Incident Report: 37,000 SOL in Losses — A Call for Investigation and Action

Well, since Marinade has decided to stay silent and not comment on the situation, even after the people from the Top 10 themselves revealed the entire scheme of receiving free stake, we will continue to bring attention to the issue that has not been solved with the new fix. Validators are not receiving any penalties and continue to receive stake from Marinade, even with bids lower than 0.01 SOL.

In epoch 785, the MIN_effective_BID was 0.078 SOL. In this epoch, Marinade missed at least 199.72 SOL.

As of epoch 785, there are 92 validators receiving stake from Marinade, while their bid is less than 0.01 SOL. Two validators have been penalized. One was completely stripped of their bond — a total of 302.987 SOL was deducted as a penalty (55d5XyCu3Ap1yLHHJd6ChBT3pgP4HE6MPmJrU7TbAwYw), and the second lost only 44.971 SOL, but still has a remaining bond of 46.932 SOL (2wUhcnViyzstvWmk7NAboKtjbFbqJPo4BvFBV37dacLc), which will likely be enough for one more epoch.

The total stake, either fully or partially unpaid by validators for epoch 785, is 2,590,198.891 SOL (this figure already excludes the two penalized validators mentioned above).

Additionally, it’s worth noting that 5 validators have set their MEV commission to 100%, meaning that stakers are not receiving any MEV income from these validators. The total stake for these validators is 410,000 SOL.

