Stake DAO
Rejected venues wait the longest for re-review; a rejection has to earn another look before the scheduled date.
REJECTED. Stake DAO is not one vault and is not accurately classified as a discretionary vault-of-vaults allocator. The tracked slug combines liquid lockers for governance tokens, boosted strategies for user-selected LP positions, lending against strategy collateral and Votemarket. DefiLlama records about $117.5M across ten reported networks, but neither that aggregate nor the documentation homepage maps one client instrument to product-level TVL on a named chain. An sdCRV holder relies on permanently relocked CRV and secondary sdCRV liquidity; a strategy depositor still owns Curve, Balancer or another protocol’s LP risk; a borrower adds liquidation; a Votemarket participant sells or buys voting incentives. The new protocol timelock improves current controls, but its 48-hour delay, guardian powers and withdrawal promise must be verified for the exact deployment. No aggregate approval can bridge these product, chain and exit differences. The individual verdict remains zero.
- Reopen only for one named locker, strategy or lending market on one chain with product-level TVL, exact underlying assets, every live contract, proxy admin, guardian, gauge, reward receiver, bridge and fee mapped at one timestamp
- Every selected deployment must reconcile to a read audit and resolved findings, with twelve months of product-level pause, loss, oracle, liquidation and failed-withdrawal history and no unexplained event
- A locker requires three proposed-size sdToken sales in separate months within 100 basis points and disclosed pool depth at least ten times proposed size; permanent underlying lock cannot be represented as native redemption
- A strategy requires both receipt withdrawal and underlying LP unwind within one business day and 100 basis points at proposed size; a lending market additionally requires liquidation and bad-debt stress inside written limits
- Any guardian action that blocks withdrawal, timelock bypass, undisclosed authority change, bridge dependency without an audited escape path, or reliance on aggregate Stake DAO TVL keeps the selected product rejected
The research file
Product and chain scope
Liquid lockers accept a named governance token, lock and continuously relock it for maximum duration, and mint a transferable sdToken. Strategies instead deposit a named LP token into that underlying protocol’s gauge and apply Stake DAO voting power to boost rewards. Lending wraps a strategy position as collateral and adds an oracle, borrow and liquidation path. Votemarket is a separate vote-incentive marketplace. Stake DAO documentation says lockers and strategies span multiple networks; the contract registry is the required source of truth for each deployment. The DefiLlama slug reports Ethereum, Base, Arbitrum, Fraxtal, OP Mainnet, Gnosis, Avalanche, Polygon, Linea and Sonic, but that chain list does not mean every product or sdToken exists on every chain. Review must select one product, token, contract and network.
Current authorities and underlying dependencies
Stake DAO’s current control documentation says a ProtocolTimelock owns the ProtocolController and critical parameters. A governance multisig proposes changes, execution is permissionless after a minimum 48-hour delay, a guardian can immediately pause deposits or shut down a gauge, and an admin can change guardian roles. The page states emergency actions do not block withdrawals. The address registry identifies core Ethereum SDT, vlSDT and governance contracts and is synchronized from an off-chain registry, but the memo still lacks a frozen product-by-chain map of every proxy admin, guardian, strategy, gauge, reward receiver and bridge. Each underlying Curve, Balancer or other gauge retains its own governance, oracle, pool and token controls.
Security and incident evidence
Stake DAO publishes an audit inventory spanning named locker, strategy, governance and Votemarket components, plus external-review and bug-bounty pages. That establishes review artifacts, not that the selected deployed bytecode is in scope or every finding was remediated. No cited primary page is a complete product-by-product incident ledger covering core contracts, gauges, bridges, reward tokens, oracle failures, liquidation losses and failed withdrawals. The memo therefore makes no claim that the protocol has never suffered an incident. Before reopening, on-chain loss and pause history must be reconciled for the exact locker, strategy or lending market and every dependency.
