Lido's Staking Router v3 Upgrade Hit By Accounting Bug
Lido's Staking Router v3 (SRv3) upgrade was rolled out in July, but it wasn't without its issues. A post-mortem report revealed that a bug occurred due to an oversight in the AccountingOracle during the transition from Lido's legacy accounting methodology to the new balance-based system introduced by SRv3.
The glitch omitted a single 32 ETH validator deposit and briefly skewed the daily stETH rebase to an incorrect 2.04% APR figure, but fortunately, no user funds were lost.
The root cause of the issue was identified as an operational edge case specific to the migration period, not a systemic flaw in the SRv3 architecture itself.
The SRv3 upgrade is one of the most consequential infrastructure changes Lido has shipped, with three audit firms signing off on the code prior to deployment. However, the bug that surfaced underscores the reality that audits can only catch code-level vulnerabilities and not operational edge cases during live migrations.