# How Lido Works - Full Content --- ## Section: Lido Essentials --- # Staking Basics ![](https://lido.fi/static/from-cms/how-lido-works/staking_overview.png) Lido is open-source software on Ethereum that makes it easier for people and organizations to stake ETH, earn rewards, and support the security of the network. Liquid staking connects individuals and institutions looking to stake their ETH (provide security to the Ethereum network and earn staking rewards) with Node Operators running the infrastructure required for staking. The Lido protocol further enables users to mint transferable liquid staking tokens that receive rewards linked to staking, unlocking other activities, including DeFi. Staking on Ethereum involves locking 32+ ether (ETH) to secure the blockchain by running a network validator. Validators propose and validate blocks, earning rewards for performing their duties timely and correctly, or facing penalties for downtime or rule violations. Staking can be approached in three main ways: #### Solo Staking The original, most decentralized method requires the solo staker to run their own validator node. It demands 32 ETH+ per validator, technical expertise, and ongoing maintenance. Solo stakers have full control over funds and keys and bear all operational responsibilities and risks. **32+ ETH** · **To run your node** · **High level** - - - #### Delegated Staking Delegated staking involves delegating the staker's ETH to a third-party service provider, which is often a single Node Operator, but may be a custodial service that sub-contracts to Node Operators. This approach lowers technical barriers and reduces the minimum ETH requirement to stake. Depending on the setup, delegated staking can be custodial or non-custodial, meaning the staker may retain full control over their own funds or entrust them to the service provider. It also relies on the provider's integrity and security practices. **32+ ETH** · **To delegate** · **Low level** - - - #### Liquid Staking Staking through a liquid staking protocol like Lido is the easiest way to stake. ETH deposits receive a token representing staked ETH. Liquid staking tokens accrue rewards (and potential penalties) and can be freely transferred, used in DeFi, or redeemed for ETH, combining staking rewards with liquidity. **ETH** · **Any amount** · **Not needed** [Learn more](https://ethereum.org/en/staking/) --- # Lido Staking Protocol ![](https://lido.fi/static/from-cms/how-lido-works/staking_protocol.png) The Lido Staking Protocol ("Lido") is staking middleware that lets users participate in decentralized Ethereum staking without locking up their tokens. By staking through Lido, users receive a liquid token called stETH, which represents the staked ETH and reflects earned rewards (or accrued penalties), all while remaining usable within DeFi and the broader ecosystem. Lido operates via a set of smart contracts on Ethereum that manage deposits, reward distributions, and withdrawals in a non-custodial manner. Additionally, off-chain services tightly integrate with the protocol to support proper operations for deposits, withdrawals, and accounting flows. The Lido Protocol involves three major actors and their interactions: #### Staking Users Individuals or entities who wish to stake their ETH and receive stETH through the Lido protocol. --- #### Node Operators Individuals or entities that run validators using ETH provided by staking users in a non-custodial manner. [Learn more.](https://lido.fi/how-lido-works/lido-node-operators-set-overview) --- #### Lido DAO A Decentralized Autonomous Organization (DAO) that oversees the protocol's long-term development and maintenance. It is governed by LDO (Lido governance token) token holders approving upgrades, deciding on key parameters and setting fees, facilitating node-operator participation and managing oracle operator sets, and empowering committees to handle defined operational tasks. [Learn more.](https://lido.fi/how-lido-works/how-the-lido-dao-works) --- # Lido Core Staking User Flow ![](https://lido.fi/static/from-cms/how-lido-works/userflow.png) The Lido protocol has two different staking flows: Lido Core, the established and widely recognized staking flow, and stVaults, a cutting-edge staking primitive that will be introduced in the upcoming [Lido V3](https://v3.lido.fi/). Submitting ETH to the Lido Core Protocol initiates a seamless staking process. Deposited ETH is gathered in the Lido Buffer, and in return, you immediately receive stETH tokens. Buffered ETH is used either to activate new validators on the Consensus Layer, depending on staking demand, or to fulfill stETH-to-ETH withdrawal requests, ensuring efficient liquidity management. > ##### Lido Buffer > > When you stake via the Lido protocol, your ETH is first placed in the Lido Buffer, the ETH balance of the Lido stETH token contract. The buffer gathers deposits until there’s enough ETH to activate new validators in 32 ETH increments, and then deposits this ETH to the Beacon Chain, taking into account gas costs and staking efficiency. This process is overseen and effected by the Deposit Security Module. > > The buffer also enhances liquidity for stETH redemptions. If users want to exit their stETH positions, the buffer prioritizes fulfilling these requests, minimizing the need to exit validators and avoiding delays associated with validator withdrawal periods. > ### Minting stETH ![](https://lido.fi/static/from-cms/how-lido-works/minting.png) When you deposit ETH into Lido Core, you receive stETH tokens at a 1:1 ratio. These tokens represent your share of the staked ETH, including rewards earned and penalties incurred. As an ERC-20 token, stETH is fully transferable and can be used across DeFi, maintaining liquidity while your tokens remain staked. Rewards and penalties are socialized amongst all stETH holders, which means that all stETH is fungible. From the moment stETH is minted, you start accruing rewards and are exposed to potential penalties. You can track your rewards by entering your wallet address [here](https://stake.lido.fi/rewards). If you are using wrapped stETH (wstETH), note that your balance does not change with each rebase. Instead, the value of wstETH increases over time to reflect accrued rewards. ### Routing Deposits to Validators ![](https://lido.fi/static/from-cms/how-lido-works/routing.png) Users do not select specific modules or node operators for staking. Once the Lido Buffer accumulates enough ETH, the Staking Router automatically allocates it to validators. The router distributes ETH across the connected staking modules — Curated Registry Module, Community Staking Module (CSM), and Simple Distributed Validator Technology (SimpleDVT) — following the programmatic allocation rules defined within the Lido smart contracts. Each module has its own rules with respect to how stake is allocated to depositable validators. Deposited ETH is then locked in Ethereum’s staking deposit contract on the Execution Layer and credited to the corresponding validators on the Consensus Layer, enabling them to secure the network. For more information, check out the detailed explanations in the Node Operator Portal for each module: [Curated Module](https://operatorportal.lido.fi/modules/curated-module), [Simple DVT Module](https://operatorportal.lido.fi/modules/simple-dvt-module), [Community Staking Module](https://operatorportal.lido.fi/modules/community-staking-module). --- # Rewards and penalties ![](https://lido.fi/static/from-cms/how-lido-works/rewards_and_penalties.png) Via the Lido protocol, stETH holders receive rewards (or penalties) from staking based on the performance of Lido-participating validators in Ethereum’s proof-of-stake network. As stETH is a rebasing token, rewards are continuously (on a daily basis) reflected in your stETH balance, providing a seamless staking experience. For users who prefer a value-accruing token approach, stETH can also be wrapped into wstETH. ### How Rewards and Penalties Are Calculated The Lido oracle mechanisms are responsible for maintaining the connection between the Execution Layer and Consensus Layer portions of the Lido protocol. As a part of this set of activities, oracles synchronize data between the Execution and Consensus Layers, reflecting validator rewards and penalties for stETH holders via the daily rebase mechanism. Validators earn rewards by proposing and attesting to new blocks, activities critical to Ethereum’s security. Rewards and penalties are determined algorithmically by the Ethereum consensus mechanism and depend on factors like validator uptime, correctness, and timeliness of duty performance, and general network conditions. Validator rewards come in two forms: * **Consensus Layer rewards**: Determined by network rules, these include block proposal and attestation rewards, distributed predictably based on validator performance. * **Execution Layer rewards**: These dynamic rewards include transaction tips (priority fees) and possible Maximal Extractable Value (MEV) rewards, which depend on demand for blockspace, network congestion, and block building effectiveness. > ##### MEV and Lido Validators > > MEV (Maximal Extractable Value) refers to additional rewards earned by validators through optimized transaction ordering in block proposals. Using tools such as MEV-Boost, validators can outsource block building activities to block builders and MEV searchers to capture extra value. For blocks proposed by Lido validators, MEV rewards are sent by builders to the Lido Execution Rewards Vault, meaning that this income benefits both node operators as well as stETH holders. Validators follow block proposal requirements set by the Lido DAO, which guides which guides how stakers are rewarded while maintaining network fairness. #### stETH token rebase The stETH balance updates automatically to reflect the portion of rewards earned or penalties incurred by the wider Lido validator set, ensuring that the staker's balance updates automatically without any required user action. This process, known as a token rebase, occurs daily around 12:30 UTC based on data provided by the Lido AccountingOracle, though the exact timing may