Stake DAO faces an ongoing exploit after an attacker minted 5.4T vsdCRV on Arbitrum and began swapping funds for ETH, researchers said.Stake DAO faces an ongoing exploit after an attacker minted 5.4T vsdCRV on Arbitrum and began swapping funds for ETH, researchers said.

DeFi exploit hits Stake DAO as attacker swaps vsdCRV for ETH

2026/05/27 20:14
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 [email protected]으로 연락주시기 바랍니다

Stake DAO is facing an ongoing exploit tied to its vsdCRV token on Arbitrum. Blockchain security firm Blockaid said an attacker minted more than 5.4 trillion vsdCRV and began swapping the tokens for ETH.

Summary
  • Stake DAO warned users not to interact with vsdCRV as the exploit remained active.
  • Security researchers said an attacker minted about 5.4 trillion vsdCRV on Arbitrum before swapping funds.
  • The suspected cause was a compromised deployer key used to alter LayerZero peer settings.

Stake DAO confirmed it was aware of the situation and told users not to interact with vsdCRV. The project’s warning came as researchers continued tracking the attacker’s activity across Arbitrum and Ethereum.

vsdCRV, or vote-boosted sdCRV, is tied to the Curve Finance ecosystem and used within Stake DAO’s yield products. The token became the center of the incident after the attacker allegedly gained enough control to mint a huge supply.

PeckShield said part of the minted funds had already been swapped for 43.78 ETH, worth about $91,000, and bridged to Ethereum. The incident remains a developing story, and final loss figures may change as more transactions are traced.

Source: PeckShield/X

Researchers point to deployer key compromise

Blockaid said the suspected root cause was a compromised Stake DAO deployer private key. According to the firm, the attacker used that access to reconfigure the LayerZero v2 OFT peer for the vsdCRV token contract.

That change allegedly redirected trust from the legitimate Ethereum-side adapter to a malicious contract controlled by the attacker. The attacker then sent a forged cross-chain message that triggered the minting of roughly 5.44 trillion vsdCRV.

BlockSec described the attack as a case where the attacker appeared to obtain the deployer’s private key and set an arbitrary peer for vsdCRV. The firm said the forged message then caused unconditional minting to the attacker’s address.

The incident shows how privileged access remains a major risk in DeFi. Even when smart contract code works as designed, a compromised deployer key can give attackers the ability to change trusted settings and trigger losses.

DeFi security concerns deepen

The Stake DAO exploit follows a series of recent DeFi incidents. As previously reported by crypto.news, OpenZeppelin co-founder Manuel Aráoz said he now considers “all of DeFi” unsafe and has advised friends and family to exit DeFi positions.

Aráoz argued that coding agents are becoming strong tools for finding vulnerabilities, while defenders still need to fix every weakness before attackers find one. His comments came as DeFi protocols lost about $629.7 million to hacks in April.

Separately,  Wasabi Protocol lost more than $5 million across Ethereum, Base, Berachain, and Blast after a compromised admin key allowed attackers to upgrade contracts and drain funds.

That case resembles the current Stake DAO concern because both incidents involved privileged key access rather than a simple market manipulation event. Wasabi also warned users not to interact with its contracts while the team investigated.

Cross-chain risks remain in focus

The Stake DAO incident also points back to cross-chain token risks. Security reports have tracked repeated attacks involving bridges, peer settings, and message validation across chains in 2026.

BlockSec’s May security roundup listed multiple incidents across Ethereum, Sui, BNB Chain, Base, Blast, and Berachain, with total losses of about $15.9 million over a two-week period. Its blog also identified Wasabi as a key-compromise case.

In April, Kelp DAO suffered one of the year’s largest DeFi exploits after attackers drained about $292 million from a LayerZero-powered bridge. The breach raised concerns about cross-chain asset backing across more than 20 networks.

시장 기회
이더리움 로고
이더리움 가격(ETH)
$2,024.28
$2,024.28$2,024.28
-0.10%
USD
이더리움 (ETH) 실시간 가격 차트

SPACEX(PRE) Launchpad

SPACEX(PRE) LaunchpadSPACEX(PRE) Launchpad

Register for a chance to win a free lucky draw

면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, [email protected]으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

SPACEX(PRE) Launchpad

SPACEX(PRE) LaunchpadSPACEX(PRE) Launchpad

Register for a chance to win a free lucky draw