
Stake DAO, a DeFi platform focused on automated yield strategies, is experiencing an ongoing exploit that has resulted in the minting of 5.4 trillion vsdCRV tokens on Arbitrum. According to reports from The Block, Blockaid, and ChainCatcher, the attacker is actively swapping these tokens for ETH, with some already converted to 43.78 ETH worth $91,000 and bridged to Ethereum. The exploit began around 09:17 UTC on Tuesday when the attacker compromised the Stake DAO deployer private key (0x000755Fbe4A24d7478bfcFC1E561AfCE82d1ff62) and used it to reconfigure the LayerZero v2 OFT peer on the vsdCRV token contract. The attacker then sent a forged cross-chain message that triggered unconditional minting of approximately 5.44 trillion vsdCRV to their address, with the mint transaction confirmed just 25 seconds later at 09:17:33 UTC. As per BeInCrypto, the breach bypassed every smart-contract control in place, with no smart-contract flaw found - the failure occurred above the code, in the keys that set bridge peers or upgrade implementations.
Despite the exploit generating a nominal value estimated at $763 billion, the attacker struggled to convert the tokens into actual cash because of severely limited liquidity in vsdCRV markets. On-chain analyst EmberCN reported that only 16.83 million tokens were exchanged for about 43.7 ETH, or roughly $91,000, before DEX liquidity dried up. This represents a significant disparity between the theoretical value of the minted tokens and their actual market value, highlighting the critical importance of liquidity in DeFi protocols. The attacker's inability to realize meaningful profits demonstrates how poor liquidity can severely limit the effectiveness of even major exploits in the cryptocurrency market. Between 09:17 and 09:43 UTC, the attacker executed roughly 28 swap transactions across Curve, KyberSwap, MetaMask Router, and Enso, converting portions of the minted vsdCRV into the extracted ETH. The attacker then bridged the ETH via Stargate to Ethereum mainnet at 10:04 UTC, with the funds landing in the attacker's wallet (0xeF3C054d8F7eD0a7D61c8da56ff55F090577aa25) and remaining there.
According to The Block, Blockaid, and ChainCatcher, Stake DAO has acknowledged the situation and issued urgent guidance to users. The platform posted a warning on X at 10:45 UTC: "We are aware of the ongoing situation. Please do not interact with vsdCRV." The attack targets vsdCRV, or vote-boosted sdCRV, which is a yield-related derivative token tied to the Curve Finance ecosystem and used within Stake DAO. This token operates within Stake DAO's Boosted Vote Strategy, wrapping sdCRV to enhance governance voting capabilities by utilizing delegated veSDT. The fundamental issue arose when the controller of the deployer key used it to mint a staggering quantity of vsdCRV tokens, effectively creating an inflated supply that overwhelmed existing liquidity. Curve Finance issued its own advisory at 13:55 UTC, warning: "If you have deposits or loans in asdCRV LlamaLend market on Arbitrum, please exit ASAP out of precaution." The concern centers on oracle stability, as vsdCRV depegged instantly, potentially causing instability in oracle feeds used by related Curve markets that could trigger unexpected liquidations.
This exploit continues what has been described as one of the worst periods for DeFi exploits, with dozens of protocols hacked for more than $600 million since April. The most significant recent exploit was the $292 million hack of Kelp DAO. Sodot co-founder Shalev Keren noted that the Stake DAO exploit is structurally similar to the Wasabi incident last month and several other deployer-key compromises this year. The attacker's liquidation of inflated supplies of sdCRV or vsdCRV is causing severe imbalances in liquidity pools, leading to impermanent loss for providers and potential sell-offs. Investors holding sdCRV must be vigilant and reconsider the underlying security of their assets, especially regarding potential mismatches in CRV backing due to this recent exploit. Stake DAO plays a vital role in the Curve ecosystem, particularly within CRV governance power, with competitors like Convex Finance and Yearn Finance closely observing this situation. This marks the fourth reported private key compromise in DeFi within roughly two weeks, highlighting a persistent weakness: single-key admin access to critical functions without multisig or timelock protections. The incident reinforces the need for DeFi protocols to adopt multi-signature governance, hardware security modules, and transparent key management policies to protect against similar exploits.