Everstake Home
Products Solutions Security Resources Developers Company
Home
BLOG
Lessons in Validator Ethics from a Recent Delegation Mechanism Exploit
APR Was High. 37,000 SOL Was Lost.

solana

Lessons in Validator Ethics from a Recent Delegation Mechanism Exploit

Misaligned incentives. Underpaid users. A broken trust loop. We unpack what went wrong — and what needs to change.

MAY 20, 2025

Table of Contents

What Happened

The Response

Why It Matters

What We’ve Learned

Our Commitment at Everstake

Final Thoughts

Share with your network

In early May, the Solana community uncovered a troubling vulnerability in a widely used stake delegation system. The flaw wasn’t hidden in obscure code but in the logic itself. Throughout 126 epochs, it quietly enabled certain validators to extract tens of thousands of SOL in value at the expense of stakers.

This isn’t just a story about lost funds. It’s a case study in how validator incentives, delegation design, and transparency shape the integrity of staking ecosystems.

What Happened

One Solana-based staking platform uses an auction-based delegation model, where validators submit bids to receive stake from a pool. The goal is to create a competitive environment that maximizes APR for stakers by allocating SOL to validators offering the best performance-to-cost ratio.

However, several validators discovered a flaw in this system:

  • They bid high to win stake allocations.
  • After securing the delegation, they lowered their bids and bond amounts and continued to get high stake.
  • This allowed them to retain large portions of stake at a much lower cost, while still appearing competitive in future epochs.

As a result, the platform continued allocating stake to validators who had essentially stopped paying for it, draining value from the pool without providing equivalent returns.

Throughout 126 epochs, this behavior resulted in an estimated 37,000 SOL in diverted rewards, a value that could have gone to users but was instead captured by a handful of validators.

The outcome was that stakers were consistently underpaid. Users received far less than the APRs they were promised, even though the system showed numbers that looked healthy on the surface.

The Response

Once the issue gained public traction, the platform’s team released a patch. The update now penalizes validators who reduce their bids after securing delegation — a clear indication that the original design didn’t fully anticipate this kind of manipulation.

The incident was framed not as a critical bug but as a “known inefficiency.” That may be technically accurate. Ethically, however, it left room for exploitation.

Why It Matters

This wasn’t just a one-off exploit—it exposed how easily delegation systems can be gamed when incentives go unchecked. Users lost more than rewards: clarity, control, and trust.

The validators behind this exploit were also running sandwich attacks — extracting value from regular users and harming the broader network. To make things worse, the inflated APRs created by this behavior gave users a false sense of value. A high yield isn’t always a good sign — sometimes, it’s the first warning.

In this case, it signaled a broken system. Users were underpaid, and governance was prioritized over short-term profit.

When reward logic can be manipulated, the real damage isn’t just financial—it’s reputational. And that raises a bigger question: What does ethical validator behavior actually look like?

What We’ve Learned

As one of the largest non-custodial validators in the industry, we believe this incident brings several vital lessons to the forefront:

  • Ethical validators don’t exploit known inefficiencies.

Just because something is technically possible doesn’t make it acceptable. Responsible validators operate with a long-term view, not a short-term arbitrage mindset.

  • Transparency isn’t optional.

If a staking platform uses complex delegation mechanics, it must also make the logic and validator selection process accessible and auditable. This is especially critical in liquid staking models, where users don’t choose their validator directly.

  • Incentive design must evolve—and fast.

Any staking system that rewards behavior like bid manipulation or MEV extraction must be re-evaluated. Without aligned incentives, even well-intentioned platforms can enable harmful behavior.

  • Users deserve clarity and control.

Whether you’re staking 1 SOL or 10,000, you have a right to know how your funds are used, how rewards are calculated, and whether those systems are built on integrity.

Our Commitment at Everstake

Everstake was not involved in any part of this exploit. We do not participate in sandwich attacks, bid manipulation, or any practice that undermines network fairness.

Our role is to support decentralization, not distort it. We build infrastructure that prioritizes reliability, transparency, and ethical alignment—and we actively support open auditing and responsible delegation logic across the networks we serve.

Final Thoughts

This incident reminds us that the incentives behind validator delegation must be carefully designed and continuously evaluated. Users deserve clarity about where their stake goes, how rewards are calculated, and what validator behaviors are rewarded or punished.

