Ethereum 2.0 detected a dangerous bug
With it, node operators may be able to steal user funds
08.10.2021 - 09:55
661
1 min
0
What's new? On Twitter, Stake Wise posted news about the discovery of a critical bug in Ethereum 2.0 protocols called Lido and Rocket Pool. According to the co-founder of the service Dmitry Tsumak, there is a serious risk of the funds’ theft.
1/ Last night around 7PM UTC, our founder Dmitri Tsumak (@tsudmi) discovered a severe vulnerability in @Rocket_Pool that could lead to the theft of users’ funds if exploited. Upon further examination, it became apparent that @LidoFinance's architecture was also affected. https://t.co/xlpZMYkFMe— StakeWise (@stakewise_io) October 5, 2021
What consequences can be there? This vulnerability allows validators and operators of Ethereum 2.0 nodes to take over users' assets. Lido representatives believe that about $71 million is already under threat, however, in their opinion, node operators will not use this bug, because they represent “respected and ethical companies”.
When will the bug be fixed? Currently, Lido has limited stacking limits for operators, and Rocket Poll has reported testing new methods for bug fixing in collaboration with Sigma Prime auditors. Preliminary verification results may be available by October 18.
Useful material?
Incidents
The company is linking the incident to a compromised private key on a service wallet, rather than a smart contract exploit
May 22, 2026
Incidents
Following the incident, the project temporarily halted trading operations and node activity.
May 15, 2026
Incidents
The user spent weeks unsuccessfully trying to guess the password until Claude helped find an old wallet backup file
May 14, 2026
Crypto regulations
Authorities are introducing mandatory registration for companies handling cross-border crypto transactions
May 8, 2026
Incidents
According to Blockaid, the attack may have been carried out by the same hacker behind the 1inch Fusion V1 exploit.
May 7, 2026
Incidents
The attacker gained administrative access and altered contracts to drain user funds
Apr 30, 2026
Telegram
Twitter