Quantum Audit Logo

Is Liquid staked Ether 2.0 Safe?

On-chain security analysis — is it a scam or legit?

Is this your token? Publish your own audit on this page →

Liquid staked Ether 2.0 STETH
0xae7a…fe84
Ethereum
Not verifiedThis record has not gone through deep verification and is not being monitored. The score is a dated snapshot — the token’s risk can change at any time.Own this token? Put it under verification →
Last checked today 1 audit on record
How is this score calculated? → Medium Risk
Executive SummaryAI Copilot

The Lido contract, an ERC-20 token implementation, manages staked ETH and associated operations. It features extensive access control and upgradeability. The audit identified two high-severity issues related to privileged balance manipulation and a technical inconsistency with `msg.value` handling in an internal function. These findings highlight the significant power held by privileged roles within the protocol.

1 High5 Informational
Volume 24h
$26.45M
Liquidity
$104.07M
Price
$2686.0035
Token Age
5y
Top 10 Holders
62.9%

Security Findings

High

Internal Function Handling Ether Is Not Explicitly Marked Payable

CD-01The internal `_submit` function, which is responsible for processing incoming Ether (msg.value) when users stake, is not explicitly marked as `payable`. While its external callers (`submit` and the `fallback` function) are `payable`, this inconsistency in the internal function's declaration could lead to unexpected reverts if `_submit` were ever called directly or indirectly from a non-payable context while attempting to handle Ether.
IssueThe internal `_submit` function, which is responsible for processing incoming Ether (msg.value) when users stake, is not explicitly marked as `payable`. While its external callers (`submit` and the `fallback` function) are `payable`, this inconsistency in the internal function's declaration could lead to unexpected reverts if `_submit` were ever called directly or indirectly from a non-payable context while attempting to handle Ether.
FixWhile the current external callers are `payable`, it is a best practice for internal functions that are intended to receive and process Ether to be explicitly marked `payable`. This ensures clarity and prevents potential issues if the call path changes in future upgrades. Token holders should ensure that the protocol's technical team reviews and addresses this declaration for robustness.
StatusUnresolved
Info

Privileged Address Can Directly Change Token Holders' Balances

CP-02The contract allows certain privileged addresses to directly modify the token balances (shares) of any user. Functions like `transferShares`, `transferSharesFrom`, `submit`, `mintShares`, and `mintExternalShares` can be called by these privileged roles to move, create, or burn tokens from any account, including those of other token holders. This means a compromised or malicious privileged address could potentially take tokens from users or inflate the supply.
IssueThe contract allows certain privileged addresses to directly modify the token balances (shares) of any user. Functions like `transferShares`, `transferSharesFrom`, `submit`, `mintShares`, and `mintExternalShares` can be called by these privileged roles to move, create, or burn tokens from any account, including those of other token holders. This means a compromised or malicious privileged address could potentially take tokens from users or inflate the supply.
FixToken holders should be aware that the administrators of the Lido contract possess significant control over token balances. It is critical that the keys controlling these privileged addresses are secured with the highest possible standards, such as multi-signature wallets, and that all actions are transparently governed.
StatusUnresolved
Info

Who holds the supply

QA-HOLDERSThe ten largest holders own 62.9% of supply. What remains: 5.5% in wallets, 57.4% in other contracts. 628,147 holders in total. For a verified reference asset the largest holders are custodians, exchanges and bridges; concentration is reported, not scored.
IssueThe ten largest holders own 62.9% of supply. What remains: 5.5% in wallets, 57.4% in other contracts. 628,147 holders in total. For a verified reference asset the largest holders are custodians, exchanges and bridges; concentration is reported, not scored.
FixWatch the largest wallets that are not exchanges, pools or locks — those are the ones that can move the price.
StatusAcknowledged
Info

Identity verified by independent sources

QA-IDENTITYListed on CoinGecko as Lido Staked Ether (STETH), market cap $26.4B. 628,147 holders. Verified by: CoinGecko.
IssueListed on CoinGecko as Lido Staked Ether (STETH), market cap $26.4B. 628,147 holders. Verified by: CoinGecko.
FixMatch the contract address against the project's official channels before trading.
StatusAcknowledged
Info

The market for this token

QA-MARKETLiquidity $150.1M (DexScreener, all pools). 24h trading volume $49.2M (CoinGecko, all markets, daily snapshot). 24h trading volume $42.5M (DexScreener, all pools).
IssueLiquidity $150.1M (DexScreener, all pools). 24h trading volume $49.2M (CoinGecko, all markets, daily snapshot). 24h trading volume $42.5M (DexScreener, all pools).
FixSize any position to the liquidity and daily volume shown — they set how much you can sell and at what price.
StatusAcknowledged
Info

