Skip to main content

Risk disclosures

ETH bridged to Linea using the native bridge may be staked on Ethereum Mainnet as part of Linea’s Yield Boost system. Staking allows bridged ETH to earn rewards that are redistributed to certain Linea users. This design improves capital efficiency compared with locking unstaked ETH in the bridge, and it introduces additional risks.

This page outlines key risks, potential impact, and mitigations. Read it alongside Linea’s general risk disclosures before using the Linea bridge. For how withdrawals and reserves work, see the Yield Boost overview and Architecture.

Risk of ETH being slashed while staked

ETH staked on Ethereum Mainnet can be forfeited to the protocol (“slashed”) if a validator behaves incorrectly, such as making conflicting attestations or block proposals. If one or more validators used by Yield Boost are slashed, a portion of the ETH backing the system could be lost. In extreme scenarios (for example correlated validator failures from a widespread software bug), larger losses across multiple validators could occur.

Slashing is rare historically, and slashed amounts are typically small relative to stake and often offset by staking rewards. Larger losses remain possible under extreme network-wide conditions. If slashing occurs, a portion of users’ ETH may be lost, and affected validators must exit staking, which can reduce future Yield Boost rewards. Mitigations include operator selection criteria and retaining a portion of infrastructure fees for a period as an insurance buffer that may be used to compensate slashing losses.

Delays when withdrawing ETH from Linea

ETH that is actively staked is not immediately withdrawable. The LineaRollup holds a liquidity buffer of unstaked ETH for normal withdrawals. Under high withdrawal demand or congestion in Ethereum’s validator exit queue, that buffer can be exhausted. Withdrawals may then be delayed until staked ETH becomes available again.

This scenario is a delay risk (withdrawal liveness), not an automatic loss of principal. Users may be temporarily unable to withdraw ETH on their preferred schedule. Mitigations include maintaining a configured minimum reserve, monitoring and proactive unstaking by the automation service, permissionless deficit-gated unstake and replenish calls, and last-resort withdrawal as stETH (which can then be swapped for ETH on Ethereum mainnet). The permissionless validator unstake path is also subject to Ethereum's withdrawal queue. When the queue is large, unstaking remains available but will take longer to complete. Timing is not guaranteed. See Architecture: permissionless flows and Architecture: LST withdrawal.

Withdrawal disruption due to Lido oracle failures

Yield Boost relies on Lido v3. Lido requires a fresh accounting report from its oracle committee at least every 48 hours. If that report is not produced, critical operations (including withdrawals and LST minting) may be temporarily halted. Causes can include technical issues, coordination problems, or other disruptions affecting the oracle committee.

Extended oracle disruption can leave users temporarily unable to withdraw. In an extreme case where reporting permanently ceases and no governance remedy is implemented, access to assets could be blocked for an indefinite period.

Risk of Lido protocol governance or contract failure

Lido is an external protocol governed by LDO token holders. Governance decisions or smart contract upgrades (well-intentioned or malicious) could negatively affect Yield Boost users. In the worst case, a harmful upgrade could put funds at risk.

If safeguards fail and a malicious or catastrophic upgrade lands, funds backing Yield Boost could be permanently lost, and Linea would not be able to reverse or reimburse those losses. As a safeguard, Linea’s Security Council can permanently lock the StakingVault contract in its current state, opting out of any future Lido upgrades. This process is called ossification.

Smart contract exploits or hacks

Yield Boost uses smart contracts on Ethereum Mainnet and Linea, plus supporting infrastructure for staking, liquidity management, and reward distribution. Those contracts may contain undiscovered vulnerabilities. A bug, design flaw, or exploit in a Yield Boost-related contract or an external dependency (including Lido staking, vault, or bridging components) could lead to theft, loss, or irreversible locking of some or all ETH backing Yield Boost.

Audits and reviews reduce risk but do not eliminate it. Losses from a successful exploit can be permanent, and Linea may not be able to recover or reimburse affected funds. Mitigations include security reviews and audits, restricting or rate-limiting critical operations where possible, and incident response and monitoring.

Technical implementation limitations

Ethereum smart contracts cannot directly observe live validator staking state. Yield Boost relies on protocol-specific accounting, oracle reports, reserve checks, and automation-assisted flows.

Some implementation patterns are intentional consequences of the system design and external staking integrations. When assessing potential security issues, researchers should consider the full protocol design, the canonical technical specification, audit reports, and system-level invariants, rather than evaluating individual contracts in isolation.

Neither Consensys nor Linea take possession, custody, or control of any digital asset on Linea or bridged to Linea unless expressly stated in a written contract signed by the respective party. No one can execute a transaction on your behalf, and Linea cannot reverse a transaction that has been finalized onchain. Consider these risks carefully before participating.

See also

Was this page helpful?