CCT - Crypto Currency Tracker logo CCT - Crypto Currency Tracker logo
Cryptopolitan 2026-03-03 20:20:57

Lido Finance pauses new deposits to its ZKsync wstETH bridge after identifying a potential smart contract weakness

Ethereum liquid staking protocol Lido Financ e in formed its users of a potential security weakness in its ZKsync wstETH bridge endpoint contract, adding that it has suspended new deposits till the issue is resolved. The disclosure, published on X by Lido Finance, stated, “As of yet, there is no indication that the weakness was exploited, and wstETH holders on ZKsync are not affected. No other bridges are affected. ” Withdrawals from ZKsync and token transfers were described as unaffected. Nevertheless, the platform moved swiftly, pausing new bridge deposits out of what it described as “an abundance of caution.” What exactly is the vulnerability and who is affected? Lido has not publicly shared the technical nature of the flaw, referring only to a “potential weakness” reported in the ZKsync wstETH bridge endpoint contract, the smart contract layer that facilitates the movement of wrapped staked ETH between the Ethereum mainnet and the ZKsync Layer 2 network. Lido integrated ZKsync as its fifth Layer 2 deployment, developed in collaboration with Matter Labs and the txSync team to build canonical wstETH bridging smart contracts. The ZKsync bridge went live on 3 January 2024, following a Lido DAO governance vote the previous month. Lido has an emergency multisig mechanism that enables it to disable deposits and withdrawals on the ZKsync side when necessary, and that lever appears to have been pulled in this instance. Why can a fix not be deployed without governance vote? Lido wrote, “A fix has been prepared and will be audited and deployed via the next scheduled on-chain Lido governance omnibus vote (late March / early April), after which deposits will resume.” The reliance on a governance vote to deploy the fix reflects both the decentralized structure of Lido’s operations and the procedural safeguards built into its upgrade process. Yet for users and investors, it also means the timeline is subject to the mechanics of on-chain coordination, a reality that has historically introduced delays in decentralized finance protocols. Lido said updates would follow and that deposits would resume once the fix was live. The announcement has not helped the fortunes of the respective tokens, with markets unnerved by the prospect of a fix that will not arrive until at least late March and possibly early April. Lido’s native governance token, LDO, has fallen by more than 3.5% over the past 24 hours to trade at $0.3057. ZK, the native token of ZKsync’s parent network, has also dropped more than 3.1% to $0.01863 over the same period. However, both tokens were already on a decline before Lido’s announcement. The protocol controls roughly one-third of all staked ether on the Ethereum network, making it the single largest staking operator by a substantial margin. Any security incident, or even the perception of one, carries systemic implications that extend well beyond the specific ZKsync integration. For now, existing wstETH holders on ZKsync can take some comfort from Lido’s assurances while withdrawals remain fully operational. Cryptopolitan reported earlier today that another project, Neutron, a BTCFi project that offers Bitcoin holders yields on their staked tokens, also paused certain services until at least March 9 after a security update where it said” a whitehat flagged a vulnerability” in its code. If you're reading this, you’re already ahead. Stay there with our newsletter .

면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.