • Low Issues: 11 (11 Acknowledged)

See full report for more details.

08-2024 Oxorio wstETH on BNB Verification report

The deployed contracts are verified in accordance to the proposal

See full initial and remediated reports for more details.

10-2024 Quantstamp wstETH on Zircuit Verification Report

The deployed contracts are verified against the wstETH on Optimism and Governance crosschain bridges references together with the proposed setup initialization.

See full report for more details.

11-2024 Nethermind Security wstETH on Starknet Deployment Verification

The deployed contracts are verified in accordance to the proposal

See the full report for more details.

Lido on Polygon PoS

04-2022 Lido On Polygon Smart Contracts Security Audit Report for PR#69

  • Total Issues: 9 (4 Fixed, 1 Acknowledged, 1 No Issue)
  • Critical Issues: 0
  • Major Issues: 0
  • Warning Issues: 0
  • Info Issues: 9 (4 Fixed, 1 Acknowledged, 1 No Issue)

See full report for more details.

08-2022 Oxorio Lido on Polygon V2

  • Total Issues: 107 (61 Fixed, 11 Acknowledged, 35 No Issue)
  • Critical Issues: 0
  • Major Issues: 0
  • Warning Issues: 14 (12 Fixed, 2 No Issue)
  • Info Issues: 93 (49 Fixed, 11 Acknowledged, 33 No Issue)

See full report for more details.