• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
CoinLaw LogoCoinLaw

Bringing Crypto & Finance Closer to You

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
CoinLaw Logo
  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Home » Cryptocurrency

Stake DAO Hit by 5.4 Trillion vsdCRV Mint Exploit

Published on: May 27, 2026
Kelvin Scott
Written By
Kelvin Scott
Kelvin Scott
Finance News Analyst • 572 Articles
Kelvin Scott, with over 8 years of experience, covers the latest trends in digital assets, financial markets, and regulatory developments. W... See full bio
LATEST POSTS:
Laser Digital Wins Japan’s First Crypto Approval in 4 Years
Bitcoin Surges 8% Past $75,000 on Trump Crypto Push
X May Pay Creators in USDC as Revenue Sharing Ends
Barry Elad
Reviewed By
Barry Elad
Barry Elad
Founder & Senior Journalist • 588 Articles
Barry Elad is a finance and tech journalist who loves breaking down complex ideas into simple, practical insights. Whether he's exploring fi... See full bio
LATEST POSTS:
Hyperliquid Statistics 2026: Perp DEX, TVL, and HYPE Token Data
Crypto Ownership by Generation Statistics 2026: Gen Z vs Millennials
How Many Cryptocurrencies Are There Statistics 2026: Crypto Boom
Stake Dao Exploited With Infinite Minting Exploit
As Featured In
Bloomberg LogoForbes LogoFortune LogoCoinDesk LogoCoinMarketCap Logo
Share on LinkedIn ChatGPT Perplexity Share on X Share on Facebook

Stake DAO is facing a major security incident after an attacker minted more than 5.4 trillion vsdCRV tokens on Arbitrum and began swapping the assets for ETH.

Key Takeaways

  • Stake DAO suffered an ongoing exploit tied to a suspected compromised deployer private key on Arbitrum.
  • The attacker minted over 5.4 trillion vsdCRV tokens and started dumping them for ETH through liquidity pools.
  • Security researchers believe the exploit was caused by privileged access abuse, not a flaw in LayerZero or smart contracts.
  • Stake DAO has warned users to avoid interacting with vsdCRV until further notice.

What Happened?

Stake DAO, a decentralized finance platform focused on automated yield strategies and governance token products, has become the latest DeFi protocol targeted in a major exploit. Blockchain security firms including Blockaid, PeckShield, BlockSec, and ChainCatcher reported that an attacker minted approximately 5.4 trillion vsdCRV tokens on Arbitrum before rapidly swapping the tokens for ETH.

The exploit appears to still be active, with the attacker continuing to move funds across chains while draining liquidity tied to the affected token.

Stake DAO is under an ongoing exploit. An attacker compromised a deployer key on Arbitrum to mint ~5.4 trillion vsdCRV via a forged message, then swapped a portion for 43.78 ETH (~$91k) and bridged it to Ethereum.

The protocol has acknowledged the issue and warned users not to…

— unfolded. (@cryptounfolded) May 27, 2026

Attacker Exploits Deployer Access

According to multiple security researchers, the incident was likely caused by a compromised deployer private key connected to Stake DAO’s Arbitrum deployment.

BlockSec explained that the attacker allegedly gained control of the deployer credentials and changed a critical cross chain configuration tied to vsdCRV. This allowed the attacker to create a malicious LayerZero message that triggered unlimited token minting on Arbitrum.

“The attacker appears to have obtained the deployer’s private key and set an arbitrary peer for vsdCRV,” BlockSec stated.

Using that access, the attacker minted nearly 5.44 trillion vsdCRV tokens directly to their wallet before immediately selling the assets into available liquidity pools.

PeckShield reported that at least part of the stolen value had already been converted into approximately 43.78 ETH worth around $91,000 at the time of reporting and bridged to Ethereum.

What Is vsdCRV?

vsdCRV is a governance and yield related token tied to the Curve Finance ecosystem through Stake DAO’s liquid locker strategy products.

The token acts as a wrapped representation connected to Stake DAO’s sdCRV infrastructure, which is designed to maximize governance voting power and yield opportunities inside the ongoing competition for Curve Finance influence, commonly known as the “Curve Wars.”

Because vsdCRV is deeply connected to liquidity and governance systems, the sudden appearance of trillions of newly minted tokens created immediate panic across connected pools and trading markets.

Newsletter Img
Don't chase the news. Let us curate it.

You get one weekly briefing with only the stories that matter. If the market is quiet, we skip it.

✅ Join readers from Visa, Mastercard, Vanguard, and the FDIC.

No Smart Contract Bug Found So Far

Security experts emphasized that the exploit does not currently appear to involve a direct smart contract vulnerability or a failure within LayerZero infrastructure itself.

Instead, analysts pointed to operational security weaknesses involving privileged wallet access.

