StakeHound / Fireblocks Hack
What happened
StakeHound, an ETH 2.0 staking service that issued a liquid stETH token, lost access to 38,178 staked ETH (roughly $72M-$75M at June 2021 prices) after two of the four key shares controlling the deposits' withdrawal key were lost. StakeHound says its custody provider Fireblocks told it of the loss on May 2, 2021, and it disclosed the incident and sued Fireblocks in Tel Aviv on June 22, 2021. No attacker was involved: the ETH was not stolen, it became unrecoverable.
Fireblocks denied responsibility, saying it never had custody of the keys, the shares were handled in a one-off research arrangement outside its platform, and StakeHound had ignored advice to keep a third-party backup. StakeHound upgraded the stETH contract to stop the token from entering liquidity pools.
How it happened
- The withdrawal key for StakeHound's ETH 2.0 deposits was split into BLS key shares under a 3-of-4 threshold, with two shares held via Fireblocks.
- According to StakeHound, Fireblocks generated its two shares outside a production environment and left the private keys needed to decrypt those shares out of the backup sent to Coincover.
- Both of those keys were then lost, and StakeHound says Fireblocks deleted its copy before Coincover could verify the backup. Fireblocks disputes this account and blames StakeHound's own backup handling.
- With only two of four shares available, the 3-of-4 threshold could never be met, leaving 38,178 staked ETH inaccessible.
Protocol details
Evidence
- report Report archive.is
- report Report archive.is
- analysis DeFiLlama defillama.com
- analysis Fireblocks ETH 2.0 Key Management Incident stakehound.com
- analysis Staking company serves Fireblocks with a lawsuit over private keys to over $75 million in ETH theblock.co
- analysis StakeHound, Fireblocks in Hot Water After Losing Clients' $75M in Ether (ETH) crypto.news
- analysis Stakehound Accuses Fireblocks of Losing $74M of ETH thedefiant.io
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.