Vote Account Marinade Activated Stake (SOL) Bid Cpmpe Inflation Commission MEV Commission Stake Priority Unstake Priority
1 55d5XyCu3Ap1yLHHJd6ChBT3pgP4HE6MPmJrU7TbAwYw 362335,1618 0.0001 0.07 0.1 288 142
2 Cue647T8jgwpRSDUb8ttTYx7NiEfJCRZNiiw1qmchXsG 337320,6683 0.0 0.05 0.1 283 134
3 4m1PbxzwLdUnEwog3T9UKxgjktgriHgE1CfAhMqDw7Xx 312484,9489 0.0 0.05 0.1 283 135
4 ErJmwESSzVrDuDJcN5L47XnM84JWDwTi6bDMWkrXqHSV 197150,4497 0.0 0.05 1.0 305 146
5 9f7dqiYNBZbgPesAnLeWnKCtxYHSfMg5x1EMZCJwVwG7 138792,4167 1,00E-09 0.0 0.1 248 102
6 4WGMxMKhjKz9TSmn6NA52AVipeE3zZNPBhQuBghZBvqU 131530,4489 0.0 0.07 1.0 308 61
7 Simpj3KyRQmpRkXuBvCQFS7DBBG6vqw93SkZb9UD1hp 129468,8123 1,00E-07 0.05 0.1 280 131
8 GMiBDMmwFRZfxVuHt3bXe6ZF7mGUBGWKXHLfY97NwQ72 109470,2366 0.007 0.05 0.1 264 120
9 21wUViiyG1g47VZ39ZZsSkFX9nu6bkyfy6jryHGD2TUB 107036,269 1,00E-09 0.0 0.1 248 103
10 EARTHZeTM64X3UMYf5rcWonQkTCn3uifEwutBx6e656K 82464,06124 0.0 0.07 0.1 290 143
11 StepeLdhJ2znRjHcZdjwMWsC4nTRURNKQY8Nca82LJp 80867,89661 0.0 0.07 1.0 308 148
12 5akpkYincAbsTBXVbf2GDCg4KatMnc8BKkXZCh7MWGPK 79391,67014 8,00E-05 0.0 0.1 241 98
13 3teZKwABvB99bxZc5q8yVWJt5mbhxgUAx4teMdUbzgN4 77283,1441 0.001 0.0 0.0999 236 94
14 2w4dcnbJDcGrAh4CFAYYpAaEJiUB2q1rFMGByBuB5Cqz 75867,35702 0.001 0.0 0.08 229 89
15 HvuXZAhAqSekCFueQ92DqxhuFvdBRrWeyA6uea6ZaS8q 74775,45883 0.001 0.0 0.1 237 95
16 2wUhcnViyzstvWmk7NAboKtjbFbqJPo4BvFBV37dacLc 61003,44797 0.0 0.0 0.0 217 85
17 3ZUQekqiZoybB57y49eqtvSaoonqDwuNbeqEGwN88JkQ 55635,66671 1,00E-09 0.0 0.0 216 81
18 Hx4UJCvf8amGeuW9fPFfTckRoznDHxPSYiU9HuUSZKLT 53320,58077 0.0 0.05 0.1 283 137
19 8ztfVJM7Yf7CMXqTGMGBkXmTkGCiJTgVfh1CYDZZND5b 52900,25462 0.0 0.05 0.1 283 139
20 EJHf5N9is5spAF5Kz384tTvTV3CwTka6qzUoZrYm53SV 51722,44536 1,00E-09 0.05 0.1 282 133
21 3tjGkvUsNEk8UBUQECCTpeAoo6NovHvEG44MZDPCcZko 48487,93843 0.005 0.05 0.1 268 123
22 3CnKZPQn92W8WXG7KTVaFQRk8LJJ3KZbrVVF4ngUxqkg 46126,73379 0.001 0.0 0.1 237 97
23 Fbnesg4kSDDoFbjaSiDQJ3GXHHAnNb1CJCgLQp4dxj4C 38185,19548 0.001 0.0 0.1 237 96
24 DsT3eKbWAaX9wVZQYBsbkDwpFA9NTDtXfsYc9wXUEWpn 34036,04015 8,00E-07 0.0 0.1 246 101
25 BHuk6wv9pskvSuMxzAFksmFNxEWZDHDsYWSwvTKcCnhx 30288,36569 0.004 0.0 0.07 220 87
26 HMLfMHdETcGSqPGAr38rSiwewsSZvLPMMPALc5pggtiW 27905,4588 0.002 0.05 0.1 272 127
27 8hPk5CbKDoM7dN9LssTdVkFhDykeq7A8CZurA5AQSFJH 23910,92528 0.05 0.05 271 0
28 Anv7J9kMdJWr1aU6rQvQyd24zBp5GscP8NeDpRqGKz8e 23505,10654 8,00E-07 0.07 0.1 289 62
29 323d4ZiSqS1PwGwpJwD88jNPaGqkm7YYW2tJt2T8iFzo 21707,64198 1,00E-05 0.0 0.1 244 100
30 CatzoSMUkTRidT5DwBxAC2pEtnwMBTpkCepHkFgZDiqb 20478,89426 0.0 0.0 217 0
31 8HKqT579dAjdTy86zKUs8kAaGDHXY11wDC3ohGCkLSQH 17185,46122 0.0085 0.05 0.1 261 119
32 sBcuGeMJCRkdtMNgskLTX7MePb4CzCqZuyMKDrcPP8v 16706,19795 8,00E-07 0.07 0.1 289 64
33 8FPz3JG4E3HVXxGbPZVibarva4AGXSZWx3qKLUS5uFtN 12358,63082 0.0 0.0 0.1 249 109
34 GA2t11gJcmuZ4y7pShTzgYDkxVaJaVQJqkVUqojhPPsT 10345,50666 4,00E-09 0.04 0.1 269 124
35 DTwEEF6VSrmTBYkDcj3BKAc52qhvP8CEQUEAMMT1cG3 10047,01665 0.0 0.0 0.1 249 108
36 GB44NXtM7zGm6QnzQjzHZcRKSswkJbox8aJsKiXGbFJr 9317,851004 0.0 0.01 0.08 253 112
37 J1to3PQfXidUUhprQWgdKkQAMWPJAEqSJ7amkBDE9qhF 8137,735347 0.0 0.08 234 0
38 juicQdAnksqZ5Yb8NQwCLjLWhykvXGktxnQCDvMe6Nx 6878,668786 0.0 0.04 0.08 267 121
39 H7fXvnLCKtZqJBTipxeseabGfAZUdHJ9XuP6hCKrbvUb 6012,574225 0.0 0.0 0.08 234 93
40 EARNynHRWg6GfyJCmrrizcZxARB3HVzcaasvNa8kBS72 3736,763268 0.0 0.0 0.1 249 104
41 WENuuMXGi8adKogNbQj33Vxgia9oA2erkWAPF4szWN1 3511,816524 0.0 0.0 0.0 217 86
42 DriFTm3wM9ugxhCA1K3wVQMSdC4Dv4LNmyZMmZiuHRpp 3357,078095 0.0 0.0 217 0
43 BeSov1og3sEYyH9JY3ap7QcQDvVX8f4sugfNPf9YLkcV 2321,337787 0.0 0.0 0.1 249 106
44 EpicsoqLdDP8qRn3wQRKTSKAXbjK9dUgFfNPRQS77MQD 2007,747526 0.0 0.0 217 0
45 FyrSH4VeQidMVPQ9AE2szAbP5xBZBprRG3z1QMMLNi5X 1631,074478 1,00E-06 0.0 0.1 245 51
46 3N7s9zXMZ4QqvHQR15t5GNHyqc89KduzMP7423eWiD5g 1599,176914 0.08 0.1 294 0
47 vahVByZszdHguLa7U7GLz8UdUFN85mcwdkefiqVjtGt 1577,373274 0.0 0.0 0.099 243 99
48 FnAPJkzf19s87sm24Qhv6bHZMZvZ43gjNUBRgjwXpD4v 1537,834954 0.0 0.0 0.08 234 91
49 ErvMUdtMC7AX55zKdYSyy4DnWNCrTsWn5GwprSG7ocnx 1309,747813 0.0 0.05 0.1 283 141
50 9kkP5sRnyHD3qkyHykyWwbP9pQQcTWnzLPHtDcRxaE16 1110,513148 1,00E-05 0.05 0.1 278 0
51 he1iusunGwqrNtafDtLdhsUQDFvo13z9sUa36PauBtk 1049,927491 0.0 0.0 0.0 217 46

I did not publish the remaining validators because their stake from Marinade in epoch 785 is less than 1000 SOL (and they also do not pay for it, or pay partially). 1000 SOL of free stake — is it really that much in the context of a 37,000 SOL loss? I’m right to assume this, aren’t I?

Also, I would like to address those validators who say something like: “Oh, I didn’t know I was doing something wrong. Yes, I took advantage of the vulnerability, but it’s not my problem, it’s Marinade’s fault.”

Dear validators, if you find a vulnerability in a banking system and exploit it, you’ll likely face real criminal charges in your country. But you probably won’t exploit that vulnerability because you understand the consequences.
However, vulnerabilities in Marinade can be exploited without any fear of consequences, right? Of course, no one will punish you. This is exactly what Marinade demonstrates with its behavior and by ignoring this thread.

Well, no worries, we will continue to raise awareness of the scale of the issue to the Solana Foundation.