A Risk Analysis of Non-custodial Staking in Ethereum
Abstract
Non-custodial staking in Ethereum empowers users to participate in securing the network without transferring their funds to any entity other than the official deposit contract. This approach minimizes the need for trust in third parties, aligning with the core principles of decentralization. However, there is a lack of studies to understand the risk that a staker takes when choosing a non-custodial solution. Furthermore, non-custodial staking may be difficult for non-technical users. In this paper, we analyze the risk of non-custodial staking in Ethereum and we provide some tools to simplify some of the processes for non-technical users. We introduce a detailed threat model in which an attacker gains access to a validator’s private key, and evaluate both the direct financial losses due to slashing and the potential economic incentives for an attacker. Two attack scenarios are explored-targeting solo stakers and coordinated attacks on non-custodial services-quantifying their impact and feasibility. We also provide lightweight Python scripts that enable users to generate and validate voluntary exit messages without deploying a full Ethereum node. These tools are especially relevant for increasing the resilience of non-custodial staking, particularly in the event of service disruption. Our results suggest that while validator key exposure is a serious risk, rational non-custodial providers are economically disincentivized from behaving maliciously.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.