• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
CoinLaw LogoCoinLaw

Bringing Crypto & Finance Closer to You

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
CoinLaw Logo
  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Home » Cryptocurrency

Stake DAO Hit by 5.4 Trillion vsdCRV Mint Exploit

Published on: May 27, 2026
Kelvin Scott
Written By
Kelvin Scott
Kelvin Scott
Finance News Analyst • 561 Articles
Kelvin Scott, with over 8 years of experience, covers the latest trends in digital assets, financial markets, and regulatory developments. W... See full bio
LATEST POSTS:
Binance Lists USDⓈ-Margined TMF, TBT, BITO Perp Contracts
Triple-A Absorbs Undisclosed Treasury Wallet Loss
Lien Finance Hacked for $542,000 in USDC Bond Exploit
Barry Elad
Reviewed By
Barry Elad
Barry Elad
Founder & Senior Journalist • 588 Articles
Barry Elad is a finance and tech journalist who loves breaking down complex ideas into simple, practical insights. Whether he's exploring fi... See full bio
LATEST POSTS:
Crypto Ownership by Generation Statistics 2026: Gen Z vs Millennials
How Many Cryptocurrencies Are There Statistics 2026: Crypto Boom
How Many Bitcoins Are There 2026: Growth and Circulating Supply
Stake Dao Exploited With Infinite Minting Exploit
As Featured In
Bloomberg LogoForbes LogoFortune LogoCoinDesk LogoCoinMarketCap Logo
Share on LinkedIn ChatGPT Perplexity Share on X Share on Facebook

Stake DAO is facing a major security incident after an attacker minted more than 5.4 trillion vsdCRV tokens on Arbitrum and began swapping the assets for ETH.

Key Takeaways

  • Stake DAO suffered an ongoing exploit tied to a suspected compromised deployer private key on Arbitrum.
  • The attacker minted over 5.4 trillion vsdCRV tokens and started dumping them for ETH through liquidity pools.
  • Security researchers believe the exploit was caused by privileged access abuse, not a flaw in LayerZero or smart contracts.
  • Stake DAO has warned users to avoid interacting with vsdCRV until further notice.

What Happened?

Stake DAO, a decentralized finance platform focused on automated yield strategies and governance token products, has become the latest DeFi protocol targeted in a major exploit. Blockchain security firms including Blockaid, PeckShield, BlockSec, and ChainCatcher reported that an attacker minted approximately 5.4 trillion vsdCRV tokens on Arbitrum before rapidly swapping the tokens for ETH.

The exploit appears to still be active, with the attacker continuing to move funds across chains while draining liquidity tied to the affected token.

Stake DAO is under an ongoing exploit. An attacker compromised a deployer key on Arbitrum to mint ~5.4 trillion vsdCRV via a forged message, then swapped a portion for 43.78 ETH (~$91k) and bridged it to Ethereum.

The protocol has acknowledged the issue and warned users not to…

— unfolded. (@cryptounfolded) May 27, 2026

Attacker Exploits Deployer Access

According to multiple security researchers, the incident was likely caused by a compromised deployer private key connected to Stake DAO’s Arbitrum deployment.

BlockSec explained that the attacker allegedly gained control of the deployer credentials and changed a critical cross chain configuration tied to vsdCRV. This allowed the attacker to create a malicious LayerZero message that triggered unlimited token minting on Arbitrum.

“The attacker appears to have obtained the deployer’s private key and set an arbitrary peer for vsdCRV,” BlockSec stated.

Using that access, the attacker minted nearly 5.44 trillion vsdCRV tokens directly to their wallet before immediately selling the assets into available liquidity pools.

PeckShield reported that at least part of the stolen value had already been converted into approximately 43.78 ETH worth around $91,000 at the time of reporting and bridged to Ethereum.

What Is vsdCRV?

vsdCRV is a governance and yield related token tied to the Curve Finance ecosystem through Stake DAO’s liquid locker strategy products.

The token acts as a wrapped representation connected to Stake DAO’s sdCRV infrastructure, which is designed to maximize governance voting power and yield opportunities inside the ongoing competition for Curve Finance influence, commonly known as the “Curve Wars.”

Because vsdCRV is deeply connected to liquidity and governance systems, the sudden appearance of trillions of newly minted tokens created immediate panic across connected pools and trading markets.

Newsletter Img
Don't chase the news. Let us curate it.

You get one weekly briefing with only the stories that matter. If the market is quiet, we skip it.

✅ Join readers from Visa, Mastercard, Vanguard, and the FDIC.

No Smart Contract Bug Found So Far

Security experts emphasized that the exploit does not currently appear to involve a direct smart contract vulnerability or a failure within LayerZero infrastructure itself.

Instead, analysts pointed to operational security weaknesses involving privileged wallet access.

