diff --git a/README.md b/README.md index 9de9e52..041d7a7 100644 --- a/README.md +++ b/README.md @@ -1,6 +1,8 @@ # Lido Protocol Audits -## 12-2020 Sigma Prime Security Assessment +## Lido on Ethereum + +### 12-2020 Sigma Prime Security Assessment The testing team identified a total of eighteen (18) issues during this assessment, of which: @@ -10,7 +12,7 @@ The testing team identified a total of eighteen (18) issues during this assessme See [full report](Sigma%20Prime%20-%20Lido%20Finance%20Security%20Assessment%20Report%20v2.1.pdf) for more details. -## 12-2020 Quantstamp Audit +### 12-2020 Quantstamp Audit - Total Issues: 14 (7 Resolved) - High Risk Issues: 0 (0 Resolved) @@ -21,7 +23,7 @@ See [full report](Sigma%20Prime%20-%20Lido%20Finance%20Security%20Assessment%20R See [full report](QSP%20Lido%20Report%2012-2020.pdf) for more details. -## 04-2021 MixBytes Audit: ETH2 Oracle +### 04-2021 MixBytes Audit: ETH2 Oracle - Total Issues: 7 (1 Fixed, 6 No issue) - Critical Issues: 0 @@ -31,7 +33,7 @@ See [full report](QSP%20Lido%20Report%2012-2020.pdf) for more details. See [full report](MixBytes%20ETH2%20Oracle%20Security%20Audit%20Report%2004-2021.pdf) for more details. -## 05-2021 MixBytes Audit: stETH price oracle +### 05-2021 MixBytes Audit: stETH price oracle - Total Issues: 7 (4 Fixed, 1 No issue, 2 Acknowledged) - Critical Issues: 0 @@ -41,7 +43,7 @@ See [full report](MixBytes%20ETH2%20Oracle%20Security%20Audit%20Report%2004-2021 See [full report](MixBytes%20stETH%20price%20oracle%20Security%20Audit%20Report%2005-2021.pdf) for more details. -## 05-2021 MixBytes Audit: Withdrawals Manager Proxy and Stub +### 05-2021 MixBytes Audit: Withdrawals Manager Proxy and Stub - Total Issues: 1 (1 Fixed) - Critical Issues: 0 @@ -51,7 +53,7 @@ See [full report](MixBytes%20stETH%20price%20oracle%20Security%20Audit%20Report% See [full report](MixBytes%20Withdrawals%20Manager%20Stub%20Security%20Audit%20Report%2005-2021.pdf) for more details. -## 06-2021 MixBytes stETH Price Feed Security Audit +### 06-2021 MixBytes stETH Price Feed Security Audit - Total Issues: 10 (3 Fixed, 6 No issue, 1 Acknowledged) - Critical Issues: 0 @@ -61,7 +63,7 @@ See [full report](MixBytes%20Withdrawals%20Manager%20Stub%20Security%20Audit%20R See [full report](MixBytes%20stETH%20Price%20Feed%20Security%20Audit%20Report%2006-2021.pdf) for more details. -## 07-2021 MixBytes bETH Vault Security Audit +### 07-2021 MixBytes bETH Vault Security Audit - Total Issues: 5 (3 Fixed, 2 Acknowledged) - Critical Issues: 0 @@ -71,7 +73,7 @@ See [full report](MixBytes%20stETH%20Price%20Feed%20Security%20Audit%20Report%20 See [full report](MixBytes%20bETH%20Vault%20Security%20Audit%20Report%2007-2021.pdf) for more details. -## 08-2021 MixBytes bETH Vault Security Audit +### 08-2021 MixBytes bETH Vault Security Audit bETH Vault was re-audited by MixBytes to incorporate the changes made since the previous audit. @@ -83,7 +85,7 @@ bETH Vault was re-audited by MixBytes to incorporate the changes made since the See [full report](MixBytes%20bETH%20Vault%20Security%20Audit%20Report%2008-2021.pdf) for more details. -## 09-2021 MixBytes wstETH Security Audit +### 09-2021 MixBytes wstETH Security Audit - Total Issues: 5 (3 Acknowledged, 2 No Issue) - Critical Issues: 0 @@ -93,7 +95,7 @@ See [full report](MixBytes%20bETH%20Vault%20Security%20Audit%20Report%2008-2021. See [full report](MixBytes%20wstETH%20Security%20Audit%20Report%2009-2021.pdf) for more details. -## 09-2021 