Sodot co-founder and Chief Product Officer Shalev Keren said the exploit closely resembles several recent incidents involving compromised deployer keys across the DeFi sector.

Keren explained:

“

The Stake DAO deployer key on Arbitrum was used to repoint the vsdCRV cross chain bridge configuration to an attacker controlled contract on Ethereum.

Shalev KerenCo-founder and Chief Product Officer – Sodot

He added that there was “no flaw in LayerZero” and described the incident as a dangerous example of centralized control over sensitive protocol functions.

Researchers also noted that stronger protections such as multisig wallets, hardware security systems, and transaction delays are commonly used to reduce these risks.

Stake DAO Issues Warning to Users

Stake DAO acknowledged the incident publicly on platform X and urged users not to interact with vsdCRV while investigations continue.

We are aware of the ongoing situation.
Please do not interact with vsdCRV. https://t.co/3wZhMo52r6

— Stake DAO (@StakeDAOHQ) May 27, 2026

At the time of writing, Stake DAO has not released a full postmortem or confirmed the total financial impact of the exploit.

Growing Pressure on DeFi Security

The Stake DAO incident adds to a growing wave of attacks targeting decentralized finance protocols in recent months. Industry researchers estimate that DeFi projects have suffered hundreds of millions of dollars in losses since April alone.

The latest exploit has once again raised concerns about the security risks tied to privileged access and centralized operational control inside supposedly decentralized systems.

CoinLaw’s Takeaway

In my experience, exploits involving compromised private keys are becoming one of the biggest threats facing DeFi today. This attack was not caused by a complicated smart contract bug. It appears to have come down to a single sensitive key holding enormous power over critical protocol functions.

I found the most worrying part to be how quickly the attacker was able to change configurations, mint trillions of tokens, and drain liquidity before anyone could stop it. Events like this show that even audited DeFi platforms can still carry massive operational risks behind the scenes.

Definition of Blockchain. Link to full glossary entry follows the description.Blockchain

A distributed digital ledger that records transactions across a network, with each block cryptographically linked to the previous one for security.

Read more

Definition of Smart Contract. Link to full glossary entry follows the description.Smart Contract

A smart contract is a self-executing program stored on a blockchain that automatically enforces agreement terms when predefined conditions are met, without intermediaries.

Read more

Definition of DeFi. Link to full glossary entry follows the description.DeFi

Decentralized finance leverages blockchain protocols and smart contracts to enable lending, trading, and borrowing without banks or traditional intermediaries.

Read more

Definition of Cross-Chain. Link to full glossary entry follows the description.Cross-Chain

Cross-chain is the ability to move data or assets between separate blockchains via bridges, messaging protocols, or interoperability networks.

Read more

This article has been reviewed and fact-checked by Barry Elad. CoinLaw follows strict Publishing Principles and a documented Fact-Check Policy to ensure accuracy, transparency, and editorial independence across all content.

Add CoinLaw as a Preferred Source on Google for instant updates! Follow on Google News
Share ChatGPT Perplexity

References

  • Arbiscan vsdCRV Transaction History
Kelvin Scott

Kelvin Scott

Finance News Analyst


Kelvin Scott, with over 8 years of experience, covers the latest trends in digital assets, financial markets, and regulatory developments. With a strong focus on accuracy and clarity, he delivers timely updates to help readers navigate the fast-changing world of crypto and finance. An avid football fan, he never misses a chance to watch a good match, whether it’s Premier League drama or a local game.

Related Posts

Secret Network Suffers 4 67m Loss In Bridge Exploit
Cryptocurrency

Secret Network Suffers $4.67M Loss in Bridge Exploit

Credix Defi Hacked
Cryptocurrency

$4.5M CrediX Hack Underscores DeFi’s Multisig Weakness

Lien Finance Hacked For 542 000 In Usdc Bond Exploit
Cryptocurrency

Lien Finance Hacked for $542,000 in USDC Bond Exploit

Disclaimer: The content published on CoinLaw is intended solely for informational and educational purposes. It does not constitute financial, legal, or investment advice, nor does it reflect the views or recommendations of CoinLaw regarding the buying, selling, or holding of any assets. All investments carry risk, and you should conduct your own research or consult with a qualified advisor before making any financial decisions. You use the information on this website entirely at your own risk.

Reader Interactions

Leave a Comment Cancel reply

Primary Sidebar

Connect With Us

facebook x linkedin google-news telegram pinterest whatsapp email
google-preferred-source-badge Add as a preferred source on Google

You Should Also Read

Sui DeFi Hit: Volo Protocol Loses $3.5M in Vault Exploit
TrustedVolumes Loses $5.87M in DeFi Attack Linked to 1inch
Tessera DAO Hit by Exploit as TSR Drops 99%

Table of Contents

  • Key Takeaways
  • What Happened?
  • Attacker Exploits Deployer Access
  • What Is vsdCRV?
  • No Smart Contract Bug Found So Far
  • Stake DAO Issues Warning to Users
  • Growing Pressure on DeFi Security
  • CoinLaw’s Takeaway
Connect on Telegram

Footer

CoinLaw Logo

Bringing Finance Closer to You.