Sodot co-founder and Chief Product Officer Shalev Keren said the exploit closely resembles several recent incidents involving compromised deployer keys across the DeFi sector.

Keren explained:

“

The Stake DAO deployer key on Arbitrum was used to repoint the vsdCRV cross chain bridge configuration to an attacker controlled contract on Ethereum.

Shalev KerenCo-founder and Chief Product Officer – Sodot

He added that there was “no flaw in LayerZero” and described the incident as a dangerous example of centralized control over sensitive protocol functions.

Researchers also noted that stronger protections such as multisig wallets, hardware security systems, and transaction delays are commonly used to reduce these risks.

Stake DAO Issues Warning to Users

Stake DAO acknowledged the incident publicly on platform X and urged users not to interact with vsdCRV while investigations continue.

We are aware of the ongoing situation.
Please do not interact with vsdCRV. https://t.co/3wZhMo52r6

— Stake DAO (@StakeDAOHQ) May 27, 2026

At the time of writing, Stake DAO has not released a full postmortem or confirmed the total financial impact of the exploit.

Growing Pressure on DeFi Security

The Stake DAO incident adds to a growing wave of attacks targeting decentralized finance protocols in recent months. Industry researchers estimate that DeFi projects have suffered hundreds of millions of dollars in losses since April alone.

The latest exploit has once again raised concerns about the security risks tied to privileged access and centralized operational control inside supposedly decentralized systems.

CoinLaw’s Takeaway

In my experience, exploits involving compromised private keys are becoming one of the biggest threats facing DeFi today. This attack was not caused by a complicated smart contract bug. It appears to have come down to a single sensitive key holding enormous power over critical protocol functions.

I found the most worrying part to be how quickly the attacker was able to change configurations, mint trillions of tokens, and drain liquidity before anyone could stop it. Events like this show that even audited DeFi platforms can still carry massive operational risks behind the scenes.

Definition of Blockchain. Link to full glossary entry follows the description.Blockchain

A distributed digital ledger that records transactions across a network, with each block cryptographically linked to the previous one for security.

Read more

Definition of Smart Contract. Link to full glossary entry follows the description.Smart Contract

A smart contract is a self-executing program stored on a blockchain that automatically enforces agreement terms when predefined conditions are met, without intermediaries.

Read more

Definition of DeFi. Link to full glossary entry follows the description.DeFi

Decentralized finance leverages blockchain protocols and smart contracts to enable lending, trading, and borrowing without banks or traditional intermediaries.

Read more

Definition of Cross-Chain. Link to full glossary entry follows the description.Cross-Chain

Cross-chain is the ability to move data or assets between separate blockchains via bridges, messaging protocols, or interoperability networks.

Read more

This article has been reviewed and fact-checked by Barry Elad. CoinLaw follows strict Publishing Principles and a documented Fact-Check Policy to ensure accuracy, transparency, and editorial independence across all content.

Add CoinLaw as a Preferred Source on Google for instant updates! Follow on Google News
Share ChatGPT Perplexity

References

  • Arbiscan vsdCRV Transaction History
Kelvin Scott

Kelvin Scott

Finance News Analyst


Kelvin Scott, with over 8 years of experience, covers the latest trends in digital assets, financial markets, and regulatory developments. With a strong focus on accuracy and clarity, he delivers timely updates to help readers navigate the fast-changing world of crypto and finance. An avid football fan, he never misses a chance to watch a good match, whether it’s Premier League drama or a local game.

Related Posts

Secret Network Suffers 4 67m Loss In Bridge Exploit
Cryptocurrency

Secret Network Suffers $4.67M Loss in Bridge Exploit

Credix Defi Hacked
Cryptocurrency

$4.5M CrediX Hack Underscores DeFi’s Multisig Weakness

Defi Protocol Summer Fi Exploited
Cryptocurrency

Summer.fi Hit by $6 Million DAI Exploit

Disclaimer: The content published on CoinLaw is intended solely for informational and educational purposes. It does not constitute financial, legal, or investment advice, nor does it reflect the views or recommendations of CoinLaw regarding the buying, selling, or holding of any assets. All investments carry risk, and you should conduct your own research or consult with a qualified advisor before making any financial decisions. You use the information on this website entirely at your own risk.

Reader Interactions

Leave a Comment Cancel reply

Primary Sidebar

Connect With Us

facebook x linkedin google-news telegram pinterest whatsapp email
google-preferred-source-badge Add as a preferred source on Google

You Should Also Read

Sui DeFi Hit: Volo Protocol Loses $3.5M in Vault Exploit
TrustedVolumes Loses $5.87M in DeFi Attack Linked to 1inch
Tessera DAO Hit by Exploit as TSR Drops 99%

Table of Contents

  • Key Takeaways
  • What Happened?
  • Attacker Exploits Deployer Access
  • What Is vsdCRV?
  • No Smart Contract Bug Found So Far
  • Stake DAO Issues Warning to Users
  • Growing Pressure on DeFi Security
  • CoinLaw’s Takeaway
Connect on Telegram

Footer

CoinLaw Logo

Bringing Finance Closer to You.