MixBytes Easy Track Security Audit +### 09-2021 MixBytes Easy Track Security Audit - Total Issues: 3 (2 Fixed, 1 No Issue) - Critical Issues: 0 @@ -103,7 +105,7 @@ See [full report](MixBytes%20wstETH%20Security%20Audit%20Report%2009-2021.pdf) f See [full report](MixBytes%20Easy%20Track%20Security%20Audit%20Report%2009-2021.pdf) for more details. -## 09-2021 MixBytes 1inch Rewards Manager Security Audit +### 09-2021 MixBytes 1inch Rewards Manager Security Audit - Total Issues: 4 (4 Acknowledged) - Critical Issues: 0 @@ -113,7 +115,7 @@ See [full report](MixBytes%20Easy%20Track%20Security%20Audit%20Report%2009-2021. See [full report](MixBytes%201inch%20Rewards%20Manager%20Security%20Audit%20Report%2009-21.pdf) for more details. -## 10-2021 MixBytes Aragon Voting Security Audit +### 10-2021 MixBytes Aragon Voting Security Audit The version of the [Aragon Voting smart contract](https://github.com/lidofinance/aragon-apps/blob/8c46da8704d0011c42ece2896dbf4aeee069b84a/apps/voting/contracts/Voting.sol) with support of the voting time change. @@ -125,7 +127,7 @@ The version of the [Aragon Voting smart contract](https://github.com/lidofinance See [full report](MixBytes%20Aragon%20Voting%20Security%20Audit%20Report%2010-2021.pdf) for more details. -## 10-2021 Sigma Prime Easy Track Smart Contract Security Review +### 10-2021 Sigma Prime Easy Track Smart Contract Security Review The testing team identified a total of nine (9) issues during this assessment, of which: @@ -135,7 +137,7 @@ The testing team identified a total of nine (9) issues during this assessment, o See [full report](Sigma%20Prime%20-%20Lido%20Easy%20Track%20Smart%20Contract%20Security%20Review%20Report%20v2.0%2010-2021.pdf) for more details. -## 01-2022 MixBytes bETH Vault Security Audit Report +### 01-2022 MixBytes bETH Vault Security Audit Report bETH Vault was re-audited by MixBytes to incorporate the changes made for the vault to work with Wormhole bridge instead of the Shuttle bridge. @@ -147,7 +149,7 @@ bETH Vault was re-audited by MixBytes to incorporate the changes made for the va See [full report](MixBytes%20bETH%20Vault%20Security%20Audit%20Report%2001-2022.pdf) for more details. -## 02-2022 MixBytes AAVE stETH integration Security Audit Report +### 02-2022 MixBytes AAVE stETH integration Security Audit Report - Total Issues: 11 (3 Fixed, 2 Acknowledged) - Critical Issues: 0 @@ -157,7 +159,7 @@ See [full report](MixBytes%20bETH%20Vault%20Security%20Audit%20Report%2001-2022. See [full report](MixBytes%20AAVE%20stETH%20integration%20Security%20Audit%20Report%2002-22.pdf) for more details. -## 02-2022 MixBytes In-protocol Coverage Security Audit Report +### 02-2022 MixBytes In-protocol Coverage Security Audit Report - Total Issues: 3 (3 Fixed) - Critical Issues: 1 (1 Fixed) @@ -167,7 +169,7 @@ See [full report](MixBytes%20AAVE%20stETH%20integration%20Security%20Audit%20Rep See [full report](MixBytes%20In-protocol%20Coverage%20Security%20Audit%20Report%2002-2022.pdf) for more details. -## 02-2022 MixBytes Deposit Security Module Security Audit Report +### 02-2022 MixBytes Deposit Security Module Security Audit Report - Total Issues: 22 (17 Fixed, 5 Acknowledged) - Critical Issues: 0 @@ -177,17 +179,7 @@ See [full report](MixBytes%20In-protocol%20Coverage%20Security%20Audit%20Report% See [full report](MixBytes%20Deposit%20Security%20Module%20Security%20Audit%20Report%2002-2022.pdf) for more details. -## 04-2022 Lido On Polygon Smart Contracts Security