StakeDAO Deployer Key Leak Enables Minting of 5.4 Trillion vsdCRV on Arbitrum
StakeDAO is a DeFi protocol offering yield strategies and governance-token liquidity locking. Each vsdCRV token is intended to be backed 1:1 by deposited CRV or sdCRV and circulate across chains through LayerZero OFT. The incident shows that minting safeguards can fail even without a contract vulnerability if a deployer’s private key retains the authority to change trusted peers.
At 09:17 UTC on May 27, 2026, the attacker changed the peer on Arbitrum and minted 5.446 trillion unbacked vsdCRV 25 seconds later. Blockaid issued an immediate alert. The attacker swapped the tokens for about 321,143 CRV and 7.5 ETH, ultimately cashing out 43.776 ETH, worth about $91,000. Within 47 minutes, StakeDAO transferred roughly 1.329 million sdCRV from its reserves to a governance multisig wallet.
All Coverage
3 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.