vary. The oracle report supplies the protocol with validator states, facilitates stETH withdrawal requests, and adjusts the total stETH supply (reflecting the rewards or penalties accrued by the validators underlying the protocol). The rebasing process algorithmically updates balances to account for: * Staking rewards (or penalties, including possible slashings) from the Consensus Layer, * Execution Layer rewards collected, * Changes due to fulfilled withdrawal requests. In Lido, stETH rebases using a shares-based system. Instead of tracking individual balances directly, the protocol records the share of the total pool owned by each account. Your balance is calculated as: > ``` > balanceOf(account) = shares[account] * totalPooledEther / totalShares > ``` #### Oracles The Lido protocol utilizes oracles to bridge the communication gap between Ethereum’s Execution Layer, where the Lido smart contracts reside, and the Consensus Layer, where validators function. This mechanism is required due to the limited native channels between the two layers. Oracles supply the protocol with real-time validator states, balances, and additional off-chain data necessary for protocol functionality. Oracles work by gathering data using deterministic algorithms, with a quorum of 5 out of 9 participants required to validate and deliver reports to the protocol. Built-in safety mechanisms verify Oracle data to prevent disruptions caused by anomalies or malicious inputs. Key oracles in the protocol include: * **AccountingOracle**: Handles updates to the protocol’s accounting balances, including rewards, penalties, withdrawal finalization, and historical data. Reports are generated daily around 12:30 UTC. * **ValidatorsExitBusOracle**: Alerts node operators to initiate validator exits, enabling users to withdraw ETH. Reports are provided three times daily, approximately at 12:30, 20:30, and 4:30 UTC. * **CSM Performance Oracle**: Dedicated to *the* Community Staking Module (CSM), it tracks detailed node operator performance metrics to fairly distribute rewards based on participation. * **stVaults LazyOracle**: Handles accounting report for stVaults. It uses an on-demand approach that allows the protocol to support an unlimited amount of stVaults. AccountingOracle supplies the Merkle root of all vaults’ state, while individual stVault updates happen on-demand permissionlessly. --- # Protocol Fee ![](https://lido.fi/static/from-cms/how-lido-works/protocol_fee.png) One can consider the Lido protocol as a protocol that connects three actors: the Lido DAO, stakers (stETH holders), and Node Operators (independent third parties that run validators using the Lido protocol). For the protocol to be sustainable, a protocol fee is incurred on staking rewards, which works by "splitting" rewards during the rebase process across these three actors. Lido charges a protocol fee (currently 10%) on the rewards accumulated by the staked ETH underlying the protocol. This fee sustains the protocol’s operations, supports infrastructure, and funds ecosystem development. It is automatically apportioned as a part of the daily rebase process during the rewards distribution phase. The protocol fee is waived during periods of negative net rewards, when Consensus Layer penalties exceed earned rewards. The fee rate is set by the Lido DAO through on-chain governance, subject to alignment with the protocol’s needs and user interests. The protocol fee is split into two parts: #### Node Operator Fee Compensates node operators for managing validators and maintaining network reliability. #### Treasury Fee Supports Lido DAO operations, infrastructure costs, and long-term research and development efforts. Each staking module has a distinct fee split as set by the Lido DAO in each module's configuration: --- # APR and Rewards Calculator Protocol APR means Annual Percentage Rate (APR) — the overall Consensus Layer (CL) and Execution Layer (EL) rewards received by Lido validators relative to total ETH in the protocol. APR may be calculated over a variety of time ranges. The APR displayed on Lido UI is calculated as a rolling moving average over the last 7 days. The detailed info could be found [here.](https://docs.lido.fi/#protocol-apr) > ##### APR Calculation > > To estimate the protocol's APR over a historical period and calculate rewards for a specific account, you can track the change in the `totalPooledEther / totalShares` value over time, known as the share rate. This value defines how much ETH corresponds to the underlying minted stETH token shares and changes only during the stETH token rebase event (accessible programmatically in the Lido contract as `TokenRebased`). > > ``` > // Emits when token rebased (total supply and/or total shares were changed) > event TokenRebased( > uint256 indexed reportTimestamp, > uint256 timeElapsed, > uint256 preTotalShares, > uint256 preTotalEther, /* preTotalPooledEther */ > uint256 postTotalShares, > uint256 postTotalEther, /* postTotalPooledEther */ > uint256 sharesMintedAsFees /* fee part included in `postTotalShares` */ ); > > preShareRate = preTotalEther * 1e27 / preTotalShares > postShareRate = postTotalEther * 1e27 / postTotalShares > > userAPR = secondsInYear * > ( (postShareRate - preShareRate) / preShareRate ) > / timeElapsed > ``` --- # Withdrawals ![](https://lido.fi/static/from-cms/how-lido-works/withdrawals.png) Withdrawing staked ETH from Lido can be done through the protocol's Withdrawal Queue or by swapping stETH on secondary markets, providing flexibility for users based on their needs and market conditions. #### Protocol Withdrawal Queue To redeem stETH for ETH, users can utilize the Lido protocol's native withdrawal process. By placing stETH in the Withdrawal Queue, users join a First-In-First-Out (FIFO) line. The maximum withdrawable ETH amount matches the stETH provided for redemption and cannot exceed this amount. While in the queue, users remain exposed to slashing risks — this prevents attempts to avoid losses that are socialized across the protocol. Withdrawal time depends on the queue size, Ethereum's validator exit rate, and the available ETH in the Lido Buffer. Estimated wait times are displayed before submitting or checking requests on the [stake.lido.fi](https://stake.lido.fi/withdrawals/request) interface. Details of the estimation algorithm are available [here](https://github.com/lidofinance/withdrawals-api/blob/develop/how-estimation-works.md). --- #### Secondary Markets As a liquid token, stETH can be traded on decentralized (DEXs) or centralized exchanges (CEXs) without waiting for the unstaking process. Selling stETH for ETH or other tokens provides instant liquidity, but the price may differ from ETH based on market supply and demand. Unlike stablecoins, stETH is intentionally not pegged to ETH. --- #### Withdrawal Queue Process #### 1. Request Submission ![1. Request Submission](https://lido.fi/static/from-cms/how-lido-works/withdrawals_1.png) Lock stETH in the WithdrawalQueue contract to initiate withdrawal and receive an unstETH (see below) representing the queued position and projected ETH amount. --- #### 2. Buffer Usage ![2. Buffer Usage](https://lido.fi/static/from-cms/how-lido-works/withdrawals_2.png) The Lido Buffer prioritizes fulfilling withdrawals using available ETH. If insufficient, validators are exited to meet the demand. --- #### 3. First In, First Out (FIFO) Order ![3. First In, First Out (FIFO) Order](https://lido.fi/static/from-cms/how-lido-works/withdrawals_3.png) Withdrawals follow a FIFO order, finalized in daily batches when the AccountingOracle updates protocol balances and burns the corresponding stETH. --- #### 4. Claiming ETH ![4. Claiming ETH](https://lido.fi/static/from-cms/how-lido-works/withdrawals_4.png) Once finalized, users burn their unstETH NFT to receive ETH, completing the process. Withdrawal times depend on queue size, buffer availability, and validator exit dynamics. High demand may increase wait times, with secondary markets providing an alternative for quick liquidity --- #### unstETH **unstETH** is a non-fungible token (NFT) that represents withdrawal requests you've placed in the protocol. When you initiate a withdrawal, unstETH is minted to represent your position in the withdrawal queue. This token is transferable and can potentially be integrated into DeFi applications. Each unstETH token includes: - A unique incremental ID representing your position within the withdrawal queue. - The amount of stETH you've requested to withdraw. - Once finalized and not yet claimed, the amount of ETH to be transferred to you. When you claim your ETH, the unstETH token is burned, completing the withdrawal process. --- # stVaults Basics ![](https://lido.fi/static/from-cms/how-lido-works/stvaults-basics.png) Ethereum staking comes with a trade-off between control and liquidity. With native staking, the staker keeps full control and can choose their operator, fees, and software, but staked ETH stays locked until it's exited from the withdrawal queue. With liquid staking through Lido's Core Pool, liquidity comes back as stETH at a 1:1 rate, but validator choice is lost because the protocol automatically distributes stake across a range of modules. stVaults is designed to give stakers a new alternative that combines control and liquidity. Introduced in Lido V3, stVaults are non-custodial smart contracts that let a staker delegate ETH to a chosen operator while keeping control of the withdrawal credentials. stETH can be minted on-demand against staked deposits to give stakers liquidity without the obligation and time delays that come with exiting native staking positions. The result is a more open validator marketplace where stakers pick operators and terms while still staying connected to the stETH ecosystem. ### Motivation Lido Core works for most stakers because it is simple, liquid, and widely integrated across DeFi. As the staking market grows to include new participants, new use cases are emerging that are not addressed by the shared pool model. Institutional stakers often need dedicated setups with specific node operators to meet compliance requirements, maintain auditable relationships, and keep assets