
Blockchain security firm PeckShield has confirmed that an attacker successfully minted 5.44 trillion vsdCRV tokens on Arbitrum following a suspected compromise of a StakeDAO-linked deployer key. According to PeckShield, the attacker used the compromised deployer key to modify the setPeer() configuration on the LayerZero v2 OFT contract, allegedly redirecting trust away from the legitimate Ethereum-side adapter toward an attacker-controlled contract. The exploit stemmed from a compromised deployer wallet rather than a flaw in the token contract itself, as reported by PeckShield.
The attacker used the compromised deployer key to modify the setPeer() configuration on the LayerZero v2 OFT contract, allegedly redirecting trust away from the legitimate Ethereum-side adapter toward an attacker-controlled contract. As reported by PeckShield, about 25 seconds later, that contract sent a LayerZero message back to Arbitrum, causing the legitimate Arbitrum token to mint more than 5.4 trillion vsdCRV to the attacker. Independent on-chain investigators later reconstructed the exploit timeline, tracing the attacker's preparation wallets, bridge activity, and token dumping transactions across Arbitrum and Ethereum.
Despite minting 5.44 trillion vsdCRV tokens, the attacker's realized proceeds were significantly limited by thin liquidity in the vsdCRV market. According to on-chain analyst EmberCN, the attacker swapped approximately 16.83 million vsdCRV for 43.7 Ether (ETH), worth about $91,000 at the time of the exploit. The remaining 5.44 trillion vsdCRV tokens had little meaningful liquidity to exit, with EmberCN estimating the total value at about $763 billion on paper, though this figure does not represent the attacker's realized profit or the protocol's confirmed loss. The funds were later bridged from Arbitrum back to Ethereum, where the ETH reportedly remained untouched at the time of writing.
The exploit has created significant ripple effects across multiple DeFi protocols and markets. StakeDAO, a DeFi protocol with $131 million in total value locked that allows users to earn boosted yields on Curve Finance liquidity pools through locked CRV positions, warned users to stop interacting with vsdCRV immediately following the incident. The protocol's SDT governance token fell approximately 6.6% in the 24 hours surrounding the incident, with trading volume in SDT spiking more than 400%, according to CoinMarketCap and CoinGecko data. Curve Finance warned users with deposits or loans in the asdCRV LlamaLend market on Arbitrum to exit immediately, citing concerns that the vsdCRV exploit could destabilize its price oracle and trigger unexpected liquidations. Beefy Finance, a multichain yield optimizer, separately disclosed that its Arbitrum Convex CRV/csdCRV/asdCRV vault was hit and paused the vault while coordinating with StakeDAO, Curve, and Convex on potential recovery plans.