Connect With Us

Follow Us on Google News

Editorial & Trust

  • About
  • Publishing Principles
  • Fact-Check Policy
  • Corrections Policy
  • Ethics Policy
  • Disclaimer
  • Cookie Policy

Worth Checking

  • Millennial vs. Gen Z Banking
  • Ethereum Gas Fees Statistics
  • Binance vs. Coinbase Statistics
  • Zelle vs. Venmo Statistics
  • Traditional Banks vs. Neobanks
  • Crypto Exchange Hack Statistics
  • Crypto Regulation Tracker
  • ETF Flow Tracker
  • Exchange Listings Tracker
  • Crypto Treasuries Tracker
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10 a.m. – 6 p.m. | Every day

Copyright © 2024–2026 CoinLaw. All Rights Reserved. Powered by the HODL Force ❤️

  • Privacy Policy
  • Terms
  • Accessibility Statement
Manage your privacy

To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.

Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.

Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Statistics

Marketing

Features
Always active

Always active
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
Manage options
  • {title}
  • {title}
  • {title}
Manage your privacy
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Statistics

Marketing

Features
Always active

Always active
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
Manage options
  • {title}
  • {title}
  • {title}
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • glossary icon
    Glossary
  • Stats
    Stats Research Process
  • Brand Guide Icon
    Brand Assets
Categories
  • Cryptocurrency
  • Payments
  • Banking
  • Finance
  • Insurance
Cryptocurrency
Hyperliquid Statistics
Hyperliquid Statistics 2026: Perp DEX, TVL, and HYPE Token Data
Crypto Ownership By Generation Statistics
Crypto Ownership by Generation Statistics 2026: Gen Z vs Millennials
How Many Cryptocurrencies Are There Statistics
How Many Cryptocurrencies Are There Statistics 2026: Crypto Boom
How Many Bitcoins Are There
How Many Bitcoins Are There 2026: Growth and Circulating Supply
Bitcoin All-Time High Statistics
Bitcoin All-Time High Statistics 2026: Every Cycle Peak Across Four Halvings
Crypto Market Capitalization Statistics
Crypto Market Capitalization Statistics 2026: Totals, Dominance, and Trends
Payments
Remittances By Country Statistics
Remittances by Country Statistics 2026: Inflows and Cost
Cash App vs Zelle Statistics
Cash App vs Zelle Statistics 2026: Speed, Limits and User Data
Venmo vs. PayPal Statistics
Venmo vs PayPal Statistics 2026: Users, Fees and Volume
Toast Statistics
Toast Statistics 2026: ARR, GPV & Revenue Data
Rapyd Statistics
Rapyd Statistics 2026: TPV, Valuation & Licences
Marqeta Statistics
Marqeta Statistics 2026: TPV, Revenue and Customer Mix
Banking
Global Systemically Important Banks Statistics
Global Systemically Important Banks Statistics 2026: Bucket Allocation and Capital Surcharges
Bank Failures Statistics
Bank Failures Statistics 2026: FDIC Data, DIF Costs, and Recent Trends
The 15 Largest Banks in the US
The 15 Largest Banks in the US in 2026: By Assets, Deposits, and Branches
N26 Statistics
N26 Statistics 2026: Customers, Deposits, Revenue and the BaFin Growth Cap
Revolut vs Monzo Statistics
Revolut vs Monzo Statistics 2026: Customers & Profit
Islamic Banking Statistics
Islamic Banking Statistics 2026: Assets, Growth, and Top Markets
Finance
Federal Tax Revenue By State Statistics
Federal Tax Revenue by State Statistics 2026: IRS Gross Collections, Top 10 States, Donor vs Recipient
Tariff Revenue Statistics
Tariff Revenue Statistics 2026: Customs Duties and IEEPA Refunds
Emergency Fund Statistics
Emergency Fund Statistics 2026: How Much Americans Have Saved (and How Much They Should)
Financial Advisor Statistics
Financial Advisor Statistics 2026: Headcount, AUM, and Demographics
Wealth Inequality Statistics
Wealth Inequality Statistics 2026: Hidden Wealth Divide
Blockchain In Supply Chain Finance Statistics
Blockchain in Supply Chain Finance Statistics 2026: Trade Breakthrough
Insurance
Lemonade Insurance Statistics
