Loading article…
Stake DAO confirms an attacker minted 5.4 trillion vsdCRV tokens on Arbitrum via a compromised key. Core products remain unaffected as the bridge is closed.
Stake DAO is conducting a preliminary investigation into a security incident that occurred on May 27, during which an unauthorized party minted 5.44 trillion vsdCRV tokens on the Arbitrum network [1]. While the nominal value of the minted tokens was high, the attacker was limited to extracting approximately 43.78 ETH, worth about $91,000, due to the thin liquidity available in the token's markets [1, 3].
Key takeaways
Security firms Blockaid and BlockSec identified that the attacker used the stolen deployer key to redirect trust from the legitimate Ethereum adapter to a malicious contract [1]. By sending a forged cross-chain message, the attacker triggered the unconditional minting of the vsdCRV tokens [1]. Once the tokens were minted, the attacker attempted to swap them through Curve and KyberSwap, but the lack of market depth prevented further extraction, leaving the vast majority of the minted tokens with no liquidity to sell into [1, 3].
Stake DAO contributors acted to secure the vsdCRV backing on the Ethereum mainnet before the attacker could access it, ensuring that no backing funds were seizable [2]. While the protocol’s primary yield and governance services were not compromised, the incident forced the closure of the Arbitrum asdCRV Llamalend market [2]. This decision was made because the market relied on asdCRV as collateral, and the mass minting event created instability in the associated oracles [1].
The Stake DAO incident highlights the ongoing vulnerability of DeFi protocols to private key compromises, which have accounted for significant losses across the industry in 2026 [1]. The exploit follows a pattern seen in other recent incidents, such as the Kelp DAO hack, where attackers utilized similar LayerZero peer-configuration vulnerabilities [1].
As of May 28, the investigation remains ongoing with the assistance of security partners and law enforcement [2]. Stake DAO has characterized its current findings as preliminary, and the community is awaiting a full post-mortem to determine the final scope of the incident and any potential recovery plans [1]. Users have been warned not to interact with vsdCRV while the protocol continues its review [3].
Coverage is mostly measured — 60 of 75 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
A DAO is a decentralized autonomous organization that uses blockchain-based software and smart contracts to manage organizational processes like voting and finance.
The legal status of DAOs is generally unclear and varies by jurisdiction, though some states like Wyoming have introduced legislation to recognize them as legal entities.
Because DAO code is difficult to alter once live, fixing security holes often requires writing new code and reaching an agreement to migrate all funds to a new system.
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 4 outlets · Jun 2, 2026 · How we report
Voting power is typically coordinated through governance tokens or NFTs, where holding a larger quantity of tokens often translates to greater influence over organizational decisions.