

Statemind
774 posts

@statemindio
Security research for Web3 & DeFi | Lido, Curve, Fluid, Symbiotic, Valantis, Yield Basis, Vyper | Top in Paradigm CTF | ICPC |












Aragon Vote: CSM v2 Onchain Release An Aragon omnibus vote including the previously approved CSM v2 Onchain Release • Share limit increase 3% → 5% • Community Stakers Identification Framework Audited by: @AckeeBlockchain, @statemindio & @code4rena Also included: Triggerable Withdrawals, Nethermind → Twinstake Migration, and Kiln’s key rotation. Vote here: vote.lido.fi/vote/192

Audit reports from: @statemindio @chain_security @Quantstamp @electisec @MixBytes @PashovAuditGrp docs.yieldbasis.com/user/audits-bu…




Dual Governance release is around the corner & the Aragon vote starts this Wednesday. To make sure that Dual Governance is sane and sound, four layers were audited: • Specs: mechanism design, proposal lifecycle, critical governance states. • Code: contracts for signalling escrow, rage quit, timelocks, committees. • Parameters: thresholds, delays, triggers. • Deployment & vote: mainnet contracts match audited code, voting script. See who's tested, audited & certified Dual Governance:

_ @yieldbasis is coming github.com/yield-basis/yb…

We are at a pivotal moment in Ethereum’s history. The network, and by extension its community, has a grand ambition to deliver the world computer exporting the values of verifiability and sovereignty to the entire world.

External Audits & Security Checks Multiple expert teams rigorously reviewed Dual Governance to catch edge cases, logic flaws and attack risks. What was audited: • Mechanism design: by @certora & @rv_inc; • Code: by @OpenZeppelin & @statemindio, formally verified by @certora & @rv_inc; • Params: stress-tested by @CollectifDAO, 20[] Research @fabgenovese & @dpl0a. To find all the reports, start scrolling down this list: #09-2024-certora-dual-governance-draft-audit" target="_blank" rel="nofollow noopener">github.com/lidofinance/au…

This can't go unnoticed! A client performed a FULL tree-migration of ethereum moving from Merkle Patricia Tree to Verkle tree! That means, going to Binary, Verkle or whatever has been proven possible! Shoutout to Karim and the folks at @StatelessEth for such an accomplishment!

⚠️ Emergency Lido DAO vote announcement: rotate single Lido Oracle related to compromised Chorus One oracle private key. Stakers are not affected. The protocol remains secure and fully operational. The oracle system is robust by design, with a 5/9 quorum, and all other participants remain safe. ✔️ Oracle ops functioning, no sign of issue in oracle software or reports ✔️ Other eight oracles checked and no signs of compromise ✔️ No signs of broader Chorus One compromise The vote will be started shortly.
