Bitget App
Trade smarter
Open
HomepageSign up
Bitget>
News>
Lido node operator InfStones agrees to rotate validator keys after vulnerability disclosure

Lido node operator InfStones agrees to rotate validator keys after vulnerability disclosure

The Block2023/12/03 08:48
By: The Block
ETH+0.38%
Quick Take Lido operator InfStones is expected to take precautionary measures after a vulnerability disclosure. The Tailon library-linked vulnerability, discovered in July 2023 by dWallet Labs, has been addressed. Lido Finance clarified there is no evidence of key leakage or exploit.
Lido node operator InfStones agrees to rotate validator keys after vulnerability disclosure image 0

InfStones, a key node operator for Lido Finance, is set to temporarily withdraw its Ethereum validators from the liquid staking protocol and implement key rotations in response to a significant vulnerability revealed by dWallet Labs’ security researchers.

The vulnerability, linked to the open-source library Tailon, was reported to InfStones in July 2023 and has since been resolved. Nonetheless, this event has led to the adoption of preventative security measures.

As the largest liquid staking protocol on Ethereum, Lido oversees 9.23 million ether, with a market value exceeding $19 billion . The protocol enables users to deposit ETH and participate in network staking through validator nodes, which in turn issue a derivative token to users as a representation of their staked deposit. A network of contributors, known as operators, is responsible for running these ETH validator nodes, providing the requisite IT infrastructure and servers necessary for their operation.

Lido Finance confirmed the vulnerability was related to potential root-level access that impacted 25 of InfStones’ validator servers. Lido clarified, however, that there’s no evidence of any key leakage or exploitation as a result of this issue.

"To clarify: There is currently no indication of key leakage or compromise, and the vulnerability may not affect validators related the Lido protocol," it said .

In its security report , dWallet Labs alleged the vulnerability could have potentially triggered a security breach impacting the ETH staked through InfStones’ nodes on Lido. Consequently, the firm recommended the rotation of validator keys for all nodes that were possibly exposed to the vulnerability.

InfStones' response

InfStones said the issue flagged by dWallet only affected a small part of its infrastructure, with less than 0.1% of its systems via a specific network port on its network that had the issue. As such it implied the affected validator nodes was a small number.

“The instances (servers) identified in production constitute a fraction below 0.1% of the live nodes we have launched to date. We found that outside traffic, through a port 55555 opened for Tailon, could imitate viewer privileges and access a portion of the development and testing data,” InfStones said.

Despite the absence of a confirmed key compromise, InfStones has proactively agreed to exit its validators and transition to new keys, pending governance’s approval, Lido Finance added . The ether that was previously staked on the potentially affected validators is planned to be redirected into the Lido protocol for re-staking, ensuring its continuity and stability.


Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

New spot margin trading pair — HOLO/USDT!
Bitget Announcement2025/09/12 07:46
FUN drops by 32.34% within 24 hours as it faces a steep short-term downturn

- FUN plunged 32.34% in 24 hours to $0.008938, marking a 541.8% monthly loss amid prolonged bearish trends. - Technical breakdowns, elevated selling pressure, and forced liquidations highlight deteriorating market sentiment and risk-off behavior. - Analysts identify key support below $0.0080 as critical, with bearish momentum confirmed by RSI (<30) and MACD indicators. - A trend-following backtest strategy proposes short positions based on technical signals to capitalize on extended downward trajectories.

Bitget-RWA2025/09/12 06:14
OPEN has dropped by 189.51% within 24 hours during a significant market pullback

- OPEN's price plummeted 189.51% in 24 hours to $0.8907, marking its largest intraday decline in history. - The token fell 3793.63% over 7 days, matching identical monthly and yearly declines, signaling severe bearish momentum. - Technical analysts cite broken support levels and lack of bullish catalysts as key drivers of the sustained sell-off. - Absence of stabilizing volume or reversal patterns leaves the market vulnerable to further downward pressure.

Bitget-RWA2025/09/12 06:14
New spot margin trading pair — LINEA/USDT!
Bitget Announcement2025/09/11 10:04

Trending news

More
1
New spot margin trading pair — HOLO/USDT!
2
FUN drops by 32.34% within 24 hours as it faces a steep short-term downturn

Crypto prices

More
Bitcoin
Bitcoin
BTC
$116,105.98
+0.11%
Ethereum
Ethereum
ETH
$4,687.9
-0.48%
XRP
XRP
XRP
$3.12
+0.60%
Tether USDt
Tether USDt
USDT
$1
-0.01%
Solana
Solana
SOL
$247.09
+2.01%
BNB
BNB
BNB
$937
+0.94%
USDC
USDC
USDC
$0.9997
+0.00%
Dogecoin
Dogecoin
DOGE
$0.2924
+5.44%
TRON
TRON
TRX
$0.3509
-0.36%
Cardano
Cardano
ADA
$0.9280
+0.00%
How to sell PI
Bitget lists PI – Buy or sell PI quickly on Bitget!
Trade now
Become a trader now?A welcome pack worth 6200 USDT for new users!
Sign up now
Trade smarter