Loading article…
Stake DAO confirms an attacker minted 5.4 trillion vsdCRV tokens on Arbitrum via a compromised key. Core products remain unaffected as the bridge is closed.
Stake DAO is conducting a preliminary investigation into a security incident that occurred on May 27, during which an unauthorized party minted 5.44 trillion vsdCRV tokens on the Arbitrum network [1]. While the nominal value of the minted tokens was high, the attacker was limited to extracting approximately 43.78 ETH, worth about $91,000, due to the thin liquidity available in the token's markets [1, 3].
Key takeaways
Security firms Blockaid and BlockSec identified that the attacker used the stolen deployer key to redirect trust from the legitimate Ethereum adapter to a malicious contract [1]. By sending a forged cross-chain message, the attacker triggered the unconditional minting of the vsdCRV tokens [1]. Once the tokens were minted, the attacker attempted to swap them through Curve and KyberSwap, but the lack of market depth prevented further extraction, leaving the vast majority of the minted tokens with no liquidity to sell into [1, 3].
Stake DAO contributors acted to secure the vsdCRV backing on the Ethereum mainnet before the attacker could access it, ensuring that no backing funds were seizable [2]. While the protocol’s primary yield and governance services were not compromised, the incident forced the closure of the Arbitrum asdCRV Llamalend market [2]. This decision was made because the market relied on asdCRV as collateral, and the mass minting event created instability in the associated oracles [1].
The Stake DAO incident highlights the ongoing vulnerability of DeFi protocols to private key compromises, which have accounted for significant losses across the industry in 2026 [1]. The exploit follows a pattern seen in other recent incidents, such as the Kelp DAO hack, where attackers utilized similar LayerZero peer-configuration vulnerabilities [1].
As of May 28, the investigation remains ongoing with the assistance of security partners and law enforcement [2]. Stake DAO has characterized its current findings as preliminary, and the community is awaiting a full post-mortem to determine the final scope of the incident and any potential recovery plans [1]. Users have been warned not to interact with vsdCRV while the protocol continues its review [3].
Coverage is mostly measured — 142 of 146 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 4 outlets · Jun 2, 2026 · How we report
A Dao Crypto acts as a governance structure for protocols, allowing token holders to participate in decision-making and protocol management. For example, Curve DAO uses its native token to enable holders to lock assets and vote on governance matters, while TRON DAO facilitates integrations with other protocols to expand ecosystem utility.
Dao Crypto governance allows community members to vote on the status of leadership roles, which can lead to the termination of personnel. As of the reported event involving the Ethereum Name Service, community delegates voted to remove a director of operations following public controversy over past statements.
The price of the CRV token increased by more than 16% due to renewed investor interest in the decentralized finance sector and higher trading volumes on decentralized platforms. This movement reflects a broader trend of capital flowing back into established DeFi protocols as of the recent market period.
TRON DAO expands its ecosystem by integrating new assets and protocols, such as the recent partnership with Ethena Labs to bridge synthetic dollar tokens onto the TRON network. This integration allows users to utilize USDe and sUSDe within TRON-based DeFi platforms like JustLend DAO and SUN.io.