segregated. Node operators want to attract stake directly instead of waiting for Lido's Staking Router to allocate it to them. Vault builders and asset managers want to create leverage strategies, restaking products, and structured reward bearing instruments that a shared pool was never built to support. stVaults sit alongside the Core Pool as a modular building block. Each stVault is independent, with a single operator and a single owner. These two parties set the parameters, including fees, validator configuration, and risk tolerance. With stVaults, Lido shifts from a liquid staking protocol to Ethereum staking infrastructure. It becomes a shared platform where different staking setups can coexist, with stETH as the common liquidity layer. ### **Who Uses stVaults** Delegate your ETH to a third-party Node Operator who runs validators for you. This approach lowers technical barriers and reduces the minimum ETH requirement. Depending on the setup, delegated staking can be custodial or non-custodial, meaning you may retain full control over your funds or entrust them to the operator, and relies on the operator's integrity and security practices. #### Institutional Stakers ![Institutional Stakers](https://lido.fi/static/from-cms/how-lido-works/insti-stakers.svg) ETFs, ETPs, custodians, and liquid funds can set up dedicated vaults with specific operators, control who can deposit, and manage withdrawals under their own rules. The setup stays non-custodial: vault owners keep control, and stETH liquidity remains available to process withdrawals.\n\nMany institutions cannot use shared pools where the counterparty relationship is effectively undefined. stVaults let them stake with a specific operator under a clear, auditable arrangement while still getting liquid staking economics. --- #### Node Operators ![Node Operators](https://lido.fi/static/from-cms/how-lido-works/node-operator.svg) stVaults create an entirely new business model for Node Operators, enabling them to build bespoke staking setups backed by stETH liquidity, and keeping direct ownership over staking rewards. Operators can launch vaults, offer stakers access to stETH under customized terms, and run multiple vaults in parallel with different stakers, geographies, fee structures, and validator configurations. This creates a direct channel to institutional capital, while maintaining the network advantages that come with stETH, including DeFi integration and market-leading liquidity depth.\n\nAs an example, a single operator might run one vault with a 3% fee for retail users, another at 1% for a large institutional client, and a third with custom validator client requirements for a compliance-sensitive fund. Each vault operates independently on the same operational infrastructure. --- #### Builders and Asset Managers ![Builders and Asset Managers](https://lido.fi/static/from-cms/how-lido-works/builder.svg) stVaults are composable building blocks. Restaking protocols can add extra reward layers, vault wrappers can create structured products, and yield tokenization platforms can provide early access to future rewards. The validator logic remains local to each vault while enabling integration with the broader DeFi ecosystem.\n\n[DeFi Wrapper](https://docs.lido.fi/run-on-lido/stvaults/building-guides/pooled-staking-product/), a simple low-code toolkit built on top of stVaults, extends this further by enabling teams to build pooled products, reward bearing strategies, and leverage loops. --- #### Advanced Stakers ![Advanced Stakers](https://lido.fi/static/from-cms/how-lido-works/advanced-stakers.svg) For capital-efficient strategies, stETH can be minted, posted as collateral on lending protocols, and used to borrow ETH to stake again. This enables leverage loops, restaking opportunities, and reward optimization, all built on top of a single underlying staking position. ### How stVaults Work stVaults extend the Lido protocol to include operator selection and vault customization. Stakers choose an operator and deposit ETH, with the option to unstake at any time. Minting stETH is optional. Minting is overcollateralized: only a portion of the vault's ETH can be used to back minted stETH, with the remainder held in reserve. To fully exit a vault with outstanding stETH, the minted amount plus accrued fees must be repaid first. The fundamental principle of stETH remains unchanged: one stETH represents one staked ETH and can be redeemed through the withdrawal queue. What differs is the backing structure. Previously, all backing came from the Core Pool. Now two sources exist: ETH held within the Core Pool (internal backing) and ETH staked through stVaults (external backing). Both contribute to the total stETH supply. The Core Pool serves as the APR oracle that stVaults use for fee calculations. Without it, the system could neither price stVault fees consistently nor guarantee stETH redeemability. > ##### Overcollateralized Minting > > Core Pool mints stETH at a 1:1 ratio. stVaults stETH is overcollaterized. stVaults retain a portion of deposited ETH - defined by the Reserve Ratio - as a buffer against slashing losses. This overcollateralization preserves stETH fungibility. ### stVaults vs Lido Staking Protocol ### Core Actors: #### Vault Owner The staker owns the vault, deposits ETH, and controls the staking position. The vault owner selects the operator, decides whether to mint stETH, and retains authority over all operational decisions: additional deposits, withdrawals, minting, repayment, and rebalancing. The vault owner and operator bear primary economic responsibility for the position, including maintaining collateralization. --- #### Node Operator The party that runs validators using the vault's ETH. Operators determine which validators receive deposits, manage validator lifecycle, and earn fees on staking rewards. A single operator can manage multiple vaults. Operators hold validator keys for performing duties but cannot access deposited funds because withdrawal credentials are controlled by the vault contract. --- #### Lido DAO The governance layer that sets protocol-level parameters: fee rates, risk thresholds, operator onboarding criteria, and vault upgrade policies. Individual vaults retain autonomy over their own configurations within the boundaries established by governance. ### Infrastructure Each vault is isolated, but it still depends on Lido Protocol services: **VaultHub** serves as the central registry and coordination point for protocol services. Vaults call VaultHub to mint and burn stETH. VaultHub enforces minting limits, reserve requirements, and fee collection. **OperatorGrid** organizes vaults by risk tier and operator. It assigns reserve ratios, share limits, forced rebalance thresholds, and fee rates. It tracks cumulative stETH minted across all vaults. **PredepositGuarantee (PDG)** protects against front-running vulnerabilities during validator deposits: a risk that could otherwise allow operators to steal deposited funds. **LazyOracle** handles accounting reports for vaults. It verifies data from the oracle network and forwards updates to VaultHub. Suspicious value increases - anomalous reward spikes - are quarantined for three days before being credited, preventing oracle manipulation. **VaultFactory** deploys verified vault instances in a single transaction. VaultHub rejects any vault not deployed through the factory, ensuring contract code is verified and storage is untampered. --- # Economy The economics align incentives across stakers, operators, and the protocol to support sustainable, long-term value creation in the Ethereum staking ecosystem. ### Reward Generation Rewards derive from staking rewards. Validators earn staking rewards by proposing and attesting to blocks on the Ethereum network. There are two categories of rewards: * **Consensus layer rewards** are deterministic. They are governed by network rules, proportional to validator performance and uptime. * **Execution layer rewards** are variable: transaction tips, MEV, and other block-building rewards. The vault's total value grows as validators accumulate rewards. Fees are deducted, and the remainder accrues to the staker. ### Fee Flows **Stakers** deposit ETH and earn rewards net of fees. There is also a liquidity fee for those who mint stETH. **Node operators** run validators and collect a fee on the staking rewards those validators generate. **The DAO** provides shared infrastructure including oracles, infrastructure, stETH minting mechanics and charges a fee on staking rewards. ### Fee Structure There are two categories of fees, configured per vault and collected automatically by the protocol: #### Node Operator Fee Node Operator Fees are an optional fee charged on actual staking rewards generated by the vault's validators. The rate is agreed upon by the owner and operator, and can be set to zero. Fee accounting uses a high-water mark approach calculated on growth, meaning any ETH that wasn’t deposited to the vault is considered the growth amount (MEV, tips, CL rewards). This ensures operators are compensated for value they generate, and negative performance periods do not accrue fees until the vault recovers past its previous high. This fee mechanism is only available for vaults using [Dashboard](https://docs.lido.fi/contracts/dashboard#what-is-dashboard). Advanced stakers can implement their own operator accounting arrangements outside the Lido protocol. --- #### DAO Fees **Infrastructure fees are** charged on "deemed" rather than actual rewards. The protocol calculates what the vault *would* have earned at the Core Pool's APR. The infrastructure fee is a percentage of this deemed amount. **Liquidity fees** are charged on minted stETH and accumulates over time while the stETH remains outstanding. Stakers who never mint never pay this fee. **Reservation fees** secure the right to mint stETH at a specific reserve ratio. The reservation fees are currently set at 0%. > [Default Parameters](https://research.lido.fi/t/default-risk-assessment-framework-and-fees-parameters-for-lido-v3-stvaults/10504#p-22550-proposed-fee-parameters-for-the-stvaults-launch-8): > Infrastructure fee: 1%. Liquidity fee: 6.5%. Reservation