Loading article…
Stake DAO reports an unauthorized minting of 5.4 trillion vsdCRV tokens on Arbitrum after a deployer private key was compromised, leading to a security alert.
The decentralized finance platform Stake DAO has confirmed a security breach on the Arbitrum network that resulted in the unauthorized issuance of 5.44 trillion vsdCRV tokens [1]. The protocol’s development team has officially acknowledged the incident and urged users to refrain from interacting with the affected asset while they work to address the vulnerability [1].
Key takeaways
The exploit originated from the direct compromise of a Stake DAO deployer private key on the Arbitrum network [1]. By obtaining this privileged credential, the attacker was able to modify the configuration of a cross-chain bridge to link a malicious contract they controlled on the Ethereum network [1]. According to Shalev Keren, co-founder of the security firm Sodot, the attacker used this access to send a validation message via LayerZero’s interoperability technology, which deceived the system into triggering the massive, unauthorized minting of tokens [1].
Security analysts noted that the absence of a multi-signature scheme or a time-delay mechanism enabled the attacker to execute the exploit rapidly [1]. Data from Sodot indicates that only twenty-five seconds passed between the modification of the bridge configuration and the minting of the tokens [1]. Following the minting, the attacker began swapping the vsdCRV assets for ETH and moving the funds to the Ethereum mainnet using decentralized bridges [1].
The Stake DAO team has temporarily suspended minting operations to mitigate further damage [1]. They are currently coordinating with infrastructure providers and blockchain forensic firms to monitor the movement of the remaining funds [1]. The team expects to deploy a patched contract on Arbitrum once the compromised key's functions have been fully revoked [1].
This incident follows a broader trend of increased activity targeting decentralized finance protocols. Industry estimates suggest that cumulative losses from exploits in the sector have exceeded $600 million since April 2026 [1]. Analysts have pointed to the use of advanced artificial intelligence tools by attackers as a contributing factor to the rise in these security incidents [1]. The operational pattern observed in the Stake DAO attack has been compared to the exploit suffered by the Wasabi protocol last month [1].
Coverage is mostly measured — 103 of 107 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 2 outlets · Jun 2, 2026 · How we report
DAI is a stablecoin that aims to stay close to one US dollar by being backed by over‑collateralized crypto assets and governed by MakerDAO.
Governance is conducted by MKR token holders who propose and vote on changes to collateral parameters, ratios, and interest rates via on‑chain mechanisms.
The hack led the Ethereum community to hard‑fork the blockchain to recover most funds, after which the DAO token was delisted and the organization became defunct.
Sky's flagship stablecoin is USDS, with a reported supply of $21 billion in early 2026.
Sky's press release estimated $611 million in gross revenue for its ecosystem in 2025.