Audit Report for PR#69 - -- Total Issues: 9 (4 Fixed, 1 Acknowledged, 1 No Issue) -- Critical Issues: 0 -- Major Issues: 0 -- Warning Issues: 0 -- Info Issues: 9 (4 Fixed, 1 Acknowledged, 1 No Issue) - -See [full report](polygon/Oxorio%20Lido%20on%20Polygon%20pr69%20report%2004-2022.pdf) for more details. - -## 05-2022 Oxorio Jumpgate Smart Contracts Security Audit Report +### 05-2022 Oxorio Jumpgate Smart Contracts Security Audit Report - Total Issues: 12 (11 Fixed, 1 Acknowledged) - Critical Issues: 0 @@ -197,7 +189,7 @@ See [full report](polygon/Oxorio%20Lido%20on%20Polygon%20pr69%20report%2004-2022 See [full report](Oxorio%20Jumpgate%20Smart%20Contracts%20Security%20Audit%20Report%2005-2022.pdf) for more details. -## 05-2022 MixBytes Lido Protocol Security Audit Report +### 05-2022 MixBytes Lido Protocol Security Audit Report - Total Issues: 15 (13 Fixed, 2 Acknowledged) - Critical Issues: 0 @@ -207,7 +199,7 @@ See [full report](Oxorio%20Jumpgate%20Smart%20Contracts%20Security%20Audit%20Rep See [full report](MixBytes%20Lido_Protocol_Security_Audit_Report%2005-2022.pdf) for more details. -## 06-2022 MixBytes Lido Two-Phase Voting Security Audit Report +### 06-2022 MixBytes Lido Two-Phase Voting Security Audit Report - Total Issues: 10 (7 Fixed, 3 Acknowledged) - Critical Issues: 0 @@ -217,7 +209,7 @@ See [full report](MixBytes%20Lido_Protocol_Security_Audit_Report%2005-2022.pdf) See [full report](MixBytes%20Lido%20Two-Phase%20Voting%20Security%20Audit%20Report%2006-2022.pdf) for more details. -## 08-2022 ChainSecurity Code Assessment of the Lido Smart Contracts Audit Report +### 08-2022 ChainSecurity Code Assessment of the Lido Smart Contracts Audit Report - Total Issues: 9 (4 Risk accepted, 5 Acknowledged) - Critical Issues: 0 @@ -228,21 +220,11 @@ See [full report](MixBytes%20Lido%20Two-Phase%20Voting%20Security%20Audit%20Repo See [full report](ChainSecurity%20Code%20Assessment%20of%20the%20Lido%20Smart%20Contracts%20Report%2008-22.pdf) for more details. -## 08-2022 MixBytes Lido Protocol Security Auditor's Note On The Deployed Code Compliance +### 08-2022 MixBytes Lido Protocol Security Auditor's Note On The Deployed Code Compliance See [note](MixBytes%20Note%20on%20Deployed%20Code%20Compliance%2008-22.pdf) contents for more details -## 08-2022 Oxorio Lido on Polygon V2 - -- Total Issues: 107 (61 Fixed, 11 Acknowledged, 35 No Issue) -- Critical Issues: 0 -- Major Issues: 0 -- Warning Issues: 14 (12 Fixed, 2 No Issue) -- Info Issues: 93 (49 Fixed, 11 Acknowledged, 33 No Issue) - -See [full report](polygon/Oxorio%20Lido%20on%20Polygon%20V2%2008-2022.pdf) for more details. - -## 09-2022 Statemind MEV-Boost relay allowlist Security Audit Report +### 09-2022 Statemind MEV-Boost relay allowlist Security Audit Report - Total Issues: 7 (5 Fixed, 2 Acknowledged) - Critical Issues: 0 @@ -252,7 +234,7 @@ See [full report](polygon/Oxorio%20Lido%20on%20Polygon%20V2%2008-2022.pdf) for m See [full report](Statemind%20MEV-Boost%20relay%20allowlist%20Security%20Audit%20Report%2009-2022.pdf) for more details. -## 09-2022 Statemind Insurance Fund Audit Report +### 09-2022 Statemind Insurance Fund Audit Report - Total Issues: 4 (1 Fixed, 3 Acknowledged) - Critical Issues: 0 @@ -262,7 +244,7 @@ See [full report](Statemind%20MEV-Boost%20relay%20allowlist%20Security%20Audit%2 See [full report](Statemind%20Insurance%20Fund%20Audit%20Report%2009-2022.pdf) for more details. -## 09-2022 Statemind Easy Track Payment Processor with