Incidents and Security Advisories
A historical record of vulnerabilities, smart contract bugs, operational outages, slashing events, and the recovery actions taken by the protocol and community. Risk teams, node operators, and integrators use this group to assess the protocol's security track record and understand failure modes.
Minipool Exploit and Vulnerability History
Chronological record of smart contract bugs and economic exploits targeting Rocket Pool's minipool architecture, including deposit front-running, finalization logic errors, and reward distribution manipulation. Covers root cause, affected funds, and the upgrade path that resolved each incident. Essential for auditors, integrators, and risk teams evaluating minipool security.
rETH Economic and Oracle Manipulation Incidents
Documents incidents where the rETH/ETH exchange rate was manipulated or at risk, including oracle failures, bonding curve exploits, and de-pegging events triggered by market volatility or MEV. Critical for DeFi protocols, exchanges, and custodians assessing rETH as collateral or a reserve asset.
Node Operator Slashing and Mass Penalty Events
Historical analysis of significant slashing or mass penalty (leaking) events affecting Rocket Pool validators. Covers correlated failures such as client bugs and cloud outages, the root cause, financial impact on operators and the protocol, and recovery steps. Node operators and infrastructure teams use this to model tail-risk scenarios.
Smartnode Client Vulnerability Advisories
Security advisory log for the Smartnode software stack, tracking critical bugs that could lead to validator downtime, key exposure, incorrect attestations, or MEV misconfiguration. Includes severity ratings and mandatory upgrade deadlines. Node operators and infrastructure teams depend on this for operational security.
Governance Attack and Treasury Risk Incidents
Records of attempted or successful governance attacks on the Protocol DAO, including flash-loan voting exploits, malicious RPIPs, and treasury mismanagement events. Analyzes the attack vector, protocol defense mechanisms, and outcome. Governance participants and risk teams use this to assess pDAO security.
Smoothing Pool Operational Failures
Documents incidents where the Smoothing Pool failed to distribute rewards correctly, experienced a trust or accounting error, or was exploited by operators gaming the system. Critical for node operators evaluating the risk/reward of joining the pool and for integrators modeling reward expectations.
RPL Token Economic Exploits
Focuses on incidents involving the RPL token's staking, claiming, or slashing mechanics, such as inflationary bugs, staking contract exploits, or manipulation of the RPL/ETH ratio used for node operator bonding requirements. Integrators and risk teams use this to assess RPL token security.
Deposit Pool DoS and Griefing Attacks
Record of denial-of-service or griefing attacks on the deposit pool, such as front-running minipool creation with dust deposits or exploiting gas limits to prevent rETH minting. Analyzes the impact on protocol liveness and user experience. Integrators and node operators use this to understand liveness risks.
Third-Party Integration Security Incidents
Tracks security breaches at major third-party services integrated with Rocket Pool, such as MEV relays, staking-as-a-service providers, or DEXs hosting rETH liquidity, and analyzes the cascading impact on the Rocket Pool ecosystem. Integrators and risk teams use this to map dependency risks.
Cross-Contract Reentrancy and Composability Attacks
Deep dive into incidents where the complex interaction between Rocket Pool's contracts (minipool, network prices, RPL staking) was exploited through reentrancy or composability flaws, detailing the specific call path and the fix. Auditors and protocol developers use this to understand systemic risk patterns.
Withdrawal Credential and Key Management Incidents
Documents security advisories and user-impacting incidents related to the management of validator withdrawal credentials, including the transition from 0x00 to 0x01 types, bugs in setting the ETH withdrawal address, and key recovery procedures. Node operators and wallet integrators use this for operational security.
MEV Theft and Relay Censorship Incidents
Record of incidents where Rocket Pool node operators were victims of MEV theft by malicious relays or block builders, or where transactions were censored. Analyzes the protocol's built-in safeguards like the smoothing pool's role and minipool penalty mechanisms. Node operators use this to configure MEV relay selection.
Network-Level Congestion and Gas Spike Impacts
Post-mortems of Ethereum network congestion events that uniquely impacted Rocket Pool operations, such as mass liquidations of undercollateralized nodes due to high gas fees preventing RPL top-ups, or failed oracle updates causing price staleness. Node operators and risk teams use this for contingency planning.
pDAO Voting Manipulation and Sybil Incidents
Analyzes security incidents related to the Protocol DAO's voting process, including Sybil attacks on snapshot votes, vote-buying schemes, or technical bugs in the on-chain voting contracts that could have altered governance outcomes. Governance participants and security auditors use this to assess voting integrity.
Emergency Shutdown and Pause Event History
Log of all instances where the protocol's emergency pause functionality was activated, detailing the triggering incident, the scope of the pause, and the unpausing process. Integrators, node operators, and risk teams use this to understand the protocol's crisis response capabilities and trust assumptions.