fee: 0%. These are tier-level defaults; the DAO can adjust them globally or per vault. --- #### Relationship to stETH APR The DAO's infrastructure fee uses Core Pool APR as a reference rate, effectively treating it as an oracle for normal staking returns. The DAO thus receives a consistent share of expected returns regardless of individual vault performance. The staker's economics depend on how their chosen operator performs relative to the network average. Outperformance accrues to the staker after fees. Underperformance is borne by the staker. This separation creates clear incentives: operators are motivated to maximize performance, stakers are motivated to select capable operators. --- #### Fee Settlement Protocol fees settle permissionlessly through VaultHub. Any party can trigger settlement. Until fees are settled, the vault faces restrictions including limited withdrawals and reduced minting capacity. The protocol does not allow vaults to accumulate fee obligations indefinitely. Node Operator fees (for vaults using Dashboard) also settle permissionlessly. Settlement computes the fee using the high-water mark, and pays the fee to the configured recipient from the vault's available balance. --- # Enablers ### Web UI [A web interface](https://stvaults.lido.fi/) for managing vaults without direct contract interaction. Vault owners can create and configure vaults, deposit and withdraw ETH, mint and repay stETH, and monitor vault health and performance. ### CLI [A command-line toolkit](https://github.com/lidofinance/lido-staking-vault-cli) for operators and technical users. It supports the full range of vault operations: deployment, configuration, validator management, reward distribution, and withdrawal queue handling, with scripting and automation. ### VaultFactory [Handles vault deployment in a single transaction](https://docs.lido.fi/contracts/staking-vault-factory). It creates a StakingVault and its management Dashboard, initializes parameters, and sets permissions. Two paths are available: owner-initiated (connecting to VaultHub immediately after funding the 1 ETH deposit) or operator-initiated (creating the vault for later connection by the owner). VaultHub accepts only factory-deployed vaults. Any other deployment is rejected, ensuring verified code and untampered storage. --- # DeFi Wrapper ![](https://lido.fi/static/from-cms/how-lido-works/defi-wrapper.png) The [DeFi Wrapper](https://docs.lido.fi/run-on-lido/stvaults/building-guides/pooled-staking-product/) is a toolkit that enables builders, operators, and platforms to launch user-facing staking products powered by stVaults with optional automated rewards-boosting strategies. While stVaults are single-owner, single-operator contracts by design, many practical use cases require pooled access with multiple users depositing into a single staking setup managed by an operator. The DeFi Wrapper addresses this by providing pre-built modules for pooled staking on top of stVaults. ### Product Archetypes Pooled Delegated Staking: Multiple users stake ETH with the same operator and earn APR from validator performance. Users deposit ETH, receive stvToken shares representing their portion, and earn through share price appreciation. Suitable for end-user products with conservative, validation-based returns. > stvToken is a reward-bearing ERC-20 token that represents a user’s share in the vault’s pool. The tokens can be transferred, integrated into other DeFi protocols and redeemed for the underlying ETH through the DeFi Wrapper withdrawal queue. Pooled Delegated Liquid Staking: The same pooled structure, but users can access stETH liquidity within the vault's reserve ratio. Useful for institution-facing products combining liquidity access with compliance features such as whitelisting. Boosted APR: Higher risk and higher potential rewards through leverage strategies. Strategy adapters optimize capital deployment to generate returns above staking rewards. This creates more validator exposure than the original deposit amount. Custom DeFi strategies are also supported through [the adapter interface](https://docs.lido.fi/run-on-lido/stvaults/building-guides/pooled-staking-product/custom-strategy). ### Architecture The DeFi Wrapper operates through four layers: Deposits and Withdrawals: the DeFi Wrapper accepts ETH deposits, funds the underlying vault, and issues stvToken shares. A withdrawal queue manages exits, requiring fresh oracle reports and enforcing minimum delays. stETH Wrapping: Enables liquidity access by minting stETH against stvToken positions, accounting for reserve ratio constraints. Strategy Adapters: For boosted products, adapters deploy per vault-strategy-user combinations, enabling automated leverage or reward optimization through third-party lending protocols. Utility Layer: Includes a web interface for end-users, a factory for single-transaction deployment, and CLI tools for operators. ### Withdrawal Queue All withdrawals proceed through a First In, First Out (FIFO) queue. Fresh oracle reports are required for processing, with a minimum one-day delay between request and finalization. If the share rate drops while a withdrawal is being processed, it is settled at the dropped rate, ensuring that users in the queue share any losses occurred during processing. ### Rewards Staking rewards flow through oracle reports and are reflected in stvToken price appreciation. Sidecar rewards are additional incentives from third-party protocols. They are handled through a RewardDistributor contract that allocates ERC20 tokens among DeFi Wrapper users based on their stvToken holdings. ### Pause and Upgradability DeFi Wrapper contracts support granular pausing of deposits, minting, withdrawals, and finalization. An emergency committee can pause any of these independently for immediate vulnerability response but cannot unpause. Resuming requires governance action through the timelock. ### Risks 1. **Smart contract complexity**: Additional contracts and interactions increase implementation complexity and expand the risk surface. 2. **Leverage risk**: Leveraged strategies can be liquidated if the stETH/ETH ratio moves unfavorably. 3. **Oracle dependency**: Reward accounting and withdrawal processing depend on fresh and correct oracle reporting. 4. **Liquidity constraints**: Large withdrawals may require validator exits, which can delay settlement and increase execution risk. 5. **Strategy risk**: External strategy adapters and third-party protocol integrations can introduce additional failure modes. 6. **Node operator risk**: Operators affect deposits, finalization timing, and report freshness, which can impact user outcomes. Mitigations include auditing, conservative health factors for leverage, quarantine periods for suspicious oracle values, strategy whitelisting, position limits, and the PredepositGuarantee for deposit protection. --- # Risk Framework Staking through stVaults involves several risk categories. Each has corresponding mitigations built into the protocol design: ### Slashing and Operational Risk Validators can be penalized if they violate network rules, for example by signing conflicting messages, or if they stay offline for extended periods. If several validators run by the same operator fail at the same time, the losses can snowball because Ethereum increases penalties for correlated failures. Even without slashing, long downtime reduces rewards, which degrades the vault’s performance over time. The Reserve Ratio is a key safeguard intended to reduce slashing-related risk. It sets how much of a vault’s ETH must stay as a buffer when minting stETH. For example, with 100 ETH and a 10% reserve ratio, the vault can mint up to 90 stETH and keep 10 ETH in reserve. That reserve is meant to absorb losses first if slashing happens, though it cannot guarantee protection in every scenario. The ratio is set based on the operator’s risk profile, total stake, external exposures, and Ethereum’s correlated-penalty mechanics. Two additional requirements apply: the connect deposit (1 ETH) prevents spam vaults, and the slashing reserve locks extra ETH when validators are undergoing active slashing. ### Concentration Risk Large operators create a bigger systemic risk. If one operator holds a lot of stake and several of its validators get slashed at the same time, the resulting losses can be large enough to matter beyond a single vault. OperatorGrid is the mechanism designed to reduce that concentration risk. It groups vaults into tiers with different reserve ratios, share limits, and fee rates. New vaults start in the default tier with a high reserve ratio (currently 50%). Operators with an established track record can register custom groups where higher tiers require more reserve as the operator’s total stake grows. The intent is to add economic friction against centralization. As an operator’s exposure increases, collateral requirements increase too, which can make smaller operators more attractive. Early stakers keep the terms they entered with, so a Tier 1 vault keeps Tier 1 conditions even if the operator later grows into Tier 3. ### Undercollateralization A vault can become undercollateralized if losses or weak performance reduce its ETH value. Slashing, penalties, and extended downtime can all push collateral below required levels of backing for minted stETH. The Health Factor measures whether collateral is sufficient: > Health Factor = Total Value × (1 − Forced Rebalance Threshold)/stETH Liability At or above 100%, the vault is adequately collateralized. Below 100%, the vault is past its target buffer and needs to be restored. VaultHub tracks obligations in priority order: health obligations (liability shares that can trigger force-rebalancing), redemption obligations (the vault’s contribution to system-wide stETH redemptions), and fee obligations (outstanding protocol fees). These obligations limit withdrawals and reduce how much new stETH can be minted. Corrective measures: the vault owner can add more ETH, repay stETH liability, or rebalance by sending ETH to the Core Pool in exchange for reducing liability. If the reserve falls below the Forced Rebalance Threshold, permissionless rebalancing