Summary
Stake DAO is a non-custodial DeFi protocol built around liquid staking, yield aggregation, and governance participation via veToken mechanics. The protocol has suffered three documented security incidents since 2023, the most severe of which — a May 2026 deployer private key compromise — enabled the minting of 5.4 trillion fraudulent vsdCRV tokens on Arbitrum, resulting in roughly $91,000 in realized losses despite a nominally catastrophic exposure. Repeated operational security failures across a two-year span, including a March 2026 oracle exploit draining $176,000 from its Votemarket product, indicate a pattern of infrastructure risk that audited smart contracts alone have not resolved.
Connected Entities
1 entitiesTimeline(9 events)
2021-01-20
Stake DAO and SDT token launched on Ethereum mainnet; initial airdrop distributed.
2021-02-04
SDT reaches all-time high price of $16.63.
2022-01-01
Stake DAO adopts veTokenomic model; SDT lockable for veSDT governance rights.
2022-06-15
SDT reaches all-time low of $0.1750 amid broader crypto bear market.
2023-01-01
Two-year linear vesting for initial contributors and angel investors concludes.
2023-11-29
Stake DAO discloses LiquidityGauge deployment error on BNB Chain; approximately $4,011 in CAKE tokens stolen; affected users compensated via airdrop.
2026-03-12
Votemarket oracle contract exploited on Arbitrum and Base; approximately $176,000 drained across 54 reward campaigns. Governance proposal SDGP-65 introduced to reimburse affected users from treasury.
2026-05-27
Deployer private key compromised; attacker mints 5.4 trillion vsdCRV on Arbitrum via forged LayerZero v2 cross-chain message. Attacker realizes approximately $91,000 before DEX liquidity exhausted. Stake DAO shuts down vsdCRV bridge and urges users not to interact with vsdCRV.
2026-05-28
Stake DAO publishes follow-up statement assuring users that core products (Liquid Lockers, Boosted Yields, Votemarket, Morpho lending) are unaffected; vsdCRV backing on Ethereum mainnet confirmed secured.
Decision Log
- hash: ESZXryXwjtoCADpwDGfqBSbtf49dvFPV78q7J9SKGajd
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:18 AM
last updated: 5/29/2026, 2:35:00 AM
avoid.net — verified advice for a post-truth world