
Lido
Liquid staking protocol for Ethereum allowing users to stake ETH without locking assets
ETHMOONBEAMMOONRIVERMATICARBOPDeFi StakingPoC RequiredTriaged
Verified ProgramKYC Not RequiredPoC RequiredTriaged
Max Bounty$2,000,000
Min Bounty$1,000
PayoutUSDC
Findings0
Accepted0
Chains6
TVL$17.3B
Live SinceMay 2021
10 Audit Reports Available
Scroll Lido Gateway AuditZellic
2023auditsExternal
2025-12-19-cyfrin-lido-earn-v2.0.pdfCyfrin
2025-12Lido V3Consensys Diligence
2025-08The MixBytes team was highly engaged throughout the audit, consistently available and proactive with insightful questions that demonstrated a deep understanding of the protocol. Their commitment to a thorough review, high level of expertise, adherence to deadlines, and professional approach made the audit process smooth and effective.MixBytes
README.mdMixBytes
LidoDedaub
Security ZK Audit of Lido's Accounting zk-Oracle Built on SP1 September 16, 2025Nethermind
2025Show detailsHexens
auditsExternal
01Severity & Rewards
02Program Rules
- 01Proof of Concept is required for all submissions. Reports without a working PoC demonstrating the vulnerability will not be considered.
- 02KYC is not required for this program. Pseudonymous submissions are accepted.
- 03Submissions are triaged by the security team. Expect initial response within 48 hours of submission.
- 04Only previously unreported vulnerabilities are eligible. Duplicate submissions will be closed.
- 05Vulnerabilities must be reported through the WhiteClaws platform. Public disclosure before resolution disqualifies the submission.
- 06Testing must not disrupt live protocol operations. Use mainnet forks or testnets for Proof of Concept execution.
- 07For Critical severity findings, the security team may arrange direct communication for expedited resolution.
โ IN SCOPE
- โstETH token contract
- โWithdrawal queue
- โNode operator registry
- โOracle reporting
CRITICAL FUNCTIONS
submit()handleOracleReport()requestWithdrawals()HIGH FUNCTIONS
claimWithdrawals()addNodeOperator()setWithdrawalCredentials()โ OUT OF SCOPE
- โFrontend applications
- โwstETH wrapper on L2s
- โOff-chain oracle nodes
โ Protocol Information
Audited By
OpenZeppelin
Certora
Chainsecurity
ChainSecurity
Immunefi
MixBytes
Nethermind
1 Audit Report
Security Contacts
Bounty program indexed and verified by WhiteClawsProgram data sourced from on-chain analysis and public bounty disclosures.