becomes available. The threshold is set slightly below the reserve ratio (for example, 49.75% vs 50%) to avoid triggering on small fluctuations. If the ETH is still on the consensus layer, EIP-7002 can enable forced validator withdrawals. Bad debt escalation: if losses get so large that the vault’s ETH value drops below its stETH liability, the system follows an escalation path. First, the vault owner is expected to top up. If that does not happen, losses can be spread across the operator’s other vaults, then covered by any available reserve or coverage. As a last resort, remaining losses can be absorbed at the protocol level by reducing stETH rebase. Governance can also jail a vault to halt new minting while the issue is addressed. ### Oracle Risk stVaults depend on oracle accounting. If reports are wrong or delayed, vault health can be misread. That can lead to unnecessary rebalancing, or in the other direction, allow minting when collateral is weaker than it appears. LazyOracle is the control layer designed to reduce that risk. It publishes accounting reports with total value, validator states, and accumulated rewards or penalties. Suspicious value increases are quarantined for three days before being credited, which helps limit manipulation. If reports go stale, minting and withdrawals are restricted until fresh data is posted. ### Governance Risk The DAO can upgrade vault code and change protocol parameters. If governance is ever compromised, those powers could be used in ways that hurt vault owners, such as raising collateral requirements or changing fees. If a vault has no outstanding stETH, the owner can disconnect from VaultHub and permanently freeze the vault's code by pinning the current implementation address. The vault then operates fully under owner control, rejecting any future DAO upgrades at the cost of losing the ability to reconnect to the Lido protocol. ### Deposit Frontrunning Risk During validator deposits, a malicious operator could try to front-run the transaction and submit a deposit with different withdrawal credentials, effectively redirecting the withdrawals. PredepositGuarantee’s bond requirement is intended to discourage this attack. Validator activation starts with a 1 ETH deposit, and the operator must post a matching 1 ETH bond for each validator. Once the validator is live, the operator proves the withdrawal credentials point to the vault. If the proof is correct, the bond is released back to the operator. If not, the bond is confiscated and paid to the vault. ### Liquidity Risk During market stress, many holders may try to redeem stETH at once, which can strain liquidity and slow withdrawals. The Core Pool is the main shared buffer used to process redemptions. Liquidity fees and limits on how large stVaults can grow relative to the Core Pool are designed to keep that buffer healthy. In more extreme conditions, vaults can be required to contribute ETH to support system-wide redemptions. ### Smart Contract Risk Undiscovered bugs are still possible, especially given the number of moving parts and integrations across vaults, VaultHub, oracles, and external protocols. Comprehensive auditing, formal verification where applicable, and upgradeability mechanisms reduce the risk surface for stVaults. The sovereignty mechanisms also limit the blast radius of any potential problems: vault owners can isolate themselves from protocol-level issues. ### Risk Distribution **Vault owners** bear primary risk: their collateral absorbs losses first, and they are responsible for maintaining adequate vault health. **Node operators** bear reputational and economic risk: poor performance leads to higher reserve requirements in subsequent tiers, and bad debt can be socialized across all their vaults. **stETH holders** benefit from overcollateralization. Only after all escalation steps are exhausted can vault-specific losses affect stETH supply through bad debt internalization. --- # Lido Node Operators Set Overview ![](https://lido.fi/static/from-cms/how-lido-works/node_operator_overview.png) #### What Node Operators Do Node Operators (NOs) are independent entities participating in the Lido protocol. They run the validators that secure Ethereum. They perform all duties required by the network: proposing and attesting to blocks, participating in sync committees, and maintaining validator uptime using ETH deposited through the Lido protocol. They operate under a _non-custodial model,_ which means they hold validator private keys, allowing them to perform validator duties, but cannot access or move user funds. The withdrawal credentials for every validator point to a protocol-controlled address called the Withdrawal Vault, meaning validator rewards and principal can only return to this address. This mechanism is defined by the Ethereum protocol itself and enforced by the Beacon Chain deposit contract, eliminating the possibility for any operator to redirect or seize assets. Lido protocol’s validator set is intentionally broad, comprising professional operators, community stakers, and distributed validator clusters. Together, they form a decentralized infrastructure layer. --- #### Validator Lifecycle and Key Control Before any ETH is staked, Node Operators register validator public keys with the Lido protocol. The protocol checks that each key is valid and unique before it can receive deposits. When the Lido Buffer has enough ETH to form new validators, the protocol deposits it automatically and securely. A built-in safeguard called the Deposit Security Module verifies deposit data and can pause deposits if something looks off. All deposit information is published on-chain for transparency. Each validator’s withdrawal credentials are fixed to Lido’s Withdrawal Vault, a protocol-controlled address. This means that, no matter what happens on the operator side, validator rewards and principal always flow back to the protocol, never to individual operators. Once activated, validators perform their duties on the Consensus Layer until they are exited, either by the protocol when withdrawals require it or by the operator under policy limits. In all cases, funds end up back in the Withdrawal Vault. --- #### Modules and Allocation Validators of the Lido protocol are organized into separate staking modules. Each module runs its own group of Node Operators and follows its own rules for joining, registering validator keys, and earning rewards. The Staking Router automatically directs new deposits between these modules to keep growth balanced and improve decentralization over time. The router uses a bottom-up approach: it allocates ETH to the module with the least active stake, as long as that module has free capacity and ready validator keys. This keeps stake growth balanced and naturally favors smaller modules, improving decentralization over time. The sections below outline how each module works: #### Curated Module ![Curated Module](https://lido.fi/static/from-cms/how-lido-works/Curated.png) The default, battle-tested module. It distributes deposits among professional NOs curated by the Lido DAO based on strict reliability and performance criteria. The curated operators registry is reviewed and adjusted via Lido DAO governance to maintain high standards and adapt to network needs. With no share limits, the module can absorb any amount of stake and serves as the fallback module when other, smaller modules are either at full capacity or do not have depositable validators. Node Operators in the Curated Module run validators as they see fit, including using DVT, with guidance from DAO contributors with regard to optimizing the decentralization of the protocol along the axes of geographic, jurisdictional, infrastructural, and software decentralization. [Learn more.](https://operatorportal.lido.fi/modules/curated-module) --- #### Simple DVT Module ![Simple DVT Module](https://lido.fi/static/from-cms/how-lido-works/DVT.png) The Simple DVT Module allows Node Operators of all types and sizes - from home stakers to professionals - to work in concert in so-called Operator Clusters to run validators together using Distributed Validator Technology (DVT). DVT improves fault tolerance by distributing a validator’s duties across multiple NOs. This approach reduces slashing risks and enhances security. Simple DVT houses clusters using both Obol and SSV DVT technologies. [Learn more.](https://operatorportal.lido.fi/modules/simple-dvt-module) --- #### Community Staking Module (CSM) ![Community Staking Module (CSM)](https://lido.fi/static/from-cms/how-lido-works/CSM.png) The CSM is the permissionless module of the Lido Core. Although any NO type can use the module, one of the core aims of CSM is to empower community stakers (individuals running validators in a non-professional capacity), thereby increasing the number of NOs using Lido to run validators and increasing the decentralization of the underlying validator set. As the module is permissionless, instead of reputation, CSM requires a stETH bond from operators. It employs automated performance monitoring and advanced mechanisms for validator withdrawal and slashing proofs, enhancing transparency and decentralization. [Learn more.](https://operatorportal.lido.fi/modules/community-staking-module) --- # How the Lido DAO works The Lido Protocol operates under the oversight of the Lido DAO, a decentralized autonomous organization governed by LDO token holders. The DAO manages key aspects of the protocol, including operator selection for permissioned modules, parameter adjustments, and upgrades through a phased governance process. With over [55,000 unique LDO token holders](https://etherscan.io/token/0x5a98fcbea516cf06857215779fd812ca3bef1b32), the Lido DAO stewards the protocol towards community and decentralization alignment. Additional safeguard for the protocol is provided by stETH holders via [the Dual Governance system](https://blog.lido.fi/dual-governance-101-explainer/) that allows them to delay contentious proposals before execution. #### LDO LDO is [the Lido DAO's governance token](https://etherscan.io/token/0x5a98fcbea516cf06857215779fd812ca3bef1b32). Built on the ERC-20 standard, it includes balance