manifoldfinance / defi-threat

a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations on decentralized finance
Mozilla Public License 2.0
485 stars 53 forks source link

Withdrawal credentials protection #20

Open sambacha opened 1 year ago

sambacha commented 1 year ago

Withdrawal credentials protection

A known security vulnerability for delegated staking applications is the possibility of users front-running the initial deposit and registering their own withdrawal credentials

see https://research.lido.fi/t/mitigations-for-deposit-front-running-vulnerability/1239