{"id":153322,"date":"2023-09-11T07:25:41","date_gmt":"2023-09-11T01:55:41","guid":{"rendered":"https:\/\/dripp.zone\/news\/?p=153322"},"modified":"2023-09-11T07:25:41","modified_gmt":"2023-09-11T01:55:41","slug":"lido-assures-ldo-steth-tokens-remain-safe-despite-flaw-in-token-contract-crypto-news","status":"publish","type":"post","link":"https:\/\/dripp.zone\/news\/lido-assures-ldo-steth-tokens-remain-safe-despite-flaw-in-token-contract-crypto-news\/","title":{"rendered":"Lido assures LDO, stETH tokens remain safe despite flaw in token contract &#8211; Crypto News"},"content":{"rendered":"<div data-v-398ae7b2=\"\">\n<p>Ethereum staking protocol Lido Finance has assured both Lido DAO <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cointelegraph.com\/lido-dao-ldo-price-index\">(LDO)<\/a> and staked-Ether (stETH) tokens remain safe despite hackers allegedly exploiting a known security flaw in LDO\u2019s token contract.<\/p>\n<p>Lido didn\u2019t <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/LidoFinance\/status\/1700888072299462895\">confirm<\/a> any exploits, but acknowledged the security flaw was known and reassured LDO and <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/500k-worth-of-steth-redeemed-in-3-hours-as-lido-enables-withdrawals\">stETH funds remain safe<\/a> in response to a Sept. 10 post by blockchain security firm SlowMist.<\/p>\n<p>SlowMist said LDO\u2019s flawed token contract allows bad actors to facilitate \u201cfake deposit\u201d attacks on exchanges because LDO\u2019s token contract enables users to execute transactions even where they don\u2019t have sufficient funds. This code deviates from the <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cointelegraph.com\/explained\/erc-20-tokens-explained\">Ethereum Request for Comment 20<\/a> (ERC-20) token standard, according to SlowMist.<\/p>\n<p>However, Lido Finance argued the flaw is built into all ERC-20 tokens \u2014 not just Lido\u2019s LDO token:<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">This behaviour is expected and conforms to the ERC20 token standard (see tweet below). Both LDO and stETH (and Lido governance) remain safe. <\/p>\n<p>Lido token integration guides will be updated with LDO specifics to make this more visible shortly.<\/p>\n<p>\u2014 Lido (@LidoFinance) <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/LidoFinance\/status\/1700888072299462895?ref_src=twsrc%5Etfw\">September 10, 2023<\/a><\/p><\/blockquote>\n<p>SlowMist said the \u201cfake deposit\u201d attacks came from LDO\u2019s token contract executing transfers where the value is larger than what the user actually owns, triggering a false return as opposed to reverting the transaction. While the firm said Lido&#8217;s token contract has recently been exploited via this attack, no on-chain evidence was provided.<\/p>\n<p>Cointelegraph reached out to SlowMist for comment but did not receive an immediate response.<\/p>\n<p>Meanwhile, on-chain analyst \u201cHercules\u201d <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/Hercules_Defi\/status\/1700977359632191869\">explained<\/a> on Sept. 10 that the security flaw may not be picked up by cryptocurrency exchanges.<\/p>\n<p>SlowMist recommends LDO holders to also check the return values of the token contract transfers in addition to the success or failure of a transaction.<\/p>\n<p>The blockchain security firm <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/SlowMist_Team\/status\/1700782739950289070\">concluded<\/a> that token contract implementations and behaviors vary by project and to conduct comprehensive testing before integrating any new tokens.<\/p>\n<p><strong><em>Related: <\/em><\/strong><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/ethereum-staking-services-agree-self-limit-validators\"><strong><em>Ethereum staking services agree to 22% limit of all validators <\/em><\/strong><\/a><\/p>\n<p>However, Lido highlighted in the official <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/erc-20-inventor-discusses-origins-new-blockchains-brc-20\">Ethereum Improvement Proposal document<\/a> \u2014 co-authored by Vitalik Buterin in November 2015 \u2014 that both the \u201ctransfer\u201d and \u201ctransferFrom\u201d functions must return the transfer status and are only recommended to revert a transaction in exceptional cases.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">ERC20 token standard: <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/t.co\/YlrS1ZN6Fd\">https:\/\/t.co\/YlrS1ZN6Fd<\/a><\/p>\n<p>1) Both transfer and transferFrom are required to return transfer status and are only recommended to revert a tx in exceptional cases.<\/p>\n<p>2) The standard says that a caller is obliged to check the return status (see &#8216;Token methods&#8217;). <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/t.co\/6KTcIyxo2F\">pic.twitter.com\/6KTcIyxo2F<\/a><\/p>\n<p>\u2014 Lido (@LidoFinance) <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/LidoFinance\/status\/1700888476571611139?ref_src=twsrc%5Etfw\">September 10, 2023<\/a><\/p><\/blockquote>\n<p>To resolve the security flaw, Lido <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/LidoFinance\/status\/1700888072299462895\">confirmed<\/a> the LDO token integration guides will soon be updated.<\/p>\n<p><strong><em>Magazine: <\/em><\/strong><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cointelegraph.com\/magazine\/ethereum-is-woefully-undervalued-but-growing-more-powerful-defi-dad-hall-of-flame\/\"><strong><em>DeFi Dad, Hall of Flame: Ethereum is \u2018woefully undervalued\u2019 but growing more powerful<\/em><\/strong><\/a><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Ethereum staking protocol Lido Finance has assured both Lido DAO (LDO) and staked-Ether (stETH) tokens remain safe despite hackers allegedly exploiting a known security flaw in LDO\u2019s token contract. Lido didn\u2019t confirm any exploits, but acknowledged the security flaw was known and reassured LDO and stETH funds remain safe in response to a Sept. 10 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":153323,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[235,203,210,234,231,232,237,238,236,233],"class_list":["post-153322","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blockchain","tag-bitcoin","tag-crypto-currency","tag-elon-musk","tag-ethereum","tag-hyperledger","tag-ibm","tag-mining","tag-nodes","tag-spacex","tag-tesla"],"_links":{"self":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/153322","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/comments?post=153322"}],"version-history":[{"count":2,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/153322\/revisions"}],"predecessor-version":[{"id":153325,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/153322\/revisions\/153325"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media\/153323"}],"wp:attachment":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media?parent=153322"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/categories?post=153322"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/tags?post=153322"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}