
Stake DAO is facing a significant exploit after an attacker successfully minted more than 5.4 trillion vsdCRV tokens on Arbitrum and began swapping them for ETH. According to blockchain security firm Blockaid, the attacker used a compromised Stake DAO deployer private key to reconfigure the LayerZero v2 OFT peer for the vsdCRV token contract. This change allegedly redirected trust from the legitimate Ethereum-side adapter to a malicious contract controlled by the attacker, who then sent a forged cross-chain message that triggered the massive minting operation. The breach bypassed every smart-contract control in place, with the attacker dumping the tokens for ether through MetaMask's public router, demonstrating how a single compromised private key with privileged rights can drive hundreds of millions in DeFi losses.
As reported by PeckShield, part of the minted funds had already been swapped for 43.78 ETH, worth approximately ₹91,000, and bridged to Ethereum. The incident represents one of the largest DeFi exploits in recent months, with the total financial impact still being assessed as researchers continue tracking the attacker's activity. Stake DAO has confirmed it is aware of the situation and has warned users not to interact with vsdCRV tokens while the exploit remains active. The breach follows a familiar pattern of key compromises, with similar peer-configuration abuse previously seen in April's Wasabi Protocol drain that pulled around $4.5 million from vaults on four chains.
According to BlockSec, the attacker appeared to obtain the deployer's private key and set an arbitrary peer for vsdCRV, with the forged message causing unconditional minting to the attacker's address. The exploit demonstrates how privileged access remains a major risk in DeFi, even when smart contract code works as designed. As noted by security researchers, a compromised deployer key can give attackers the ability to change trusted settings and trigger losses, highlighting the critical importance of key management in decentralized finance protocols. Notably, a recent LayerZero exploit on KelpDAO occurred through similar peer-configuration abuse, with each protocol having passed audits before the compromises.
The Stake DAO incident follows a series of recent DeFi security breaches, with OpenZeppelin co-founder Manuel Aráoz now considering "all of DeFi" unsafe and advising friends and family to exit DeFi positions. According to previous reports, DeFi protocols lost approximately ₹5,300 crore to hacks in April, with Aráoz arguing that coding agents are becoming strong tools for finding vulnerabilities while defenders still need to fix every weakness before attackers find one. As noted by Sodot co-founder Shalev Keren, "The question DeFi has to answer in 2026 is no longer whether protocols get audited, because almost all of them do. It is whether the small set of operational keys behind those audited contracts... are still allowed to live as a single object on a single laptop." The incident also highlights cross-chain token risks, with security reports tracking repeated attacks involving bridges, peer settings, and message validation across multiple chains in 2026.