Security Review Flags Governance Vulnerabilities in ether.fi Stake Protocol
A security audit of ether.fi Stake, a liquid staking protocol with approximately $4.53 billion in total value locked, identified seven governance-related vulnerabilities as of September 11, 2026. The most critical findings include highly concentrated voting power, where just 12% of token holders control over half of all voting weight, and a ProxyAdmin multi-sig setup that includes a single externally-owned address with no time delay, potentially enabling unauthorized contract upgrades. Reviewers also flagged a 24-hour timelock on critical actions as insufficient compared to the industry-recommended minimum of 72 hours, leaving the protocol exposed to flash-loan front-running. Additional risks include a replaceable bridge relayer contract that could be exploited to mint tokens and drain liquidity, and a lack of any emergency pause mechanism for governance. The protocol received an overall risk score of 7 out of 10, indicating functional but materially flawed governance design.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in