> ## Content Index
> Fetch the complete content index at: https://blog.lido.fi/llms.txt
> Use this file to discover other available public pages before exploring further.

# Lido V3 & Cactus: Accessing stVaults via Cactus Link
- URL: https://blog.lido.fi/lido-v3-cactus-accessing-stvaults-via-cactus-link/
- Published: 2026-05-29T08:21:53.000Z
- Updated: 2026-05-29T08:45:11.000Z
- Description: Cactus Custody, an institutional digital asset custodian, supports Lido V3 stVaults through Cactus Link, its DeFi connector. Cactus Custody clients can create and manage stVaults from their existing custody account.
- Author: Lido
- Tags: Lido V3

[Cactus Custody](https://www.mycactus.com/?ref=blog.lido.fi), an institutional digital asset custodian, now supports [Lido V3 stVaults](https://lido.fi/stvaults?ref=blog.lido.fi) through Cactus Link, its DeFi connector. Cactus Custody clients can create and manage stVaults from their existing custody account.

Cactus Custody is the institutional digital asset custody solution of [BIT](https://www.bit.com/?ref=blog.lido.fi) (formerly Matrixport), founded in February 2019\. The platform safeguards digital assets across 60+ blockchain ecosystems for over 400 institutional clients, including investment funds and asset managers, exchanges, OTC providers, payment platforms, mining pools, and institutional DeFi participants.

Cactus Custody holds a Hong Kong Trust or Company Service Provider (TCSP) license and a Bhutan Gelephu Mindfulness City Authority (GMCA) Financial Services Licence (FSL), with SOC 1 Type II and SOC 2 Type II attestations (Deloitte) [covering its custody operations](https://www.mycactus.com/trust-center?ref=blog.lido.fi). Its architecture combines HSM-backed cold storage with an institutional MPC offering, giving clients a choice between qualified-custodian and self-custody-style configurations.

Cactus Custody [is one of the Qualified Custodians](https://docs.lido.fi/run-on-lido/stvaults/qualified-custodians/?ref=blog.lido.fi) supporting stVaults, Lido protocol's modular staking infrastructure. stVaults introduce a single-operator architecture that enables large staking entities (including institutions, ETFs, ETPs, and asset managers) to deploy dedicated, customizable vaults with control over validator choice, fee terms, and infrastructure, while retaining on-demand liquidity through optional stETH minting.

Compared to pooled staking approaches, stVaults are designed to address the control-versus-liquidity tradeoff, enabling stakers to run validators with their chosen counterparty, define geographic or jurisdictional parameters, and configure MEV routing and insurance mandates to meet specific internal risk and policy requirements.

![](https://blog.lido.fi/content/images/2026/05/data-src-image-d2333bc2-e1f0-49eb-b92e-0569bb2197d3.png)

The integration builds on Cactus Custody’s existing support for stETH and wstETH. Institutions holding Lido liquid staking tokens in custody can now combine them with stVault operations and other DeFi protocols accessible through Cactus Link.

![](https://blog.lido.fi/content/images/2026/05/Cactus_quote_Sam.png)

## **How It Works**

The connection runs through [Cactus Link](https://chromewebstore.google.com/detail/cactus-link/chiilpgkfmcopocdffapngjcbggdehmj?ref=blog.lido.fi), a browser extension that operates similarly to a standard hot wallet. Setup is two steps:

1. Install [the Cactus Link extension](https://chromewebstore.google.com/detail/cactus-link/chiilpgkfmcopocdffapngjcbggdehmj?ref=blog.lido.fi) and confirm DeFi account permissions with the Cactus Custody administrator.
2. [In the stVaults Web UI](https://stvaults.lido.fi/?ref=blog.lido.fi): click 'Connect Wallet', then 'Browser' in the dialog window.

Once connected, vault owners can create stVaults and perform day-two operations: supplying or withdrawing ETH, minting or repaying stETH, monitoring vault health, triggering rebalancing or closure, and following emergency procedures. 

Full setup steps are [in the Cactus Custody user guide](https://docs.lido.fi/run-on-lido/stvaults/qualified-custodians/cactus/?ref=blog.lido.fi).

