# Stake DAO halts Arbitrum vsdCRV market after 5.4 trillion token mint

**Published:** 2026-05-29T12:30:52.000Z  
**Topic:** Arbitrum  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/2f346652-5d99-4e9c-a1f6-855da8ea464a

Stake DAO’s Arbitrum protocol was exploited on May 27, minting 5.4 trillion vsdCRV tokens and losing about $91 k before the team froze the market and secured

Stake DAO confirmed that on May 27 an attacker exploited an infinite‑mint vulnerability on its Arbitrum vsdCRV vault, creating roughly 5.4 trillion synthetic tokens and draining about $91 000 in digital assets before the breach was contained [1].

**Key takeaways**
- An infinite‑mint flaw in the vsdCRV vault allowed the creation of 5.4 trillion counterfeit tokens [1].
- The attacker realized roughly 43.8 ETH (≈ $91 k) before the exploit was stopped [3].
- Stake DAO secured the Ethereum‑mainnet backing, deactivated the vsdCRV bridge, and sunset the Arbitrum asdCRV Llamalend market [1].
- The breach was flagged by security firms Blockaid and PeckShield, which traced the attack to a compromised deployer key rather than an Arbitrum bug [3].
- Law enforcement has been notified and the protocol is working with external auditors to trace the stolen assets [1].

## Exploit mechanics and immediate response
Preliminary analysis by Blockaid identified an “infinite‑minting” loophole in the vsdCRV vault logic and reward distribution system. The contract accepted an invalid state transition, inflating the token supply by 5.4 trillion units [1]. A separate investigation by PeckShield and Blockaid linked the attack to a compromised Stake DAO deployer key that altered the LayerZero v2 OFT peer configuration, redirecting cross‑chain trust to a malicious contract [3]. This forged message allowed the attacker to mint the massive supply on Arbitrum and swap a portion for ETH, netting about 43.8 ETH before the breach was detected [3].

Stake DAO’s core contributors acted quickly. They secured the vsdCRV backing on Ethereum, deactivated the cross‑chain bridge, and announced that no main‑net funds could be seized by the attacker [1]. The team also announced the permanent sunset of the Arbitrum asdCRV Llamalend market and urged users to avoid interacting with vsdCRV contracts while they relocate capital to unaffected markets [1].

## Broader security context
The incident arrives amid heightened scrutiny of DeFi safety, amplified by OpenZeppelin co‑founder Manuel Aráoz’s claim that “all DeFi is unsafe.” Stake DAO’s exploit underscores the ongoing challenges of operational security and cross‑chain trust, rather than a fundamental flaw in the Arbitrum layer‑2 itself [1]. OpenZeppelin responded by emphasizing AI‑driven security research and attributing many recent incidents to operational failures [1].

## Why it matters
The attack highlights the vulnerability of cross‑chain token bridges and the potential for a single compromised key to generate massive counterfeit supplies, even when the underlying blockchain remains secure. Stake DAO’s rapid containment limited financial loss to under $100 k, but the incident erodes confidence in vsdCRV and related markets, prompting users to migrate assets and regulators to watch DeFi exploits more closely. Ongoing forensic audits and cooperation with law enforcement aim to trace the stolen ETH and reinforce safeguards against similar attacks in the future.

## Sources
1. News — [Stake DAO Freezes Arbitrum vsdCRV Markets After Attacker Mints...](https://news.bitcoin.com/stake-dao-freezes-arbitrum-vsdcrv-markets-after-attacker-mints-5-4t-synthetic-tokens/)
2. Decrypt — [News Explorer — Stake DAO Hacked as Attacker Mints Trillions of VsdCRV Tokens](https://decrypt.co/news-explorer?pinned=1432286&title=stake-dao-hacked-as-attacker-mints-trillions-of-vsdcrv-tokens)
3. Coininsider — [StakeDAO Exploit Nets $91K After 5.4T Mint](https://www.coininsider.com/news/stakedao-exploit-5-4t-vsdcrv-nets-only-91k/)

---
Cite as: TrendWatcher, "Stake DAO halts Arbitrum vsdCRV market after 5.4 trillion token mint", https://www.trendwatcher.in/article/2f346652-5d99-4e9c-a1f6-855da8ea464a