And one more reminder: if a validator’s advertised APR looks too good to be true, far above the network average, that’s often a red flag, not a selling point. Responsible staking means asking questions, doing your own research, and choosing validators who prioritize the network’s health, not just profit.

To those staking with Everstake—whether directly or via third-party platforms—know this: you’re delegating to a team that prioritizes long-term trust over short-term gain, integrity over opportunism, and sustainability over exploitation.

***

Everstake is a software platform that provides infrastructure tools and resources for users but does not offer investment advice or investment opportunities, manage funds, facilitate collective investment schemes, provide financial services, or take custody of, or otherwise hold or manage, customer assets. Everstake does not conduct any independent diligence on or substantive review of any blockchain asset, digital currency, cryptocurrency, or associated funds. Everstake’s provision of technology services allowing a user to stake digital assets is not an endorsement or a recommendation of any digital assets by it. Users are fully and solely responsible for evaluating whether to stake digital assets.

Share with your network

Everstake

Content Manager

Everstake is the leading non-custodial staking provider, delivering audited, globally distributed infrastructure aligned with SOC 2 Type II, ISO 27001, and NIST CSF 2.0 for institutional and retail clients.

Related Articles

DES -286

solana

Understanding the Solana Consensus Mechanism: A Guide to Proof of History

This article explores how Solana’s Proof of History functions as a cryptographic clock to establish a verifiable sequence of events, eliminating the communication setbacks found in traditional blockchains.

FEB 24, 2026

Знімок екрана 2026-02-05 о 11.22.52

ethereum

solana

Everstake partners with Digital Shield to support secure, non-custodial ETH and SOL staking

Everstake has partnered with Digital Shield to support a security-first approach to non-custodial staking for self-custody users. As staking becomes a foundational component of Proof-of-Stake networks, the reliability of validator infrastructure and the clarity of custody boundaries are increasingly important. This partnership brings together hardware-based key protection and non-custodial validator operations to support secure participation...

FEB 05, 2026

SOL staking that fits in your pocket

solana

How to Stake SOL via MetaMask Portfolio with Everstake: Guide for Mobile

Everstake brings reliable Solana staking to MetaMask Portfolio. Secure, non-custodial, effortless. This guide shows how to proceed.

OCT 29, 2025

Disclaimer

Everstake, Inc. or any of its affiliates is a software platform that provides infrastructure tools and resources for users but does not offer investment advice or investment opportunities, manage funds, facilitate collective investment schemes, provide financial services or take custody of, or otherwise hold or manage, customer assets. Everstake, Inc. or any of its affiliates does not conduct any independent diligence on or substantive review of any blockchain asset, digital currency, cryptocurrency or associated funds. Everstake, Inc. or any of its affiliates’s provision of technology services allowing a user to stake digital assets is not an endorsement or a recommendation of any digital assets by it. Users are fully and solely responsible for evaluating whether to stake digital assets.

Sign Up for
Our Newsletter

By submitting this form, you are acknowledging that you have read and agree to our Privacy Notice, which details how we collect and use your information.

PRODUCTS

Institutional StakingYield InfrastructureVaaSSWQOSShredStream

Everstake Validation Services LLC

Hermes Corporate Services Ltd., Fifth Floor, Zephyr House

122 Mary Street, George Town, P.O. Box 31493

Grand Cayman KY1-1206, Cayman Islands

Privacy NoticeTerms of UseCookie Policy

Everstake is a software platform that provides infrastructure tools and resources for users but does not offer investment advice or investment opportunities, manage funds, facilitate collective investment schemes, provide financial services or take custody of, or otherwise hold or manage, customer assets. Everstake does not conduct any independent diligence on or substantive review of any blockchain asset, digital currency, cryptocurrency or associated funds. Everstake’s provision of technology services allowing a user to stake digital assets is not an endorsement or a recommendation of any digital assets by it. Users are fully and solely responsible for evaluating whether to stake digital assets. All metrics displayed on the website, including without limitations value of staked assets, total number of active users, rewards rates, and networks supported, are historical figures and may not represent the actual real-time data.

Copyright © 2026 Everstake