snapshotting functionality that calculates voting power based on token holdings from the block before voting begins. This prevents vote manipulation through last-minute market trades. --- #### Governance Process Lido DAO’s governance follows a multi-staged, publicly documented process designed to balance efficient decision-making, security, and transparency. The process is permissionless on several stages. Proposals begin [on the Research Forum](https://research.lido.fi/), where anyone can submit proposals and engage in community discussions. Refined proposals then move to [Snapshot voting](https://snapshot.box/#/s:lido-snapshot.eth) (requires 1,000 LDO to initiate; with insufficient balance, DAO Ops can help to submit). If supported, proposals requiring on-chain changes advance [to an Aragon vote](https://dao.lido.fi) divided into two phases (a main phase and an objection‑only phase). After an on-chain vote passes, proposals enter [Dual Governance](https://dao.lido.fi/dg), a dynamic timelock that allows stETH holders to review the decision and, if opposition arises, extend the execution delay. [Learn more](https://lido.fi/governance). --- #### Goal setting and funding framework The Lido DAO establishes strategic goals through [GOOSE (Guided Open Objective Setting Exercise)](https://research.lido.fi/t/the-guided-open-objective-setting-exercise-goose-proposal-a-genesis-step-to-jump-start-a-dao-wide-goal-setting-exercise-and-cadence/5355), an open process that sets one - and three-year objectives. Proposals are submitted on the Research Forum, refined through community discussion, and approved via Snapshot vote. To support achieving the approved goals, the DAO votes to fund grants using [the Ecosystem Grants gRequests (EGGs) framework](https://research.lido.fi/t/ecosystem-grants-grequest-egg-a-budget-request-framework-in-the-service-of-goose/6053). --- --- # Governance Stack ![](https://lido.fi/static/from-cms/how-lido-works/governance_stack.png) Lido DAO employs mature governance features aimed at enhancing security and accountability. #### Two-phase voting Lido DAO’s on-chain voting uses a two‑phase process to prevent last‑minute governance actions. The first phase allows votes for and against, while the second phase accepts only against votes, adding crucial time for voters to counter malicious proposals. The system is intentionally conservative, making it easier to block proposals than pass them, enhancing security. [Learn more](https://blog.lido.fi/lido-dao-governance-security-measures-oversight/) --- #### Delegation LDO holders can delegate their voting power on both off - and on-chain voting platforms. For Snapshot voting, delegation is managed using the platform's built-in mechanisms. For Aragon voting, Lido’s Delegation framework allows LDO holders to assign their voting power to another address, enabling delegates to vote on their behalf. LDO tokens remain fully under the tokenholder’s control to be transferred, sold, or used in any way. Delegated votes are counted alongside direct votes and can be tracked on the voting platform. The tokenholder can override the delegate’s decision or revoke delegation rights at any time. [Learn more](https://dao.lido.fi/vote/delegation). --- #### Dual Governance On-chain actions targeting Lido protocol features enter Dual Governance — a dynamic timelock that allows stETH holders to extend execution delay based on the opposition. Each proposal faces a minimum 3‑day delay; if no objections arise, it is scheduled and becomes executable after 24 hours. With over 1% of total stETH opposing, motions are blocked for 5–45 days; with over 10%, governance remains paused until the opposing stakers exit. [Learn more](https://blog.lido.fi/dual-governance-101-explainer/). --- #### Easy Tracks (Optimistic Governance) [The Easy Track](https://dao.lido.fi/easy-track) is an optimistic governance tool for routine DAO operations used to reduce voter fatigue. Only authorized multisig addresses can initiate Easy Track motions that pass automatically after 72 hours unless 0.5% of the total LDO supply objects. A notable case of optimistic governance implementation is [STONKS](https://research.lido.fi/t/lido-stonks-treasury-swaps-via-optimistic-governance/6860), a tool operated by the Treasury Management Committee (TMC) to maintain transparent and secure fund allocation. Swap orders are executed through CoW Protocol with MEV protection and price guarantees, and proceeds return directly to the DAO treasury. Other common Easy Track motions include updating node operator parameters, adjusting staking limits, or funding grants within predefined budgets. --- #### How to Engage **Propose:** Submit ideas on the Research Forum and contribute expertise by engaging in discussions. Participate in GOOSE cycles to help shape the DAO's direction. **Vote or Delegate:** LDO holders vote on proposals via Snapshot (off-chain) and Aragon (on-chain). Voting power [can be delegated](https://dao.lido.fi/vote/delegation) to trusted representatives while retaining full control; delegation can be overridden or revoked at any time. **Review:** Monitor protocol state via [Dune dashboards](https://dune.com/lido/lido-dashboards-catalogue), review decentralization progress [on the Scorecard](https://lido.fi/scorecard), attend [Tokenholder Update Calls](https://blog.lido.fi/recap-lido-q3-2025-tokenholder-update/) for the latest news from Lido Labs, read published reports, and subscribe [to the real‑time governance notification bot](https://t.me/lido_dao_bot). #### Governance checks and balances An incentive misalignment exists between LDO and stETH holders, posing a risk that LDO governance power could be misused to substantively alter the protocol or introduce upgrades that harm stakers. This risk is heightened [by **EIP-7002**](https://eips.ethereum.org/EIPS/eip-7002), which enables the DAO to use the Lido withdrawal credentials contract to trigger validator exits without Node Operator consent—making protocol-level attacks more feasible if governance is captured. Yet, a mass exit of validators would take a very long time (weeks to months), and it would give the DAO time to respond via further governance action. **Mitigation Measures**: - **Two-phase voting:** On-chain voting is divided into two parts, with the second being the objection phase that concludes every vote. It allows LDO holders to object to unexpected last‑minute decisions, effectively creating a ‘better timelock’ mechanism. - **Dual Governance**: Introduces a "foot voting" mechanism for stETH holders. It allows them to: - **Delay execution:** Extend the default 3-day timelock based on the level of opposition. - **Exit**: Exit the protocol before governance decisions take effect. For more details, read the [Lido Dual Governance stETH holder Guide](https://blog.lido.fi/participating-in-dual-governance-a-guide-for-steth-holders/). --- # Known Risks and Mitigations The Lido Protocol operates in a dynamic ecosystem where various risks must be actively managed. Below is an outline of key known risks affecting stakers, node operators, and the Lido protocol, along with measures to mitigate them. While these risks are continuously monitored and reduced through decentralization, governance, and technical safeguards, it is important to note that new or currently unknown risks may emerge over time as the protocol and its surrounding ecosystem continue to evolve. #### Slashing Risks Validators can potentially face staking penalties. In very extreme cases of slashing (i.e., validator behavior seen as malicious by the rest of the network), up to 100% of staked funds could be at risk, but such scenarios would necessitate severe client software bugs, malicious takeover, or a compromise of multiple large node operators, leading to correlated slashing penalties. To minimize this risk, the Lido Protocol maintains a diverse validator set, with hundreds of participating node operators. The protocol's protections include: - **Decentralization**: Each unique entity controls less than 1% of the Ethereum network's validators. - [**Diversified Node Operators and setups**](https://operatorportal.lido.fi/operator-statistics-and-metrics): Hundreds of independent operators spread across the world employ heterogeneous client and infrastructure setups to reduce systemic risks. - **Ad hoc slashing fund**: An ad hoc fund set aside by Lido DAO provides an additional safety net against severe slashing events. This fund, operated via a [vault contract](https://etherscan.io/address/0x8B3f33234ABD88493c0Cd28De33D583B70beDe35), holds around 6,600 stETH for potential coverage of severe losses. The use of the fund is subject to governance, requiring DAO discussions and approval before execution. --- #### Oracle Data Manipulation Risks The Lido Protocol relies on the [Oracle Committee](https://research.lido.fi/t/expansion-of-lidos-ethereum-oracle-set/2836?ref=blog.lido.fi) to report external data, including validator states and balances on the Consensus Layer. This data can affect the internal protocol rate of stETH to ETH through [rebasing](https://docs.lido.fi/contracts/lido?ref=blog.lido.fi#rebase). In a worst-case scenario, a compromise of the majority of the Oracle Committee (i.e., five or more of the 9 members) could report incorrect balances, which could lead to triggering of significant negative rebases. Users should bear in mind risks related to stETH rebasing when entering into complex DeFi positions, such as leveraged staking or borrowing uncorrelated tokens (such as stables) against stETH positions. **Mitigation Measures**: - The Oracle software is open-sourced, and all material changes are audited by professional third-party security auditors before being used on the Ethereum mainnet. - The Oracle Committee is made up of nine independent oracle operators. - **OracleReportSanityChecker**: An in-protocol safety net that verifies incoming reports against abnormal changes, requiring governance intervention if anomalies are detected. - **Trustless data availability**: Ongoing efforts to make Oracle-provided data verifiable on-chain using technologies like zero-knowledge proofs (ZK proofs). --- #### Governance Misalignment Governance