limits +### 09-2022 Statemind Easy Track Payment Processor with limits - Total Issues: 9 (9 Acknowledged) - Critical Issues: 0 @@ -272,7 +254,7 @@ See [full report](Statemind%20Insurance%20Fund%20Audit%20Report%2009-2022.pdf) f See [full report](Statemind%20Easy%20Track%20Payment%20Processor%20with%20limits%2009-2022.pdf) for more details. -## 01-2023 Statemind TRP Vesting Escrow Audit Report +### 01-2023 Statemind TRP Vesting Escrow Audit Report - Total Issues: 5 (4 Fixed, 1 Acknowledged) - Critical Issues: 0 @@ -282,7 +264,7 @@ See [full report](Statemind%20Easy%20Track%20Payment%20Processor%20with%20limits See [full report](Statemind%20TRP%20Vesting%20Escrow%20Audit%20Report%2001-2023.pdf) for more details. -## 02-2023 ChainSecurity Lido Staking Router Audit Report +### 02-2023 ChainSecurity Lido Staking Router Audit Report - Total Issues: 13 (10 Fixed, 3 Acknowledged) - Critical Issues: 0 @@ -292,7 +274,7 @@ See [full report](Statemind%20TRP%20Vesting%20Escrow%20Audit%20Report%2001-2023. See [full report](ChainSecurity%20Lido%20Staking%20Router%20audit%20report%2002-23.pdf) for more details. -## 03-2023 Sigma Prime dc4bc Security Audit +### 03-2023 Sigma Prime dc4bc Security Audit - Total Issues: 8 (8 Fixed) - Critical Issues: 0 @@ -303,7 +285,7 @@ See [full report](ChainSecurity%20Lido%20Staking%20Router%20audit%20report%2002- See [full report](Sigma%20Prime%20-%20Lido%20-%20dc4bc%20Security%20Assessment%20Report%20-%20v2.2%2003-2023.pdf) for more details. The report had been updated on 14 March 2023 with the build hashes of 4.1.0 release. -## 04-2023 Hexens Lido V2 Smart Contract Audit +### 04-2023 Hexens Lido V2 Smart Contract Audit - Total Issues: 25 (16 Fixed, 9 Acknowledged) - Critical Issues: 1 (1 Fixed) @@ -314,7 +296,7 @@ See [full report](Sigma%20Prime%20-%20Lido%20-%20dc4bc%20Security%20Assessment%2 See [full report](Hexens%20Lido%20V2%20Smart%20Contract%20Audit%20Report%2004-23.pdf) for more details. -## 04-2023 MixBytes Camp Lido V2 Contest +### 04-2023 MixBytes Camp Lido V2 Contest - Total Issues: 17 (8 Fixed, 9 Acknowledged) - Critical Issues: 0 @@ -324,7 +306,7 @@ See [full report](Hexens%20Lido%20V2%20Smart%20Contract%20Audit%20Report%2004-23 See [full report](MixBytes%20Camp%20Lido%20V2%20Contest%20Report%2004-23.pdf) for more details. -## 04-2023 Statemind GateSeals Audit +### 04-2023 Statemind GateSeals Audit - Total Issues: 4 (3 Fixed, 1 Acknowledged) - Critical Issues: 0 @@ -335,7 +317,7 @@ See [full report](MixBytes%20Camp%20Lido%20V2%20Contest%20Report%2004-23.pdf) fo See [full report](Statemind%20GateSeals%20Audit%20Report%2004-2023.pdf) for more details. -## 04-2023 Certora Lido V2 Audit +### 04-2023 Certora Lido V2 Audit - Total Issues: 23 (14 Fixed, 9 Acknowledged) - Critical Issues: 2 (2 Fixed) @@ -346,7 +328,7 @@ See [full report](Statemind%20GateSeals%20Audit%20Report%2004-2023.pdf) for more See [full report](Certora%20Lido%20V2%20Audit%20Report%2004-23.pdf) for more details. -## 04-2023 Statemind Lido V2 Audit +### 04-2023 Statemind Lido V2 Audit - Total Issues: 120 (75 Fixed, 45 Acknowledged) - Critical Issues: 2 (1 Fixed, 1 Acknowledged) @@ -356,7 +338,7 @@ See [full report](Certora%20Lido%20V2%20Audit%20Report%2004-23.pdf) for more det See [full report](Statemind%20Lido%20V2%20Audit%20Report%2004-23.pdf) for more details. -## 05-2023 Statemind Lido V2 Upgrade Template Audit +### 05-2023 Statemind Lido V2 Upgrade Template Audit - Total Issues: 14 (7 Fixed, 7 Acknowledged) - Critical