Connect With Us

Follow Us on Google News

Editorial & Trust

  • About
  • Publishing Principles
  • Fact-Check Policy
  • Corrections Policy
  • Ethics Policy
  • Disclaimer
  • Cookie Policy

Worth Checking

  • Best Cloud Mining Platforms
  • Millennial vs. Gen Z Banking
  • Ethereum Gas Fees Statistics
  • Binance vs. Coinbase Statistics
  • Zelle vs. Venmo Statistics
  • Traditional Banks vs. Neobanks
  • Crypto Exchange Hack Statistics
  • Crypto Regulation Tracker
  • ETF Flow Tracker
  • Exchange Listings Tracker
  • Crypto Treasuries Tracker
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10 a.m. – 6 p.m. | Every day

Copyright © 2024–2026 CoinLaw. All Rights Reserved. Powered by the HODL Force ❤️

  • Privacy Policy
  • Terms
  • Accessibility Statement
Manage your privacy

To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.

Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.

Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Statistics

Marketing

Features
Always active

Always active
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
Manage options
  • {title}
  • {title}
  • {title}
Manage your privacy
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Statistics

Marketing

Features
Always active

Always active
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
Manage options
  • {title}
  • {title}
  • {title}
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • glossary icon
    Glossary
  • Stats
    Stats Research Process
  • Brand Guide Icon
    Brand Assets
Categories
  • Cryptocurrency
  • Payments
  • Banking
  • Finance
  • Insurance
Cryptocurrency
Crypto Ownership By Generation Statistics
Crypto Ownership by Generation Statistics 2026: Gen Z vs Millennials
How Many Cryptocurrencies Are There Statistics
How Many Cryptocurrencies Are There Statistics 2026: Crypto Boom
How Many Bitcoins Are There
How Many Bitcoins Are There 2026: Growth and Circulating Supply
Bitcoin All-Time High Statistics
Bitcoin All-Time High Statistics 2026: Every Cycle Peak Across Four Halvings
Crypto Market Capitalization Statistics
Crypto Market Capitalization Statistics 2026: Totals, Dominance, and Trends
How Many People Use Cryptocurrency Worldwide
How Many People Use Cryptocurrency Worldwide 2026: Global User Count by Year and Region
Payments
Remittances By Country Statistics
Remittances by Country Statistics 2026: Inflows and Cost
Cash App vs Zelle Statistics
Cash App vs Zelle Statistics 2026: Speed, Limits and User Data
Venmo vs. PayPal Statistics
Venmo vs PayPal Statistics 2026: Users, Fees and Volume
Toast Statistics
Toast Statistics 2026: ARR, GPV & Revenue Data
Rapyd Statistics
Rapyd Statistics 2026: TPV, Valuation & Licences
Marqeta Statistics
Marqeta Statistics 2026: TPV, Revenue and Customer Mix
Banking
Global Systemically Important Banks Statistics
Global Systemically Important Banks Statistics 2026: Bucket Allocation and Capital Surcharges
Bank Failures Statistics
Bank Failures Statistics 2026: FDIC Data, DIF Costs, and Recent Trends
The 15 Largest Banks in the US
The 15 Largest Banks in the US in 2026: By Assets, Deposits, and Branches
N26 Statistics
N26 Statistics 2026: Customers, Deposits, Revenue and the BaFin Growth Cap
Revolut vs Monzo Statistics
Revolut vs Monzo Statistics 2026: Customers & Profit
Islamic Banking Statistics
Islamic Banking Statistics 2026: Assets, Growth, and Top Markets
Finance
Federal Tax Revenue By State Statistics
Federal Tax Revenue by State Statistics 2026: IRS Gross Collections, Top 10 States, Donor vs Recipient
Tariff Revenue Statistics
Tariff Revenue Statistics 2026: Customs Duties and IEEPA Refunds
Emergency Fund Statistics
Emergency Fund Statistics 2026: How Much Americans Have Saved (and How Much They Should)
Financial Advisor Statistics
Financial Advisor Statistics 2026: Headcount, AUM, and Demographics
Wealth Inequality Statistics
Wealth Inequality Statistics 2026: Hidden Wealth Divide
Blockchain In Supply Chain Finance Statistics
Blockchain in Supply Chain Finance Statistics 2026: Trade Breakthrough
Insurance
Lemonade Insurance Statistics
