A recent security incident involving Lido, the largest liquid staking protocol on Ethereum, has been contained with minimal losses. The breach, which targeted one of Lido's nine oracle keys, resulted in the theft of approximately 1.46 ETH ($4,200) in gas fees, but did not compromise any user funds. The incident occurred when a private key belonging to validator operator Chorus One was compromised, triggering an emergency response from Lido.
As a precautionary measure, Lido has initiated a DAO vote to replace the compromised oracle key with a new, more secure key. The vote aims to rotate the key across three contracts: the Accounting Oracle, the Validators Exit Bus Oracle, and the CS Fee Oracle.
The new key has been generated with enhanced security controls to prevent similar incidents in the future. The compromised address is being replaced, and the on-chain vote has been approved, with a 48-hour objection period currently underway. Lido's oracle system, which provides Ethereum consensus data to the protocol's smart contracts, is designed to function securely even if up to four keys are compromised, thanks to its 5-of-9 quorum mechanism. The incident highlights the importance of robust security measures in the Ethereum ecosystem, particularly for systemically important protocols like Lido, which secures over 25% of all ether staked on Ethereum.