Administrators must whitelist the stVaults smart contract addresses before interaction; the address list is available in the [Qualified Custodians overview](https://docs.lido.fi/run-on-lido/stvaults/qualified-custodians/?ref=blog.lido.fi#whitelisting-smart-contract-addresses).

This flow is for vault owners: institutions that want to create and operate their own vault.

Support varies by jurisdiction, entity, and onboarding scope. Before creating a vault, teams should confirm availability and policy settings with their Cactus account manager.

### **Security & Risk**

Standard Ethereum staking risks apply — for the full breakdown, see Lido's [Risk Assessment Framework for stVaults](https://research.lido.fi/t/risk-assessment-framework-for-stvaults/9978?ref=blog.lido.fi). 

The following measures have been implemented to support the security of Lido V3\*:

- **Smart contracts.** Lido V3 stVaults smart contracts have undergone audits by [Certora](https://github.com/lidofinance/audits/blob/main/Certora%20Lido%20V3%20Audit%20Report%20-%2012-2025.pdf?ref=blog.lido.fi) (including [formal verification](https://github.com/lidofinance/audits/blob/main/Certora%20Lido%20V3%20Formal%20Verification%20Report%20-%2012-2025.pdf?ref=blog.lido.fi)), [MixBytes](https://github.com/lidofinance/audits/blob/main/MixBytes%20Lido%20V3%20Security%20Audit%20Report%20-%2012-2025.pdf?ref=blog.lido.fi), [Consensys Diligence](https://github.com/lidofinance/audits/blob/main/Consensys%20Diligence%20Lido%20V3%20Security%20Audit%20-%2011-2025.pdf?ref=blog.lido.fi), [Composable Security](https://github.com/lidofinance/audits/blob/main/Composable%20Security%20Lido%20V3%20Oracle%20V7%20Audit%20Report%20-%2012-2025.pdf?ref=blog.lido.fi), [Ackee Blockchain](https://github.com/lidofinance/audits/blob/main/Ackee%20Blockchain%20Vault%20Wrapper%20Report%2001-2026.pdf?ref=blog.lido.fi), and [Sigma Prime](https://github.com/lidofinance/audits/blob/main/Sigma%20Prime%20-%20Lido%20BLS%20Library%20Security%20Assessment%20Report%20v2.0%20-%2001-2026.pdf?ref=blog.lido.fi). An ongoing [Immunefi bug bounty](https://docs.lido.fi/security/bugbounty?ref=blog.lido.fi) offers white hats up to $2M in rewards.
- **Custody-side controls.** Interactions with stVaults contracts are performed via Cactus Link.
- **Built-in operational controls.** stVaults’ design allows Vault Owners to end-to-end control the funds in the vault: supply/withdraw ETH, mint/repay stETH, monitor the vault health parameters and metrics, trigger ETH withdrawals from validators, perform rebalancing and vault closure or disconnect from the Lido protocol (Web UI support for these actions arriving in early Summer 2026).

*\* Audits, bug bounties, and operational controls are intended to reduce but do not eliminate underlying protocol or market risks. Additional risks may remain or be unidentified.*

For institutions, the key point is that stVaults can be operated with a familiar security model: on-chain actions may be gated by your existing Cactus Custody policies, while Lido V3 contracts have undergone audits and include clearly defined emergency procedures. Teams should still run their own diligence on smart-contract, operational, and regulatory risks, and ensure internal approvals and monitoring are in place before going live.

[Book a call](https://share-eu1.hsforms.com/1J9K3wmpfTiSn6lO7UgqXWw2dywmt?ref=blog.lido.fi) with the Lido Institutional team for further details.

## **Further Reading**

- [Cactus Announcement](https://blog.mycactus.com/announcements/cactus-lido-stvaults/?ref=blog.lido.fi)
- [Qualified Custodians Overview](https://docs.lido.fi/run-on-lido/stvaults/qualified-custodians/?ref=blog.lido.fi)
- [Cactus Custody Integration Guide](https://docs.lido.fi/run-on-lido/stvaults/qualified-custodians/cactus/?ref=blog.lido.fi)
- [stVaults Documentation](https://docs.lido.fi/run-on-lido/stvaults/?ref=blog.lido.fi)
- [stVaults 101](https://lido.fi/how-lido-works/stvaults-basics?ref=blog.lido.fi)