escrow-vulnerability

1 article
sort: new top best
clear filter
0 5/10
vulnerability

A griefing vulnerability in Lido's Dual Governance RageQuit mechanism allowed permissionless prolongation of the RageQuit extension period, potentially blocking ETH withdrawals and protocol governance. The issue required >10% stETH veto participation to trigger and was mitigated by Emergency Committee safeguards; a patched smart contract fix was successfully deployed in September 2025.

Lido Immunefi Dual Governance RageQuit Escrow.startRageQuitExtensionPeriod() Emergency Committee Tiebreaker committee Vote #191 Proposal #4 stETH LDO
research.lido.fi · riptide · 15 hours ago · details