defirisk.co
rubric v1.7.0

Audit scope mismatch

Lido's assessment for RD-F-001 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Core V2 contracts covered by audit commits (e57517730c / 2bce10d4f0). V3 stVaults deployed Jan-Mar 2026 with Certora FV dated 2026-01-10 and Consensys Diligence fix-review at commit 88ce9647. Diligence noted 'new vulnerabilities still being identified at end of audit' and recommended delayed production deployment. Broad but temporally compressed audit coverage on V3 surface.

Sources #

  • URL
    SyagEmMwohttps://hackmd.io/@lido/SyagEmMworetrieved 2026-04-28
  • URL
    SecurityReportshttps://github.com/Certora/SecurityReportsretrieved 2026-04-28
  • URL
    retrieved 2026-04-28
  • URL
    lido-stvaults-mainnethttps://www.theblock.co/post/387769/lido-stvaults-mainnetretrieved 2026-04-28

Methodology #

Check whether the commit SHA cited in the audit report matches the bytecode deployed at the production proxy/implementation address.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol lido factor RD-F-001 score yellow collected_at 2026-04-28 13:58:42