# Stake DAO Investigates Exploit After Unauthorized Token Mint

**Published:** 2026-05-28T12:16:16.000Z  
**Topic:** Dao Crypto  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/4e5d9e73-80ec-44b3-88d4-99d4600ca81c

Stake DAO confirms an attacker minted 5.4 trillion vsdCRV tokens on Arbitrum via a compromised key. Core products remain unaffected as the bridge is closed.

Stake DAO is conducting a preliminary investigation into a security incident that occurred on May 27, during which an unauthorized party minted 5.44 trillion vsdCRV tokens on the Arbitrum network [1]. While the nominal value of the minted tokens was high, the attacker was limited to extracting approximately 43.78 ETH, worth about $91,000, due to the thin liquidity available in the token's markets [1, 3].

**Key takeaways**
* The exploit was traced to a compromised deployer private key used to reconfigure the LayerZero v2 OFT peer for the vsdCRV contract [1].
* Stake DAO confirmed that core products, including Boosted yields, Liquid Lockers, Votemarket, and Morpho lending, remain unaffected [2].
* The protocol has permanently closed the vsdCRV bridge to prevent further cross-chain spread [1].
* The Arbitrum asdCRV Llamalend market is being sunset, and depositors have been advised to move funds to other markets [2].

## Anatomy of the Arbitrum Bridge Exploit
Security firms Blockaid and BlockSec identified that the attacker used the stolen deployer key to redirect trust from the legitimate Ethereum adapter to a malicious contract [1]. By sending a forged cross-chain message, the attacker triggered the unconditional minting of the vsdCRV tokens [1]. Once the tokens were minted, the attacker attempted to swap them through Curve and KyberSwap, but the lack of market depth prevented further extraction, leaving the vast majority of the minted tokens with no liquidity to sell into [1, 3].

Stake DAO contributors acted to secure the vsdCRV backing on the Ethereum mainnet before the attacker could access it, ensuring that no backing funds were seizable [2]. While the protocol’s primary yield and governance services were not compromised, the incident forced the closure of the Arbitrum asdCRV Llamalend market [2]. This decision was made because the market relied on asdCRV as collateral, and the mass minting event created instability in the associated oracles [1].

## Why it matters
The Stake DAO incident highlights the ongoing vulnerability of DeFi protocols to private key compromises, which have accounted for significant losses across the industry in 2026 [1]. The exploit follows a pattern seen in other recent incidents, such as the Kelp DAO hack, where attackers utilized similar LayerZero peer-configuration vulnerabilities [1]. 

As of May 28, the investigation remains ongoing with the assistance of security partners and law enforcement [2]. Stake DAO has characterized its current findings as preliminary, and the community is awaiting a full post-mortem to determine the final scope of the incident and any potential recovery plans [1]. Users have been warned not to interact with vsdCRV while the protocol continues its review [3].

## Sources
1. Daotimes — [How a Stolen Key Left Stake DAO's Bridge Closed and Core...](https://daotimes.com/how-a-stolen-key-left-stake-daos-bridge-closed-and-core-products-intact/)
2. Crypto — [Stake DAO exploit update: Key products unaffected, bridge closed](https://crypto.news/stake-dao-exploit-update-key-products-unaffected-bridge-closed/)
3. Crypto Briefing — [Stake DAO faces ongoing exploit as attacker mints 5.4T vsdCRV on...](https://cryptobriefing.com/stake-dao-exploit-vsdcrv-arbitrum/)
4. Coinalertnews — [Stake DAO Exploit: 5.4 Trillion Fake vsdCRV Mint Exposes Hidden...](https://coinalertnews.com/news/2026/05/28/stake-dao-exploit-exposes-defi-risk)

---
Cite as: TrendWatcher, "Stake DAO Investigates Exploit After Unauthorized Token Mint", https://www.trendwatcher.in/article/4e5d9e73-80ec-44b3-88d4-99d4600ca81c
