StakeDAO — vsdCRV Deployer Key Exploit (May 2026)
Summary
On May 27, 2026, a threat actor compromised a StakeDAO deployer private key that had retained owner privileges on the vsdCRV LayerZero v2 OFT contract on Arbitrum since March 2024, enabling the minting of 5.44 trillion unbacked vsdCRV tokens within 25 seconds. Despite the astronomically large nominal mint, thin DEX liquidity limited the attacker's realized gain to approximately 43.78 ETH (~$91,000), which was subsequently laundered via Tornado Cash. StakeDAO passed a voluntary governance proposal (SDGP-70) to compensate 242 affected addresses with 1,535,421.76 sdCRV and filed a criminal complaint with Swiss authorities.
Connected Entities
1 entities · 10 linked investigationsTimeline(9 events)
2024-03-01
StakeDAO deployer wallet (0x000755Fbe4A24d7478bfcFC1E561AfCE82d1ff62) deploys vsdCRV LayerZero OFT contract on Arbitrum and retains owner privileges rather than transferring to governance multisig — the operational failure that later enabled the exploit.
CryptoTimes post-mortem coverage2026-03-12
Separate StakeDAO oracle message spoofing incident on Arbitrum and Base chains results in an alleged $176,000 loss — a distinct vulnerability class from the May deployer key exploit.
Smart Contract Hacking incident database2026-05-27
Attacker, having funded preparation wallets via Tornado Cash, uses the compromised StakeDAO deployer key to call setPeer() on the vsdCRV LayerZero v2 OFT contract on Arbitrum, redirecting trusted peers to a malicious contract. A forged cross-chain message mints 5,446,744,073,709 vsdCRV tokens to attacker wallet 0xeF3C054d8F7eD0a7D61c8da56ff55F090577aa25 within 25 seconds. The attacker swaps approximately 16.83 million vsdCRV across Curve and KyberSwap DEX pools, extracting 43.78 ETH (~$91,000), draining 321,143 CRV and 7.5 ETH from the Curve pool.
The Block, AMBCrypto, CryptoTimes2026-05-27
Blockaid publicly flags the exploit in progress. PeckShield and BlockSec confirm the attack vector. StakeDAO warns users not to interact with vsdCRV. Curve Finance warns LlamaLend users to withdraw. Beefy Finance pauses Arbitrum vaults.
Crypto Briefing, CryptoTimes2026-05-27
StakeDAO contributors secure mainnet vsdCRV backing within 47 minutes of the forged mint, preventing additional collateral loss. Arbitrum bridge permanently closed. Deployer owner privileges revoked and transferred to governance multisig same day.
CryptoTimes post-mortem, Stake DAO Assures Users2026-05-31
Attacker deposits extracted ETH proceeds into Tornado Cash in multiple transactions on Ethereum mainnet.
AMBCrypto2026-06-09
Stake DAO publishes detailed post-mortem and SDGP-70 governance proposal for voluntary ex gratia compensation of 1,535,421.76 sdCRV (~$173,000) to 242 affected addresses. Stake DAO also confirms it has filed a criminal complaint with Swiss authorities.
CryptoTimes, Stake DAO Governance2026-07-01
SDGP-70 compensation claims become available via Merkle tree contract on Ethereum mainnet through the Stake DAO portfolio interface, with a six-month claim window.
Stake DAO Governance SDGP-702026-08-03
SDGP-75 voting concludes, extending ex gratia compensation to Arbitrum asdCRV LlamaLend market borrowers unfairly liquidated during the vsdCRV price collapse on May 27.
Stake DAO Governance SDGP-75Decision Log
- #1publish⛓ pending8/8/2026, 5:15:33 PMhash: DmynN5Py4hbpV1Kx64dizcwQAW8FjnhH23KyyWXkZEfk
8 of 18 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/8/2026, 5:15:25 PM
last updated: 8/8/2026, 9:52:56 PM
avoid.net — verified advice for a post-truth world