Lemonade Insurance Statistics 2026: Customers, In-Force Premium, Loss Ratio, Pet & Auto Segments
Chubb Statistics
Chubb Statistics 2026: Powerful Data Insights
Virtual Reality In Insurance Statistics
Virtual Reality In Insurance Statistics 2026: Innovations, Risks, and Opportunities
US Life Insurance Industry Statistics
US Life Insurance Industry Statistics 2026: Growth Facts
US Auto Insurance Industry Statistics
US Auto Insurance Industry Statistics 2026: What You Must Know Now
UK Insurance Industry Statistics
UK Insurance Industry Statistics 2026: Growth Data
Categories
  • Cryptocurrency
  • Investments
  • Fintech
  • Compliance
  • Finance
Cryptocurrency
Everything Protocol Solved DeFi s Oracle Risk Paper Says
Everything Protocol Solved DeFi’s Oracle Risk, Paper Says
Laser Digital Wins Japan s First Crypto Approval in 4 Years
Laser Digital Wins Japan’s First Crypto Approval in 4 Years
Bitcoin Surges Past 75 000 as Trump Presses Congress on Crypto Bill
Bitcoin Surges 8% Past $75,000 on Trump Crypto Push
X Eyes Usdc Stablecoin Payouts In Creator Shake Up
X May Pay Creators in USDC as Revenue Sharing Ends
Coinbase 50x Perps Base App
Coinbase Unleashes 50x Perpetual Futures on Base App
Trading Technologies To Link Institutions To Og Com In Q4
Trading Technologies Adds OG.com Access in Major Q4 Push
Investments
Cantor Opens Kalshi Block Trading To 3 000 Institutions
Cantor Opens Kalshi Block Trading to 3,000 Institutions
Nvidia Eyes 500 Billion Ai War Chest With Wall Street
Nvidia Eyes $500 Billion AI War Chest With Wall Street
Bitdeer Q2 2026 Results Stock Drop
Bitdeer Stock Drops 16.82% Despite Q2 Bitcoin Output Surge
Coinhako Sbi Holdings Acquisition
SBI Holdings Acquires Coinhako Crypto Exchange
Keyrock Acquires Blockfills Trading And Brokerage Assets
Keyrock Completes the Acquisition of BlockFills’ Trading Assets
Crypto Com Raises 400 Million From Citadel Securities
Crypto.com Raises $400 Million From Citadel Securities
Fintech
World ID Comes to peaqOS Robots Without Sharing Identity
World ID Comes to peaqOS Robots Without Sharing Identity
K Lab Names Nasdaq Veteran Jay Heller U S CEO
K Lab Names Nasdaq Veteran Jay Heller U.S. CEO
Citi Bitcoin Custody
Citi Launches Custody+ With Real-Time Asset Servicing, Bitcoin Ahead
Kalshi And Apex Fintech Open Predictions Market
Apex and Kalshi Open Prediction Markets to More Firms
OKX App Returns to South Korea's Google Play Store
OKX Wins Back Korea’s Play Store After 4-Day Block
Uphold Cuts 17 Of Global Workforce
Uphold Cuts 17% of Global Workforce Amid Crypto Winter
Compliance
Bitpanda Mica Austria Fine
Bitpanda Fined €70,000 in First Austrian MiCA Penalty
Wintermute Wins Us Broker Dealer Status
Wintermute Enters US Markets With Broker-Dealer Status
Taiwan Targets Crypto Transfers Travel Rules
Taiwan’s Crypto Crackdown Raises Compliance Stakes
Bybit Lead Global Compliance Robert Loo
Bybit Poaches VARA’s Ex-Counsel to Lead Global Compliance
Robinhood Wins Uk Fca License
Robinhood Lands Key FCA Registration Before UK Crypto Rules
Circle Clears Nydfs Trust Charter
Circle Clears NYDFS Trust Charter After Decade Under BitLicense
Finance
Polymarket Seeks 20b Usd Valuation
Polymarket Targets $20B Valuation in Bold $1B Funding Push
Lsg To Operate 24 7 For Etps
London Stock Exchange Plans Overnight Trading by 2027
Avax One Regains Nasdaq Listing Compliance
AVAX One Regains Nasdaq Listing Compliance
Kraken Lets Traders Post Tokenized Stocks As Collateral
Kraken Lets Traders Post Tokenized Stocks as Collateral
Kalshi Targets Ipo After Massive Valuation
Kalshi Targets IPO After Massive Growth and $22B Valuation
Coinbase To Launch Tokenized Us Stocks
Coinbase Sparks New Race With 1:1 Backed Tokenized Stocks
Newsletter Img

Too much noise in crypto?

We respect your time. You get one high-impact briefing a week. If the market is quiet, so are we.

✅ Join readers from Visa, Mastercard, Vanguard, and the FDIC.
Newsletter Img

The Weekly Briefing

We track the market 24/7. You get a 5-minute summary. If it’s quiet, we skip it.

✅ Read by pros at Visa, Mastercard, Vanguard, and the FDIC.