Lido DAO contributors opened an emergency on-chain vote on May 11, 2025, to replace a compromised oracle address operated by Chorus One. The proposal targeted the address across three HashConsensus contracts used by Lido’s Accounting Oracle, Validators Exit Bus Oracle and Community Staking Module Fee Oracle.

The action mattered because those oracle processes help translate Ethereum consensus- and execution-layer data into protocol decisions. Yet the evidence available on May 11, 2025, did not show a protocol-wide takeover. Lido’s contemporaneous incident notice said its reporting system required agreement from five of nine oracle members, leaving one compromised signer below quorum. The notice said stakers were unaffected and the protocol remained operational; those were contemporaneous findings, not a completed forensic conclusion.

What the chain and incident record showed

Etherscan records a successful transfer of 1.463679274854623774 ETH from the affected address at 02:37:23 UTC on May 10, 2025. The Lido forum notice said that transfer drained the address and that a low-balance alert prompted a contributor to investigate. The signing key had been created in 2021 and remained in use in 2025.

The root cause was unresolved on May 11, 2025. Chorus One said an old hot-wallet private-key leak appeared more likely than an active infrastructure breach, while explicitly keeping its investigation open. Lido contributors said the other eight oracle members and the oracle software had been checked without signs of compromise. Chorus One also said it was preparing a new, dedicated machine for the replacement oracle key.

That distinction limited what could responsibly be claimed. The chain record verifies the ETH movement; it does not by itself establish how the key was exposed, who controlled the recipient or whether the transfer was automated. A contemporaneous report by The Block described the movement as a drain, but the event-day primary record stopped short of naming an attacker or a definitive intrusion path.

A separate reporting delay

Lido’s May 11, 2025, notice also documented delayed oracle reports on May 10, 2025, but said those delays were unrelated to the compromised Chorus One key. The Accounting Oracle report arrived at 14:06 UTC, approximately one hour late, and the Validators Exit Bus Oracle report arrived at 14:40 UTC, approximately two hours late.

According to the same notice, four other oracle operators had encountered node issues; two were linked to what contributors described as a minor Prysm bug following Ethereum’s Pectra upgrade. Operations resumed. The overlap in timing made the episode look broader than the evidence supported, but the primary account treated the key compromise and quorum delay as separate incidents.

Governance became the containment mechanism

The proposed rotation replaced 0x140Bd8FbDc884f48dA7cb1c09bE8A2fAdfea776E with 0x285f8537e1dAeEdaf617e96C742F2Cf36d63CcfB in each of the three affected HashConsensus contracts. The forum specified a 72-hour main voting phase followed by a 48-hour objection phase.

As of May 11, 2025, the verified development was the launch of Vote #186, not its approval. That distinction is central: tokenholder governance was being used to revoke a compromised operational credential while the remaining oracle quorum preserved continuity. The incident tested whether Lido’s distributed oracle design and governance process could contain a single-key failure without converting it into an invalid protocol report.

Later context

A May 16, 2025, update to the same governance record said Vote #186 reached quorum and was enacted, completing the address rotation. That outcome was not known when the emergency vote opened on May 11, 2025, and does not change the event-day uncertainty over the original key’s exposure.

Primary sourceLido Governance — Emergency rotation of compromised Chorus One oracle

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.