Locker, strategy and lending exits
A liquid-locker deposit is not natively reversible: the governance token is locked for maximum duration and continuously relocked. Stake DAO describes the holder’s exit as selling the sdToken through a DEX, whose exchange rate fluctuates with demand. Available pool depth and discount—not aggregate protocol TVL—therefore govern realization. A strategy withdrawal can return the selected LP exposure, but the investor must still remove liquidity from the underlying AMM and bear its inventory and slippage. Lending can liquidate the strategy collateral before either exit. The 48-hour timelock page states withdrawals remain active during guardian pause or shutdown; that claim must be tested against the selected live contracts, bridge and underlying gauge.
Named comparisons and decision
For sdCRV, direct veCRV is the control comparison: it sacrifices transferability for a known Curve lock, while sdCRV adds Stake DAO contracts and market discount in exchange for a tradable receipt and vote replication. For a boosted Curve LP strategy, Convex is the named aggregator comparison and direct Curve gauge staking is the no-wrapper comparison; all three retain the same LP inventory risk. For borrowing, direct Aave V3 supply is a simpler lending comparison than borrowing against a boosted LP wrapper. Stake DAO may compete on reward timing, voting power and fees, but those benefits cannot be compared until one market’s fee schedule, executable exit and authority map are measured on the same date. The aggregate record remains rejected.
Sources
The claims above trace to these. Where a number could not be independently verified, the thesis says so.
- Stake DAO current product overview · primary · accessed 2026-08-15
Supports: liquid lockers, strategies, lending, Votemarket, vlSDT governance - Stake DAO liquid-locker design · primary · accessed 2026-08-15
Supports: maximum-duration continuous relock, sdToken issuance, DEX-only locker exit, floating sdToken exchange rate, cross-chain claim - Stake DAO strategy design · primary · accessed 2026-08-15
Supports: user-selected LP gauge, boosted reward mechanism, permissionless harvest, reward timing, Convex comparison - Stake DAO protocol timelock · primary · accessed 2026-08-15
Supports: 48-hour minimum delay, proposer and executor roles, guardian pause and shutdown, admin role, withdrawal availability claim - Stake DAO live contract-address registry · primary · accessed 2026-08-15
Supports: product-by-chain address source, SDT and vlSDT contracts, governance address, off-chain registry synchronization - Stake DAO security-audit inventory · primary · accessed 2026-08-15
Supports: audit reports, component scope, review providers, report dates - Stake DAO locker rewards and fees · primary · accessed 2026-08-15
Supports: locker-specific variable fees, performance-fee basis, reward sources, liquidity incentives - Stake DAO Votemarket v2 white paper · primary · accessed 2026-08-15
Supports: vote-incentive product boundary, campaign mechanism, reward distribution, Votemarket audit claim - DefiLlama Stake DAO survey record, read 2026-08-14 · secondary · accessed 2026-08-15
Supports: aggregate survey TVL, reported chain distribution, protocol category, survey timestamp
Inherited controls
The verdict above grades the protocol layer. Every position also inherits the asset it holds and the chain it settles on. The least safe layer sets the position’s grade, and the position table names which one that is.
| Chain | Verdict | Grade | Control constraint |
|---|---|---|---|
| Ethereum | Approved | sovereign | No sequencer, no upgrade key, no operator who can be compelled — rule changes require social consensus. |
| Base | Approved · limits | hybrid | Coinbase — one regulated US company — operates the only sequencer, and admin keys can upgrade bridge contracts within ~7 days. |
| Arbitrum One | Approved · limits | hybrid | a single sequencer orders >99% of transactions and admin keys can upgrade bridge contracts on a ~7-day timelock. |
| OP Mainnet | Rejected | hybrid | Ethereum forced inclusion limits sequencer censorship, but the Foundation and Security Council can co-sign an immediate upgrade before a client can exit. |
| Gnosis Chain | Approved · limits | crypto-backed | the chain validator path is permissionless, but its xDAI and canonical bridge exposure adds an 8-of-15 governor multisig outside the base consensus grade. |
| Avalanche | Approved · limits | crypto-backed | no party can freeze or seize C-Chain funds, but one vendor writes the only production client and Messari measured over a third of stake hosted on AWS. |
| Polygon PoS | Rejected | hybrid | a public validator set orders transactions, but a 5-of-9 multisig can instantly upgrade staking and canonical bridge contracts, while a 5-of-8 controls custom child tokens. |