Asset class: Liquid staking token

QA-PROFILEA receipt for staked native tokens that keeps earning staking rewards. Its value depends on the staking protocol and its validators. Scored as an established reference asset: its identity is verified, so the issuer's or protocol's controls (listed as findings) are real and are priced once as counterparty risk, and LP locks and holder concentration are not scored — its pools belong to market makers and its largest holders are exchanges, bridges and custody. Basis: CoinGecko category: Liquid Staking Tokens. Tokenomics — Supply: fixed — the contract has no mint function. Control: an owner that could not be resolved. Code: upgradeable proxy. Fees: no buy or sell tax. Market: $150.1M of DEX liquidity across 11 pools. Launch: 2112 days of market history.
IssueA receipt for staked native tokens that keeps earning staking rewards. Its value depends on the staking protocol and its validators. Scored as an established reference asset: its identity is verified, so the issuer's or protocol's controls (listed as findings) are real and are priced once as counterparty risk, and LP locks and holder concentration are not scored — its pools belong to market makers and its largest holders are exchanges, bridges and custody. Basis: CoinGecko category: Liquid Staking Tokens. Tokenomics — Supply: fixed — the contract has no mint function. Control: an owner that could not be resolved. Code: upgradeable proxy. Fees: no buy or sell tax. Market: $150.1M of DEX liquidity across 11 pools. Launch: 2112 days of market history.
FixCheck the staking protocol's validator set, withdrawal queue and governance.
StatusAcknowledged

Category Ratings

TechnicalLow8/10

The Lido contract is an ERC-20 token with rebasing shares, inheriting from `ReentrancyGuard` for security. It includes numerous privileged functions controlled by specific roles, enabling administrative actions like pausing staking, setting limits, and managing rewards. A significant technical risk is the ability of privileged roles to directly manipulate user balances via functions like `transferShares` and `mintShares`. Additionally, the internal `_submit` function, which handles `msg.value`, is identified as non-payable, which could lead to unexpected reverts if not handled carefully by its callers (7.1 Architecture, 7.2 Code Security, 7.3 Access Control).

GovernanceLow8/10

The contract implements a robust access control system using AragonApp's ACL, assigning specific roles for critical operations. This centralized control allows for comprehensive management of staking parameters, reward distribution, and emergency actions like pausing the contract. However, the extensive power granted to these privileged roles, such as the ability to directly alter user shares through `mintShares` or `transferShares`, introduces a high governance risk. Misuse or compromise of these roles could lead to significant economic impact on token holders (7.4 Economic, 7.5 Governance).

UpgradesMedium5/10

The Lido contract is deployed as an upgradeable proxy using a custom Etherscan-detected pattern. This design allows for future modifications and enhancements to the contract logic without requiring a new deployment, providing flexibility for protocol evolution. However, the upgrade mechanism itself introduces a governance risk, as the ability to upgrade the contract is controlled by privileged roles, meaning a compromised or malicious upgrade could introduce new vulnerabilities or alter contract behavior unexpectedly (7.7 Upgrades).

Security Checklist

Contract VerifiedPass
Ownership Renounced?
No Mint FunctionPass
Liquidity LockedFail
Not a ProxyFail
HoneypotNoneBuy Tax0.0%Sell Tax0.0%

Proxy Upgrade Controls

Proxy TypeEtherscan Detected Custom
ImplementationVerified source
Upgrades (30d)0 · stable

Holder Composition

5.5% in wallets57.4% in contracts
Effective Concentration28.5%

Share held by contracts — treasury, vesting, bridge or staking — is discounted against share held by wallets when the score is computed: a contract cannot decide to sell the way an anonymous holder can, though it can still be drained or voted to sell. Effective concentration is the figure the risk score is actually calculated from.

Liquidity Depth

Show 4 more pairsShow less

One more pair holds $6 and is not listed.

The risk score reads depth across every pair. The volume figure and the volume-to-liquidity ratio elsewhere on this page describe only the pair this audit analysed, so the two are not directly comparable.

LP Distribution

Top-1 Unlocked Holder98.5%
Top-3 Unlocked99.5%

Key Addresses

Deployer
0xb8ff…88dc
Unlocked LP Held By
0x3175…bde90xd48b…9dea0x91c2…ce580x456b…307b0x462a…38780x6fc7…16190x720f…52910x771b…961f0xcb82…e0340x180a…4639

No privileged address appears among these holders: the unlocked liquidity sits with independent providers, not with the deployer.

What Raised This Score

  • Issuer controls retained (upgrade, seize balances) — counterparty risk on a known issuer, not a rug vector
  • Code: Internal Function Handling Ether Is Not Explicitly Marked Payable (High, static analysis)

Each factor is an on-chain fact recorded at the time of this analysis. The score is computed from them by a deterministic function, so the same contract returns the same score for anyone who runs the audit. How scores are computed

Related Audits

Octra (OCT)Medium RiskProgrammable (V4)Medium RiskZigCoin (ZIG)Medium RiskChainlink (LINK)Medium RiskKiteMedium RiskRaveDAO (RAVE)Medium Risk

Would You Like a More Detailed Audit of Liquid staked Ether 2.0?

Our AI-powered scanner gives you a deeper, real-time smart contract analysis — free, with every scoring factor shown.

Get Detailed Audit