of the protocol is determined by LDO holders, while stETH holders are the users who stake through it. This creates a potential conflict: governance decisions could benefit LDO holders at the expense of stakers—for example, by drastically increasing protocol fees or misusing staked ETH. **Mitigation Measures**: - **Two-phase voting:** Every on-chain voting has a special period called the ‘objection phase’. This phase is a 48-hour time lock. This is the first line of defense, designed to enable LDO holders to respond to potential issues. - **Dual Governance** empowers stETH and wstETH holders to safeguard their assets in the event of contentious or harmful governance decisions within the Lido protocol. If necessary, it enables holders to delay or block proposed changes until they have safely exited the protocol. For more details, check the [101 Explainer](https://blog.lido.fi/dual-governance-101-explainer/) --- #### Implementation Risks: Bugs, misconfigurations, and hidden vulnerabilities As with any software system, the protocol may be subject to hidden bugs, misconfigurations, and undiscovered vulnerabilities. **Mitigation Measures**: - **Rigorous development processes**: Adhering to strict development protocols for both on-chain and off-chain components. - **Specification drafting**: Creating detailed documentation before implementation. - **Design principles**: Emphasizing robust architecture and focusing on edge cases, and having emergency and failure modes covered at the spec level. - **Comprehensive testing**: Including unit tests, integration tests, and testing in diverse environments. - **External audits**: Engaging third-party security experts to review code. - **Fuzzing and formal verification**: Using advanced techniques to uncover vulnerabilities. - **Pre-deployment and acceptance testing**: Ensuring all contracts and off-chain software are initialized, functioning, and safeguarded as intended before going live. - **Bug Bounty Program:** Engaging experts to identify and report vulnerabilities through rewards. [Learn more.](https://immunefi.com/bug-bounty/lido/) --- #### Ethereum PoS Economy Risks The Lido protocol relies on the design and economic principles of Ethereum's Consensus Layer. While the protocol continually adapts to changes from network upgrades and hard forks, there is a tail risk that fundamental changes to the Consensus Layer's economic principles — or even network deprecation — could impact the Lido protocol. **Mitigation Measures**: - **Active participation**: Engaging in Ethereum network roadmap discussions. - **Community involvement**: Inviting the broader community to discuss potential impacts. - **Liquid staking advocacy**: Raising concerns and questions that may affect liquid staking protocols, leveraging Lido protocol's position as a significant actor within the Ethereum ecosystem. --- ### Token Price and Liquidity Risks Users face the risk that the price of stTokens (like stETH) on secondary markets (e.g. DEXs and CEXs) may be lower than their inherent value in ETH due to supply and demand market dynamics. Although the in-protocol withdrawal mechanism usually means that secondary market exchange rates converge towards the in-protocol ETH\:stETH rate over time, since withdrawals are not instant (owing to the validator exit and withdrawal mechanisms of Ethereum's PoS implementation), and the difference between primary and secondary market rates usually tends to balance out over time/tends to move toward alignment. **Mitigation Measures**: - **Transparency**: The Lido DAO is committed to communicating these risks openly. - **Risk management**: Ongoing efforts to minimize these risks through protocol improvements and community engagement. --- # Security Practices and Processes ### Best Practices for Technical Releases Over time, Contributors to the Lido protocol have developed best practices for delivering technical releases. Basically, it’s a structured process with checkpoints, timelines, and governance steps that gets you to releases. The checklist has seven stages from “we have an idea” to “on-chain vote is done, everything’s live, alerts are green”: 1. **Concept** — idea, feasibility, business landscape, initial forum post. 2. **Drafting & Review** — writing specs & LIP (Lido Improvement Proposal), design internal challenge. 3. **Implementation** — development, tests, devnets/testnets, deploy plan. 4. **Review** — audits, voting scripts, green lights from everyone. 5. **Deployment** — mainnet deployment, bots, alerts, off-chain infra. 6. **Voting** — DAO-wide vote with public materials. 7. **Take-off** — on-chain enactment, docs, supervision, Bug Bounty. Each stage has its own logic and key artifacts. It’s not a minimal process. It’s a complete map of all possible steps that ensures you do not miss anything. This process clarifies work, improves security, and speeds time to mainnet. It keeps teams aligned, makes handoffs explicit, and delivers the right governance artifacts at the right time, which raises stakeholder confidence and lets the DAO scale execution without losing quality. --- ### Audits The Lido protocol, from the very beginning, is built on trust in code, and that trust comes from careful and continuous verification. Every component of the Lido protocol has gone through multiple layers of independent review by leading blockchain security firms. Over the years, experts from Certora, MixBytes, Statemind, Ackee, OpenZeppelin Consensys Diligence, ChainSecurity, Oxorio, Hexens, and SigmaPrime have examined Lido protocol’s smart contracts, looking for ways to make them safer and more reliable. The results of these reviews are full audit reports and code-verification summaries, which are publicly available for anyone to explore [here](https://github.com/lidofinance/audits#lido-protocol-audits). To make the audit process more structured and consistent, the [Lido DAO formed the Audits Committee](https://research.lido.fi/t/lido-on-ethereum-form-audits-committee/3481) to coordinate all security reviews across the protocol, ensuring that every major code change receives proper review before deployment. The committee manages the schedule of audits, works with trusted security partners, and keeps a transparent record of all completed work. Its goal is not just to react to potential issues but to maintain a continuous cycle of prevention, verification, and improvement. Through this combination of external expertise and internal oversight, Lido DAO aims to uphold a high standard of security and transparency. The auditing process isn’t just a checkbox, but rather an ongoing practice that helps keep the protocol resilient, trustworthy, and open for public review. --- ### GRAPPA As the scope of the protocol expands and the number of ecosystem collaborations, network integrations, and application launches grows, the Lido DAO recognized the need for another approach to reviews for these purposes — to make the review process more responsive, scalable, and transparent. To meet that need, [the Audits Committee proposed the creation of The Guild for Review and Assessment of Protocols and Applications: GRAPPA](https://research.lido.fi/t/establishment-of-the-guild-for-review-and-assessment-of-protocols-and-applications-grappa/8997). GRAPPA is envisioned as an annually pledged role (contingent on proven success) assigned to a reputable third-party auditing provider with deep expertise in DeFi and smart contract auditing and familiarity with the Lido on Ethereum protocol. The role of GRAPPA includes manual security reviews of protocol-level changes, verification of deployments referred to as Lido Multichain, consultations on emerging features, and the publication of summary review reports for the community. The aim is to maintain high standards of security and deployment quality across its growing universe of activities, making it easier to scale confidently, launch faster, and keep the community informed. --- ### Bug Bounty As part of its ongoing commitment to security and community collaboration, the Lido DAO established [a bug bounty program](https://immunefi.com/bug-bounty/lido/information) — a standing invitation for the broader security community to help keep the protocol safe. The program is hosted on the [Immunefi platform](https://immunefi.com/bug-bounty/lido/information/?utm_source=chatgpt.com), one of the most trusted hubs for DeFi security research. Through this initiative, independent researchers are encouraged to identify and responsibly disclose vulnerabilities in the Lido protocol’s smart contracts and applications. Verified discoveries can earn rewards, with higher payouts reserved for issues of greater severity. The program’s scope covers a range of potential threats, including direct loss of user funds, denial-of-service risks, governance manipulation, and data exposure. To ensure ethical participation, all submissions must include a clear proof of concept, and testing must never disrupt production systems or fall outside the defined boundaries of responsible disclosure. Through this open invitation to white-hat researchers worldwide, Lido DAO embraces a proactive model: rather than waiting for threats to emerge, Lido DAO asks the community to help discover and fix them. The result is a broader network of oversight, stronger safeguards, and a more resilient protocol overall. --- ### Emergency Brakes & CircuitBreaker As [voted](https://dao.lido.fi/vote/202) by LDO token holders, protective mechanisms were implemented that allow certain parts of the protocol to be paused in emergency situations without requiring a full DAO-wide vote. [Emergency Brakes committees](https://docs.lido.fi/multisigs/emergency-brakes#12-emergency-brakes-ethereum) are granted permissions to temporarily pause specific protocol components such as [L2 bridges](https://lido.fi/lido-multichain) (disabling deposits and withdrawals for wstETH bridging to other networks), and [Easy Track](https://dao.lido.fi/easy-track) (preventing the creation and execution of motions). Resuming normal operations after pausing requires an on-chain DAO vote. The more universal [CircuitBreaker](https://docs.lido.fi/contracts/circuit-breaker) mechanism