Lemonade Insurance Statistics 2026: Customers, In-Force Premium, Loss Ratio, Pet & Auto Segments
Chubb Statistics
Chubb Statistics 2026: Powerful Data Insights
Virtual Reality In Insurance Statistics
Virtual Reality In Insurance Statistics 2026: Innovations, Risks, and Opportunities
US Life Insurance Industry Statistics
US Life Insurance Industry Statistics 2026: Growth Facts
US Auto Insurance Industry Statistics
US Auto Insurance Industry Statistics 2026: What You Must Know Now
UK Insurance Industry Statistics
UK Insurance Industry Statistics 2026: Growth Data
Categories
  • Cryptocurrency
  • Investments
  • Fintech
  • Compliance
  • Finance
Cryptocurrency
Core Scientific Liquidates Bitcoin
Core Scientific Liquidates Bitcoin as $14B AMD Deal Lands
Minnesota Prediction Markets Ban Blocked
Minnesota Prediction Markets Ban Blocked by Federal Judge
Emirates Crypto Com Pay For Aed Flights
Emirates Goes Live With Crypto.com Pay for AED Flights
Morgan Stanley Sol Eth Staking Etp
Morgan Stanley Launches Ethereum, Solana ETPs at 0.14% Fee
Securitize Clears Sec Adviser Registration
Securitize Clears SEC Adviser Registration, Shares Slide 46%
Ondo Finance Launches Ondo Network Execution Layer
Ondo Finance Launches Ondo Network To Replace Ondo Chain
Investments
Coinhako Sbi Holdings Acquisition
SBI Holdings Acquires Coinhako Crypto Exchange
Keyrock Acquires Blockfills Trading And Brokerage Assets
Keyrock Completes the Acquisition of BlockFills’ Trading Assets
Crypto Com Raises 400 Million From Citadel Securities
Crypto.com Raises $400 Million From Citadel Securities
Moonpay Acquires Glide Crypto Deposit Startup
MoonPay Acquires Glide in All-Equity Crypto Deposits Deal
Hyperliquid Perpetual Prices Cxmt Above Its Shanghai Ipo
Hyperliquid Perpetual Prices CXMT Above Its Shanghai IPO
Former Tether Cio Seeks To Sell 1 26 Stake
Former Tether CIO Seeks to Sell 1.26% Stake via PJT Partners
Fintech
OKX App Returns to South Korea's Google Play Store
OKX Wins Back Korea’s Play Store After 4-Day Block
Uphold Cuts 17 Of Global Workforce
Uphold Cuts 17% of Global Workforce Amid Crypto Winter
Samsung Wallet To Add Native Stablecoin Support
Samsung Wallet to Add Native Stablecoin Support
Coinbase Launches Usdc Payments For Ai Agents
Coinbase Launches USDC Payments Support for AI Agents
Keeta Layerzero Partner To Tokenize Bank Deposits
Keeta, LayerZero Partner to Tokenize Bank Deposits On-Chain
Gtn And Payward Expand Xstocks Beyond U S Equities
Payward and GTN to Expand xStocks in International markets
Compliance
Russia S State Duma Passes Crypto Law
Russia’s State Duma Passes First Comprehensive Crypto Law
Maharashtra Directs Draft Of India S First Land Tokenization Law
Maharashtra Directs Draft of India’s First Land Tokenization Law
Fss Opens Sanctions Process Against Dunamu Over Upbit Hack
FSS Opens Sanctions Process Against Dunamu Over Upbit Hack
Bitpay Secures Dutch Mica License
BitPay Secures Dutch MiCA License for EU Crypto Payments
Revolut Secures Vara Approval In Dubai
Revolut Secures VARA Approval to Launch Crypto in UAE
Aba Icba Urge Senate To Close Stablecoin Yield Loophole
ABA, ICBA Urge Senate to Close Stablecoin Yield Loophole
Finance
Lsg To Operate 24 7 For Etps
London Stock Exchange Plans Overnight Trading by 2027
Avax One Regains Nasdaq Listing Compliance
AVAX One Regains Nasdaq Listing Compliance
Kraken Lets Traders Post Tokenized Stocks As Collateral
Kraken Lets Traders Post Tokenized Stocks as Collateral
Kalshi Targets Ipo After Massive Valuation
Kalshi Targets IPO After Massive Growth and $22B Valuation
Coinbase To Launch Tokenized Us Stocks
Coinbase Sparks New Race With 1:1 Backed Tokenized Stocks
Bitmine Launches 300m Preferred Stock Offering
Bitmine Launches $300M Preferred Stock to Buy More ETH
Newsletter Img

Too much noise in crypto?

We respect your time. You get one high-impact briefing a week. If the market is quiet, so are we.

✅ Join readers from Visa, Mastercard, Vanguard, and the FDIC.
Newsletter Img

The Weekly Briefing

We track the market 24/7. You get a 5-minute summary. If it’s quiet, we skip it.

✅ Read by pros at Visa, Mastercard, Vanguard, and the FDIC.