Issues: 0 @@ -366,11 +348,11 @@ See [full report](Statemind%20Lido%20V2%20Audit%20Report%2004-23.pdf) for more d See [full report](Statemind%20Lido%20V2%20Upgrade%20Template%20Audit%20Report%2005-2023.pdf) for more details. -## 05-2023 Statemind Lido V2 Deployment Validation Note +### 05-2023 Statemind Lido V2 Deployment Validation Note See [note](Statemind%20Lido%20V2%20Deployment%20Validation%2005-2023.pdf) contents for more details. -## 05-2023 Hexens Lido V2 Oracle Security Review +### 05-2023 Hexens Lido V2 Oracle Security Review - Total Issues: 2 (2 Fixed) - Critical Issues: 0 @@ -381,7 +363,7 @@ See [note](Statemind%20Lido%20V2%20Deployment%20Validation%2005-2023.pdf) conten See [full report](Hexens%20Lido%20V2%20Oracle%20Security%20Review%20Report%2005-23.pdf) for more details. -## 05-2023 Oxorio Lido V2 On-chain Audit +### 05-2023 Oxorio Lido V2 On-chain Audit - Total Issues: 43 (4 Fixed, 37 Acknowledged, 2 No Issue) - Critical: 0 @@ -391,7 +373,7 @@ See [full report](Hexens%20Lido%20V2%20Oracle%20Security%20Review%20Report%2005- See [full report](Oxorio%20Lido%20V2%20On-chain%20Audit%20Report%2006-23.pdf) for more details. -## 05-2023 Oxorio Lido V2 Off-chain Audit +### 05-2023 Oxorio Lido V2 Off-chain Audit - Total Issues: 11 (1 Fixed, 10 Acknowledged) - Critical: 0 @@ -401,7 +383,7 @@ See [full report](Oxorio%20Lido%20V2%20On-chain%20Audit%20Report%2006-23.pdf) fo See [full report](Oxorio%20Lido%20V2%20Off-chain%20Audit%20Report%2006-23.pdf) for more details. -## 10-2023 Statemind Lido roles analysis +### 10-2023 Statemind Lido roles analysis | Impact severity \ Attack feasibility | Low | Medium | High | | ------------------------------------ | --- | ------ | ---- | @@ -413,7 +395,7 @@ See [full report](Oxorio%20Lido%20V2%20Off-chain%20Audit%20Report%2006-23.pdf) f See [full report](Statemind%20Lido%20roles%20analysis%2010-2023.pdf) for more details. -## 10-2023 Oxorio Lido Easy Track Smart Contracts Security Audit (Easy Track Factories for Stablecoins) +### 10-2023 Oxorio Lido Easy Track Smart Contracts Security Audit (Easy Track Factories for Stablecoins) - Total Issues: 9 (5 Fixed, 4 Acknowledged) - Critical: 0 @@ -423,7 +405,7 @@ See [full report](Statemind%20Lido%20roles%20analysis%2010-2023.pdf) for more de See [full report](Oxorio%20Lido%20Easy%20Track%20Smart%20Contracts%20Security%20Audit%20Report%2010-2023.pdf) for more details. -## 12-2023 Pessimistic Lido Stonks Audit +### 12-2023 Pessimistic Lido Stonks Audit This audit report covers the code up to commit [`ad6a9e83c095f5052e404bc13585ad2c752f242f`](https://github.com/lidofinance/stonks/tree/ad6a9e83c095f5052e404bc13585ad2c752f242f). For release version audit please go to [03-2024 Ackee Blockchain Lido Stonks Audit](#03-2024-ackee-blockchain-lido-stonks-audit). @@ -435,7 +417,7 @@ This audit report covers the code up to commit [`ad6a9e83c095f5052e404bc13585ad2 See [full report](Pessimistic%20Lido%20Stonks%20Audit%20Report%2012-23.pdf) for more details. -## 01-2024 Statemind Lido Simple DVT Easy Track Factories Audit +### 01-2024 Statemind Lido Simple DVT Easy Track Factories Audit - Total Issues: 10 (7 Fixed, 3 Acknowledged) - Critical: 0 @@ -445,7 +427,7 @@ See [full report](Pessimistic%20Lido%20Stonks%20Audit%20Report%2012-23.pdf) for See [full report](Statemind%20Lido%20Simple%20DVT%20Easy%20Track%20Factories%20Audit%20Report%2001-24.pdf) for more details. -## 03-2024 Ackee Blockchain Lido Stonks Audit +### 03-2024 Ackee Blockchain