serves as an on-chain panic button to pause crucial contracts for a limited duration. Each pause is single-use: a contract paused through CircuitBreaker cannot be paused through it again, and after the pause period elapses the contract resumes itself without an explicit call. CircuitBreaker assigns pause permissions per contract, so different committees can guard different parts of the protocol. Pause authority is kept active through a periodic heartbeat that pauser committees renew on a regular interval. These pause mechanisms allow sufficient time to analyze the issue, prevent further impact, and coordinate secure recovery actions. --- ## Section: Run on Lido --- # stETH and wstETH The Lido protocol offers two tokenized forms of the same staked ETH: stETH and wstETH. Both tokens represent staked ETH and allow users to participate in the Ethereum ecosystem while earning staking rewards, but they behave differently and are suitable for different use cases. #### stETH The default token users receive when staking through the Lido protocol. The user's stETH balance updates daily to reflect earned rewards, so the amount of stETH held can potentially grow automatically over time. Users can use stETH within various applications, and its balance adjusts without any manual action on their part. Because stETH grows in quantity, it’s useful in applications that support rebasing tokens, where the balance can change automatically. However, some DeFi protocols don’t support this type of token behavior. - - - #### wstETH Wrapped stETH (wstETH) is a non-rebasing version of stETH. Unlike stETH, the balance of wstETH remains fixed; instead, the value per unit increases to reflect earned rewards. This wrapping process effectively locks the staking growth into the token’s price rather than its quantity, making wstETH ideal for protocols or scenarios where a constant token balance is required. wstETH is better suited for DeFi protocols that require fixed-balance tokens, for example, lending platforms, vaults, or smart contracts that don’t handle rebasing. - - - #### Converting between stETH and wstETH, and the key difference: **Key difference**: The main distinction between stETH and wstETH lies in how they handle rewards: * **stETH**: Balance increases as rewards accrue. * **wstETH**: The token's value per unit increases while the balance stays the same. Users can convert freely between stETH and wstETH using Lido UI or supported DeFi apps. Both tokens represent the same staking position, but they differ in how that position is tracked over time (balance vs. value). --- # Lido in DeFi One of the core benefits of liquid staking is the ability to use staked tokens while still earning staking rewards. Both **stETH** and **wstETH** are integrated into a wide range of DeFi protocols across Ethereum and supported chains. #### Possible DeFi use-cases: #### Lending and borrowing: ![Lending and borrowing:](https://lido.fi/static/from-cms/how-lido-works/lending_and_borrowing.png) One of the most common DeFi integrations for stETH and wstETH is lending and borrowing on platforms like Aave. In this use case, users can deposit their stETH or wstETH as collateral to borrow other tokens such as stablecoins or ETH. Alternatively, users can lend their tokens to earn third-party rewards on top of the staking rewards already accruing from the Lido protocol. --- #### Leveraged staking: ![Leveraged staking:](https://lido.fi/static/from-cms/how-lido-works/leveraged_staking.png) In leveraged staking, stETH is used as collateral to borrow ETH, which is then staked again, creating a loop that amplifies staking growth. While leveraged staking can enhance rewards, it also introduces increased liquidation risk due to price volatility or shifts in protocol parameters. --- #### Diversified rewards: stETH and wstETH ![Diversified rewards: stETH and wstETH](https://lido.fi/static/from-cms/how-lido-works/diversified_rewards.png) can also be used in structured DeFi products designed to optimize or maximize staking rewards. These products may include auto-compounding vaults, fixed yield, or variable yield instruments. These mechanisms are usually chosen by users seeking more control over the way their rewards are generated or distributed. --- #### Restaking: ![Restaking:](https://lido.fi/static/from-cms/how-lido-works/restaking.png) Through restaking protocols, users can commit their stETH/wstETH as collateral and receive LRTs (liquid restaking tokens) with third-party rewards, which may include protocol points, tokens, or additional rewards. --- #### Using stETH and wstETH in DeFi When interacting with DeFi platforms, it’s important to understand the difference between stETH and wstETH. **stETH** is a rebasing token - its balance increases daily to reflect staking rewards. However, not all DeFi protocols can support rebasing behavior. In such cases, **wstETH** is used instead. It wraps stETH into a non-rebasing format, keeping the token balance constant while the value increases over time. Many platforms support wstETH as the preferred format for integrations. Users can freely convert between the two formats using the Lido UI or directly through supported DeFi apps. Before using any specific DeFi product, it’s recommended to verify which token format is supported. For an up-to-date overview of supported integrations, token formats, and network availability, refer to the DeFi app itself or to the [Lido Ecosystem page.](https://lido.fi/lido-ecosystem) --- # Lido Institutional ![](https://lido.fi/static/from-cms/how-lido-works/institutional.png) For institutions seeking to participate in liquid staking, the Lido DAO offers a dedicated path: institutional staking via the stETH token. Rather than setting up and running validators in-house, an endeavor that demands significant capital, infrastructure, monitoring, and operations, institutions can delegate ETH to the Lido protocol, receive stETH, and retain full liquidity and on-chain transparency. In practical terms, this means organizations can integrate stETH into their existing custody, treasury, and trading workflows while staking rewards accumulate automatically on-chain. Institutions benefit from a diversified and professionally managed validator set, slack exposure to validator-slashing risks, and access to native integrations with trusted infrastructure providers such as Fireblocks, BitGo, and Copper, [and many more](https://blog.lido.fi/category/institutional/). Lido Institutional's staking pathway has been shaped with awareness of the specific requirements of larger organizations, including the need for compliance processes, custody management, and alignment with internal governance or risk controls. These features ensure that institutions can participate in network security and staking rewards while maintaining the procedural standards expected in their operations. In this way, Lido Institutional serves as a bridge between decentralized staking and traditional institutional practices, enabling participation in Ethereum’s consensus process while maintaining flexibility, transparency, and operational compatibility with enterprise infrastructure. [Learn more.](https://lido.fi/institutional) --- # Lido Multichain ![](https://lido.fi/static/from-cms/how-lido-works/multichain.png) Lido protocol's liquid staking tokens, **stETH** and **wstETH**, are primarily issued on the Ethereum network. However, for better adoption and utility, the Lido DAO supports bridging these tokens to various other blockchain networks. This multichain approach allows users to leverage stETH and wstETH across different ecosystems, benefiting from lower fees, faster transactions, and different DeFi opportunities. #### Supported Networks wstETH can be bridged to several Layer 2 (L2) and Layer 1 (L1) networks, including OP Mainnet, Base, Arbitrum, Linea, BNB Chain, and Unichain. For information about recent changes to the list of supported networks, see [Lido Multichain: Network Support Changes (June 2026)](https://blog.lido.fi/lido-multichain-update-june-2026/). Each network may have specific requirements and supported token formats. Details on which tokens are supported on which chain can be found [here.](https://lido.fi/lido-multichain) #### wstETH as token format for Lido Multichain wstETH is a non-rebasing wrapped version of stETH designed for broader compatibility across chains, bridges, and DeFi protocols. Its balance remains constant, while staking rewards are designed to be reflected in the token’s value over time. Due to this compatibility model, wstETH is generally the recommended token format for bridging and multichain DeFi integrations. --- #### Bridging considerations When bridging stETH or wstETH: - **Use recognized bridges**: Prefer native bridges provided by the destination network (e.g., Arbitrum's canonical bridge) for enhanced security and compatibility. - **Be aware of risks**: Bridging involves smart contracts and, in some cases, third-party validators. Understand the associated risks, including potential smart contract vulnerabilities and liquidity issues on the destination chain. - **Check liquidity**: Ensure that the destination network has sufficient liquidity for stETH or wstETH to facilitate smooth transactions and interactions. - **Verify Token Contracts**: Always confirm that you're interacting with the correct token contracts on the destination network to avoid scams or unsupported tokens. For a comprehensive overview of bridging risks and best practices, please follow [the Bridging stETH/wstETH: A Guide To Risks & Best Practices.](https://help.lido.fi/en/articles/11481402-bridging-steth-wsteth-a-guide-to-risks-best-practices) --- #### Using stETH and wstETH on Other Networks Once bridged, stETH and wstETH can be utilized in various DeFi protocols on the destination networks. This includes lending platforms, liquidity pools, and more reward opportunities. The availability of these services varies by network, so it's essential to research and understand the DeFi opportunities of the specific chain you're engaging with. For more information on DeFi integrations and opportunities, visit the [Lido Multichain page.](https://lido.fi/lido-multichain)