Wrapped stETH (wstETH) is a token that represents a non-rebasing, ERC-20 format of stETH. It is designed to facilitate integration with DeFi protocols that don't support rebasing tokens—tokens whose supply automatically adjusts with each staking reward revaluation. wstETH allows holders to engage with various decentralized finance (DeFi) activities, maintaining a stable balance while reflecting the value gained through staked ETH rewards over time.
When you wrap stETH into wstETH, the stETH is locked in a smart contract, and in exchange, wstETH is minted. This provides compatibility with blockchain networks that require a stable token balance, such as when moving across different ecosystems like Ethereum's Layer 2 solutions. Staking rewards accumulate through an increase in the exchange rate between wstETH and stETH, rather than through increasing balances. This setup makes it easy for users to transfer and utilize their token in DeFi protocols while capturing staking rewards effectively.
Wrapped stETH (wstETH) emerged as a rebase-free, ERC-20 compatible token on Ethereum, designed to simplify participation in the DeFi ecosystem by providing a stable means of interacting with staked Ether (stETH). Although specific founding details for wstETH are less documented, it functions as an integral component of Lido Finance, a popular platform initiated to enhance staking on Ethereum. The project's overarching aim is to provide liquidity while allowing users to earn staking rewards. The documentation outlines the core functionality without highlighting individual founders. Instead, it emphasizes its role within DeFi and integration capabilities across various platforms.
The Wrapped stETH project does not offer native staking capabilities on its own. Instead, Wrapped stETH (wstETH) is primarily a non-rebasing, ERC-20 compatible version of stETH used to facilitate integration within DeFi protocols.
Thus, you cannot natively stake any tokens in the Wrapped stETH project itself.
There have been no significant hacks, exploits, or outages reported for Wrapped stETH itself. However, there have been several incidents involving stETH that might be relevant to your inquiry:
Idols NFT Protocol Exploit (January 2025): The Idols NFT protocol was exploited due to a vulnerability, resulting in the loss of 97 stETH (approximately $324,000). This was due to manipulation of the protocol's functions but did not directly involve Wrapped stETH.
Bybit Exchange Hack (February 2025): A significant security breach at Bybit exchange resulted in the theft of over $1.4 billion in liquid-staked Ether, including stETH. This was not a direct exploit of Wrapped stETH, but rather an attack on the exchange holding stETH.
f(x) Protocol Vulnerability (January 2025): A flaw in the accounting of LSD (wrapped stETH) versus its underlying stETH allowed attackers to drain some wstETH from the f(x) Protocol. This led to minor losses, but the protocol covered the damages.
These incidents highlight vulnerabilities in peripheral systems and the significant financial stakes involved, but Wrapped stETH's native protocol or network hasn't directly suffered from hacks or exploits.
Wrapped stETH (wstETH) is secured through several key measures and consideration of potential vulnerabilities:
Contract Standards and Upgradability: wstETH is implemented as an ERC-20, facilitating compatibility across DeFi platforms. The smart contract is upgradeable via the Lido DAO, allowing for correction of potential issues with community governance approval source.
Non-rebasing Design: Unlike stETH, which rebases, wstETH doesn't automatically adjust balances daily. This design simplifies its integration into protocols that may not support rebasing, like bridges to L2s or other chains source.
ERC20BridgedPermit: Unique to wstETH when deployed on platforms like Optimism, this includes new permit signature standards (ERC-2612 and ERC-1271), which enhances security by providing seamless wrap/unwrap functionalities source.
Custody Solutions: Institutional-grade custody solutions for wstETH have been integrated, offering secure storage and compliance solutions for large holders. This institutional involvement is crucial for ensuring asset safety source.
Smart Contract Risks: Any smart contract, including those used by wstETH, may face potential risks such as bugs that could be exploited. These need ongoing audits, although recent checks haven't identified major vulnerabilities specific to wstETH.
Operational Challenges: The reliance on multi-sig contracts and the need for DAO intervention for upgrades can potentially delay responses to urgent security threats if not carefully managed.
DeFi Integration Risks: As wstETH interacts extensively across various DeFi platforms, risks associated with those platforms can indirectly affect it, requiring careful monitoring of security developments in those integrations.
Overall, while wstETH implements robust security measures, its unique rebase-free design for DeFi compatibility demands continuous diligence in audits and updates to mitigate emergent threats.
Here are the recent audits for the Wrapped stETH project, listed in chronological order from the most recent:
These audits cover various aspects of the Wrapped stETH and its integration across different platforms, focusing on security and vulnerabilities.