Lido Stonks Audit - Total Issues: 9 (7 Fixed, 2 Acknowledged) - Critical: 0 @@ -456,11 +438,11 @@ See [full report](Statemind%20Lido%20Simple%20DVT%20Easy%20Track%20Factories%20A See [full report](Ackee%20Blockchain%20Lido%20Stonks%20Audit%20Report%2003-24.pdf) for more details. -## 04-2024 Statemind GateSeal Deployment Validation Note +### 04-2024 Statemind GateSeal Deployment Validation Note See [note](Statemind%20GateSeal%20Deployment%20Validation%2004-2024.pdf) contents for more details. -## 06-2024 ChainSecurity Code Assessment of the LIP-23: Rebase Check Smart Contracts +### 06-2024 ChainSecurity Code Assessment of the LIP-23: Rebase Check Smart Contracts - Total Issues: 3 (3 Fixed) - Critical Issues: 0 @@ -471,7 +453,7 @@ See [note](Statemind%20GateSeal%20Deployment%20Validation%2004-2024.pdf) content See [full report](ChainSecurity%20Code%20Assessment%20of%20LIP-23%20Negative%20Rebase%20Checks%20Smart%20Contracts%2006-24.pdf) for more details. -## 07-2024 Ackee Blockchain Audit of the Simple Delegation +### 07-2024 Ackee Blockchain Audit of the Simple Delegation - Total Issues: 14 (6 Fixed, 8 Acknowledged) - High Issues: 0 @@ -481,7 +463,7 @@ See [full report](ChainSecurity%20Code%20Assessment%20of%20LIP-23%20Negative%20R See [full report](Ackee%20Blockchain%20Lido%20Simple%20Delegation%20audit%20report%2007-24.pdf) for more details. -## 07-2024 Statemind Audit of the Simple Delegation +### 07-2024 Statemind Audit of the Simple Delegation - Total Issues: 6 (2 Fixed, 4 Acknowledged) - Critical Issues: 0 @@ -491,7 +473,7 @@ See [full report](Ackee%20Blockchain%20Lido%20Simple%20Delegation%20audit%20repo See [full report](Statemind%20Lido%20Simple%20Delegation%20audit%20report%2007-24.pdf) for more details. -## 07-2024 MixBytes Sanity Checker Security Audit (LIP-23) +### 07-2024 MixBytes Sanity Checker Security Audit (LIP-23) - Total Issues: 8 (4 Fixed, 4 Acknowledged) - Critical Issues: 0 @@ -501,7 +483,7 @@ See [full report](Statemind%20Lido%20Simple%20Delegation%20audit%20report%2007-2 See [full report](Lido%20Sanity%20Checker%20Security%20Audit%20Report.pdf) for more details. -## 10-2024 Ackee Blockchain Audit of Staking Router v2 (LIP-25) +### 10-2024 Ackee Blockchain Audit of Staking Router v2 (LIP-25) - Total Issues: 7 (5 Fixed, 2 Acknowledged) - Critical Issues: 0 @@ -513,7 +495,7 @@ See [full report](Lido%20Sanity%20Checker%20Security%20Audit%20Report.pdf) for m See [full report](Ackee%20Blockchain%20Lido%20Staking%20Router%20v2%20Report%2010-24.pdf) for more details. -## 10-2024 Ackee Blockchain Audit of Community Staking Module (LIP-26) +### 10-2024 Ackee Blockchain Audit of Community Staking Module (LIP-26) - Total Issues: 39 (25 Fixed, 2 Partially fixed, 12 Acknowledged) - Critical Issues: 0 @@ -525,7 +507,7 @@ See [full report](Ackee%20Blockchain%20Lido%20Staking%20Router%20v2%20Report%201 See [full report](Ackee%20Blockchain%20Lido%20Community%20Staking%20Module%20Report%2010-24.pdf) for more details. -## 10-2024 MixBytes On-chain Audit of Community Staking Module (LIP-23, LIP-25, LIP-26) +### 10-2024 MixBytes On-chain Audit of Community Staking Module (LIP-23, LIP-25, LIP-26) - Total Issues: 41 (18 Fixed, 23 Acknowledged) - Critical Issues: 0 @@ -535,7 +517,7 @@ See [full report](Ackee%20Blockchain%20Lido%20Community%20Staking%20Module%20Rep See [full report](MixBytes%20Lido%20CSM%20Security%20Audit%20Report%2010-24.pdf) for more details. -## 10-2024 MixBytes Off-chain Audit of Lido Oracle v4 +### 10-2024 MixBytes Off-chain Audit of Lido Oracle v4 - Total Issues: 3 (2 Fixed, 1 Acknowledged) - Critical Issues: 0 @@ -545,11 +527,9 @@ See [full report](MixBytes%20Lido%20CSM%20Security%20Audit%20Report%2010-24.pdf) See [full report](MixBytes%20Lido%20Oracle%20Security%20Audit%20Report%2010-24.pdf) for more details. ---- +## Lido Multichain audit reports -# L2 audit reports - -## 07-2022 Oxorio Lido L2 Smart Contracts Security Audit Report +### 07-2022 Oxorio Lido L2 Smart Contracts Security Audit Report - Total Issues: 9 (6 Fixed, 2 Acknowledged, 1 No Issue) - Critical Issues: 1 (1 Acknowledged) @@ -559,7 +539,7 @@ See [full report](MixBytes%20Lido%20Oracle%20Security%20Audit%20Report%2010-24.p See [full report](L2/Lido-L2-2022-07-Oxorio-Smart-Contracts-Security-Audit-Report.pdf) for more details. -## 08-2022 Oxorio Governance Crosschain Bridges Smart Contracts Security Audit Report +### 08-2022 Oxorio Governance Crosschain Bridges Smart Contracts Security Audit Report - Total Issues: 8 (8 Acknowledged) - Critical Issues: 0 @@ -569,7 +549,7 @@ See [full report](L2/Lido-L2-2022-07-Oxorio-Smart-Contracts-Security-Audit-Repor See [full report](L2/Governance-Crosschain-Bridges-2022-08-Oxorio-Audit%20Report.pdf) for more details. -## 09-2023 Verilog Mantle L2 ERC20 Token Bridge Audit Report +### 09-2023 Verilog Mantle L2 ERC20 Token Bridge Audit Report - Total Issues: 5 (3 Fixed, 2 Acknowledged) - High: 0 @@ -579,7 +559,7 @@ See [full report](L2/Governance-Crosschain-Bridges-2022-08-Oxorio-Audit%20Report See [full report](L2/Mantle-2023-09-Verilog-L2-ERC20-Token-Bridge-Audit-Report.pdf) for more details. -## 10-2023 Cantina zkSync Lido Bridge Audit Report +### 10-2023 Cantina zkSync Lido Bridge Audit Report - Total Issues: 22 (15 Fixed, 3 Acknowledged, 4 No issue) - Critical Issues: 1 (1 Fixed) @@ -590,20 +570,20 @@ See [full report](L2/Mantle-2023-09-Verilog-L2-ERC20-Token-Bridge-Audit-Report.p See [full report](L2/zkSync-2023-10-Cantina-Audit-Report.pdf) for more details. -## 10-2023 Diligence Linea Cross‐Chain Governance Executor Audit Report +### 10-2023 Diligence Linea Cross‐Chain Governance Executor Audit Report - Total Issues: 1 (1 Fixed) - Informational: 1 (1 Fixed) See [full report](L2/Linea-2023-10-Diligence-Cross-Chain-Governance-Executor-Audit-Report.pdf) for more details. -## 12-2023 Diligence Linea Custom Bridged Token Audit Report +### 12-2023 Diligence Linea Custom Bridged Token Audit Report - Total Issues: 0 See [full report](L2/Lidea-2023-12-Diligence-Custom-Bridged-Token-Audit-Report.pdf) for more details. -## 12-2023 OpenZeppelin Linea Bridge Audit Report +### 12-2023 OpenZeppelin Linea Bridge Audit Report > NB: the most of the contracts and issues are related not to wstETH bridge but to the entire Linea L2 system. @@ -616,14 +596,14 @@ See [full report](L2/Lidea-2023-12-Diligence-Custom-Bridged-Token-Audit-Report.p See [full report](L2/Linea-2023-12-OpenZeppelin-Bridge-Audit-Report.pdf) for more details. -## 01-2024 Zellic Scroll Lido Gateway Audit Report +### 01-2024 Zellic Scroll Lido Gateway Audit Report - Total Issues: 1 (1 No Issue) - Info Issues: 1 (1 No Issue) See [full report](L2/Scroll-2024-01-Lido-Gateway-Zellic-Audit-Report.pdf) for more details. -## 06-2024 Ackee Blockchain stETH on Optimism Audit Report +### 06-2024 Ackee Blockchain stETH on Optimism Audit Report - Total Issues: 15 (10 Fixed, 5 Acknowledged) - Critical Issues: 0 @@ -635,7 +615,7 @@ See [full