Lido publishes post-mortem on Staking Router v3 incident, traces bug to accounting oracle oversight

4 hours ago 21

Lido’s contributors dropped a post-mortem on July 25 detailing what went wrong during the rollout of Staking Router v3: an AccountingOracle glitch that omitted a single 32 ETH validator deposit and briefly skewed the daily stETH rebase to an incorrect 2.04% APR figure.

No user funds were lost. No one got rugged. But when you’re the largest liquid staking protocol on Ethereum, even a minor accounting hiccup warrants a public autopsy.

What actually happened

The incident traces back to an edge case that surfaced during the transition from Lido’s legacy accounting methodology to the new balance-based system introduced by SRv3. The old system tracked rewards on a per-validator basis. The new one aggregates balances, which is necessary to support the headline feature of SRv3: validators with effective balances up to 2,048 ETH, a massive leap from the previous 32 ETH cap.

During that switchover window, the AccountingOracle missed a 32 ETH deposit in its calculations. The resulting anomalous stETH rebase was caught and corrected without material financial impact to stakers. Lido’s post-mortem described the root cause as an operational edge case specific to the migration period, not a systemic flaw in the SRv3 architecture itself.

The SRv3 upgrade in context

Staking Router v3, formally tracked as LIP-35, represents one of the most consequential infrastructure changes Lido has shipped. The proposal moved through Snapshot governance and on-chain votes across May and July 2026, earning approval before mainnet activation.

Three audit firms, Certora, Statemind, and MixBytes, signed off on the code prior to deployment. The fact that the bug still surfaced underscores a persistent reality in DeFi: audits catch code-level vulnerabilities, but operational edge cases during live migrations are a different beast entirely.

The upgrade itself does several things beyond raising the validator balance ceiling. It modifies deposit flows, enables stake consolidation across node operators, and lays groundwork for Lido to take advantage of changes introduced by Ethereum’s Pectra upgrade.

This isn’t Lido’s first public incident report in 2026, either. Back in February, a separate event affected roughly 5,572 validators. Lido published a similarly transparent post-mortem and arranged compensation for affected parties.

Market reaction and LDO implications

LDO, Lido’s governance token, saw approximately a 12% price bump around the time the SRv3 vote passed. That enthusiasm has since faded, which is a fairly standard pattern for governance-driven rallies.

Lido’s track record of voluntary transparency on incidents tends to function as a trust signal in a market where plenty of protocols quietly patch bugs and hope nobody notices. Publishing detailed breakdowns of what went wrong, why it happened, and how it got fixed is table stakes for traditional software companies. In DeFi, it still counts as above-average disclosure.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article