defirisk.co
rubric v1.7.0

ERC-4626 virtual-share offset (OZ ≥4.9)

Lido's assessment for RD-F-074 — scored not_applicable on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

N/A — stETH is not an ERC-4626 vault. wstETH is a non-upgradeable wrapper. Share accounting is oracle-anchored to Beacon Chain state, not susceptible to ERC-4626 virtual-share inflation attack. OZ v3.4.0 used (predates ERC-4626 standard introduction in OZ 4.x).

Sources #

Methodology #

Determine whether ERC-4626 vaults use OpenZeppelin ≥4.9 virtual-share offset pattern to prevent first-depositor share-inflation.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol lido factor RD-F-074 score not_applicable collected_at 2026-04-28 13:58:42