report](L2/Scroll-2024-01-Lido-Gateway-Zellic-Audit-Report.pdf) for mo See [full report](L2/stETH-on-Optimism-2024-06-Ackee-Blockchain-Audit-report.pdf) for more details. -## 06-2024 MixBytes stETH on Optimism Audit Report +### 06-2024 MixBytes stETH on Optimism Audit Report - Total Issues: 20 (15 Fixed, 5 Acknowledged) - Critical Issues: 0 @@ -645,21 +625,13 @@ See [full report](L2/stETH-on-Optimism-2024-06-Ackee-Blockchain-Audit-report.pdf See [full report](L2/stETH-on-Optimism-2024-06-MixBytes-Audit-Report.pdf) for more details. -## 07-2024 Cantina wstETH on Mode Verification Report +### 07-2024 Cantina wstETH on Mode Verification Report The deployed contracts are verified against the [wstETH on Base](https://docs.lido.fi/deployed-contracts/#base) deployment. See [full report](L2/Mode-2024-07-18-Cantina-wstETH-deployment-verification.pdf) for more details. -## 10-2024 Quantstamp wstETH on Zircuit Verification Report - -The deployed contracts are verified against the [wstETH on Optimism](https://github.com/lidofinance/lido-l2) and [Governance crosschain bridges](https://github.com/lidofinance/governance-crosschain-bridges) references together with the [proposed setup](https://docs.lido.fi/token-guides/wsteth-bridging-guide#the-proposed-configuration) initialization. - -See [full report](L2/Zircuit_2024-10-02-Quantstamp-wstETH-deployment-verification.pdf) for more details. - -# BSC audit reports - -## 07-2024 MixBytes Lido a.DI Audit +### 07-2024 MixBytes Lido a.DI Audit - Total Issues: 13 (13 Acknowledged) - Critical Issues: 0 @@ -669,8 +641,36 @@ See [full report](L2/Zircuit_2024-10-02-Quantstamp-wstETH-deployment-verificatio See [full report](bsc/MixBytes%20Lido%20a.DI%20Security%20Audit%20Report%2007-2024.pdf) for more details. -## 08-2024 Oxorio wstETH on BNB Verification report +### 08-2024 Oxorio wstETH on BNB Verification report The deployed contracts are verified in accordance to the [proposal](https://research.lido.fi/t/wormhole-x-axelar-lido-bridge-implementation-for-wsteth-on-bnb-chain/6012) See full [initial](bsc/Lido-wstETH-on-BNB-Deployment-Verification-Report.pdf) and [remediated](bsc/Lido-wstETH-on-BNB-Deployment-Verification-Report-remediated.pdf) reports for more details. + +### 10-2024 Quantstamp wstETH on Zircuit Verification Report + +The deployed contracts are verified against the [wstETH on Optimism](https://github.com/lidofinance/lido-l2) and [Governance crosschain bridges](https://github.com/lidofinance/governance-crosschain-bridges) references together with the [proposed setup](https://docs.lido.fi/token-guides/wsteth-bridging-guide#the-proposed-configuration) initialization. + +See [full report](L2/Zircuit_2024-10-02-Quantstamp-wstETH-deployment-verification.pdf) for more details. + +## Lido on Polygon PoS + +### 04-2022 Lido On Polygon Smart Contracts Security Audit Report for PR#69 + +- Total Issues: 9 (4 Fixed, 1 Acknowledged, 1 No Issue) +- Critical Issues: 0 +- Major Issues: 0 +- Warning Issues: 0 +- Info Issues: 9 (4 Fixed, 1 Acknowledged, 1 No Issue) + +See [full report](polygon/Oxorio%20Lido%20on%20Polygon%20pr69%20report%2004-2022.pdf) for more details. + +### 08-2022 Oxorio Lido on Polygon V2 + +- Total Issues: 107 (61 Fixed, 11 Acknowledged, 35 No Issue) +- Critical Issues: 0 +- Major Issues: 0 +- Warning Issues: 14 (12 Fixed, 2 No Issue) +- Info Issues: 93 (49 Fixed, 11 Acknowledged, 33 No Issue) + +See [full report](polygon/Oxorio%20Lido%20on%20Polygon%20V2%2008-2022.pdf) for more details.