Skip to content
← Back to newsLido DAO Takes Swift Action with Emergency Vote After Oracle Key Compromise
Security

Lido DAO Takes Swift Action with Emergency Vote After Oracle Key Compromise

By ToTo BugelmanNewcomer0 rep· 5/12/2025

Lido DAO has initiated an emergency vote following the compromise of an oracle key managed by Chorus One. This incident, which resulted in a minor loss of funds, has prompted immediate action to ensure the security and integrity of the Lido liquid staking protocol.

 

Lido Finance

 

Key Takeaways

  • An oracle key managed by Chorus One was compromised, leading to a loss of 1.46 ETH.

  • Lido's protocol remains secure, with no impact on user funds or staking operations.

  • An emergency DAO vote has been launched to rotate the compromised oracle key.

  • The incident highlights the importance of robust security measures in decentralized finance.

 

Incident Overview

On May 10, 2025, Lido Finance discovered that a hot wallet associated with one of its oracle keys had been accessed by an unauthorized party. The breach was identified when a contributor noticed an unusually low balance in the wallet, which had been in use since 2021. Although 1.46 ETH was drained, Lido confirmed that the protocol itself remains secure and operational.

Chorus One, the validator operator responsible for the compromised key, clarified that the wallet was not used to store client assets and had always maintained low balances. The incident is believed to have stemmed from a private key leak rather than a breach of the underlying infrastructure.

 

Chorus One

 

Emergency Response Measures

In response to the breach, Lido DAO quickly initiated an emergency vote to rotate the affected oracle key across three contracts:

  1. Accounting Oracle

  2. Validators Exit Bus Oracle

  3. Consensus Layer Fee Oracle

The vote is set to run for 72 hours, followed by a 48-hour objection period, allowing community members to voice any concerns. A new key has already been generated and securely stored using updated security protocols.

 

Resilience of Lido's Oracle System

Lido's oracle system is designed with resilience in mind, utilizing a 5-of-9 quorum mechanism. This means that even if one oracle participant is compromised, the remaining oracles can maintain the integrity of the system. Following the incident, all other oracle addresses were checked and found to be secure, with no signs of further compromise.

 

Ongoing Investigations

Lido and Chorus One are currently conducting a thorough investigation to determine how the private key was exposed and to ensure that no other systems were affected. Preliminary findings indicate that the issue is limited to the single compromised key, and all other oracle software and dependencies are functioning normally.

 

Conclusion

The swift action taken by Lido DAO underscores the importance of governance and redundancy in decentralized systems. As the cryptocurrency landscape continues to evolve, incidents like this highlight the need for robust cybersecurity measures to protect against potential threats. A full post-mortem report will be released once the investigation concludes, providing further insights into the incident and the steps taken to enhance security moving forward.

 

Sources

 

This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.

Lido DAO Takes Swift Action with Emergency Vote After Oracle Key Compromise | BlockzHub