← Stake DAO3 decisions on this page
Audit log
Every state-changing event for Stake DAO: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-05-29 02:35:00ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 422,848,455
- sig
4a1ap9jQn4yj…NEq8mQfdexplorer ↗- hash
ESZXryXwjtoC…J9SKGajdsha256 → base58
verifying row…full verify ↗canonical bytes (6713 B) ▸
{"actor":"system:backfill","investigation_id":"22690c77-993d-44f5-aa47-0b2304ade6c1","kind":"publish","page_slug":"stake-dao","published_at":"2026-05-29T02:34:59.971Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Stake DAO","sections":[{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.stakedao.org/","type":"other","url":""},{"credibility":3,"name":"https://docs.stakedao.org/sdt","type":"other","url":""},{"credibility":3,"name":"https://iq.wiki/wiki/stake-dao","type":"other","url":""},{"credibility":3,"name":"https://defillama.com/protocol/stake-dao","type":"other","url":""},{"credibility":3,"name":"https://www.coingecko.com/en/coins/stake-dao","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://cryptoslate.com/people/julien-bouteloup/","type":"other","url":""},{"credibility":3,"name":"https://iq.wiki/wiki/julien-bouteloup","type":"other","url":""},{"credibility":3,"name":"https://www.quicknode.com/builders-guide/tools/stake-dao-julien-bouteloup?category=defi-tools","type":"other","url":""},{"credibility":3,"name":"https://members.delphidigital.io/reports/building-defi-disneyland-julien-bouteloup-covering-stakedao-blackpool-rekt-and-curve/","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://www.cryptotimes.io/2026/05/27/stake-dao-exploited-as-hacker-mints-5-4-trillion-fake-vsdcrv/","type":"other","url":""},{"credibility":3,"name":"https://cryptobriefing.com/stake-dao-exploit-vsdcrv-arbitrum/","type":"other","url":""},{"credibility":3,"name":"https://beincrypto.com/stake-dao-exploit-deployer-key-vsdcrv/","type":"other","url":""},{"credibility":3,"name":"https://invezz.com/news/2026/05/27/arbitrum-based-stakedao-contract-hit-by-5-4t-vsdcrv-exploit/","type":"other","url":""},{"credibility":3,"name":"https://crypto.news/defi-exploit-hits-stake-dao-as-attacker-swaps-vsdcrv-for-eth/","type":"other","url":""},{"credibility":3,"name":"https://protos.com/stake-dao-hit-by-hack-as-defi-security-confidence-hits-new-low/","type":"other","url":""},{"credibility":3,"name":"https://www.cryptotimes.io/2026/05/28/stake-dao-assures-users-after-vsdcrv-exploit-and-bridge-shutdown/","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://x.com/StakeDAOHQ/status/2032489716629578004","type":"other","url":""},{"credibility":3,"name":"https://gov.stakedao.org/t/sdgp-65-allow-the-refund-of-affected-users-from-the-march-12-2026-incident-from-the-treasury/1117","type":"other","url":""},{"credibility":3,"name":"https://gov.stakedao.org/t/stake-dao-association-march-2026-report/1124","type":"other","url":""},{"credibility":3,"name":"https://protos.com/stake-dao-hit-by-hack-as-defi-security-confidence-hits-new-low/","type":"other","url":""},{"credibility":3,"name":"https://smartcontractshacking.com/hacks/stake-dao-hack-2026","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://github.com/stake-dao/stake-dao-security/blob/main/disclosures/29-11-2023.md","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://github.com/stake-dao/audits","type":"other","url":""},{"credibility":3,"name":"https://docs.stakedao.org/audits","type":"other","url":""},{"credibility":3,"name":"https://www.chainsecurity.com/security-audit/stakedao-liquidlockers","type":"other","url":""},{"credibility":3,"name":"https://skynet.certik.com/projects/stake-dao","type":"other","url":""},{"credibility":3,"name":"https://beincrypto.com/stake-dao-exploit-deployer-key-vsdcrv/","type":"other","url":""},{"credibility":3,"name":"https://protos.com/stake-dao-hit-by-hack-as-defi-security-confidence-hits-new-low/","type":"other","url":""}]},{"content":"","heading":"","severity":"medium","sources":[{"credibility":3,"name":"https://docs.stakedao.org/sdt","type":"other","url":""},{"credibility":3,"name":"https://docs.stakedao.org/vesdt_governance","type":"other","url":""},{"credibility":3,"name":"https://etherscan.io/token/0x73968b9a57c6e53d41345fd57a6e6ae27d6cdb2f","type":"other","url":""},{"credibility":3,"name":"https://www.mexc.com/en-GB/price/stake-dao/info","type":"other","url":""}]}],"sources_used":[],"summary":"Stake DAO is a non-custodial DeFi protocol built around liquid staking, yield aggregation, and governance participation via veToken mechanics. The protocol has suffered three documented security incidents since 2023, the most severe of which — a May 2026 deployer private key compromise — enabled the minting of 5.4 trillion fraudulent vsdCRV tokens on Arbitrum, resulting in roughly $91,000 in realized losses despite a nominally catastrophic exposure. Repeated operational security failures across a two-year span, including a March 2026 oracle exploit draining $176,000 from its Votemarket product, indicate a pattern of infrastructure risk that audited smart contracts alone have not resolved.","timeline":[{"date":"2021-01-20","event":"Stake DAO and SDT token launched on Ethereum mainnet; initial airdrop distributed.","source":""},{"date":"2021-02-04","event":"SDT reaches all-time high price of $16.63.","source":""},{"date":"2022-01-01","event":"Stake DAO adopts veTokenomic model; SDT lockable for veSDT governance rights.","source":""},{"date":"2022-06-15","event":"SDT reaches all-time low of $0.1750 amid broader crypto bear market.","source":""},{"date":"2023-01-01","event":"Two-year linear vesting for initial contributors and angel investors concludes.","source":""},{"date":"2023-11-29","event":"Stake DAO discloses LiquidityGauge deployment error on BNB Chain; approximately $4,011 in CAKE tokens stolen; affected users compensated via airdrop.","source":""},{"date":"2026-03-12","event":"Votemarket oracle contract exploited on Arbitrum and Base; approximately $176,000 drained across 54 reward campaigns. Governance proposal SDGP-65 introduced to reimburse affected users from treasury.","source":""},{"date":"2026-05-27","event":"Deployer private key compromised; attacker mints 5.4 trillion vsdCRV on Arbitrum via forged LayerZero v2 cross-chain message. Attacker realizes approximately $91,000 before DEX liquidity exhausted. Stake DAO shuts down vsdCRV bridge and urges users not to interact with vsdCRV.","source":""},{"date":"2026-05-28","event":"Stake DAO publishes follow-up statement assuring users that core products (Liquid Lockers, Boosted Yields, Votemarket, Morpho lending) are unaffected; vsdCRV backing on Ethereum mainnet confirmed secured.","source":""}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 182e407b-59af-41f7-b6db-03405c288101 - #2reviewby reviewerreviewer2026-08-27 10:41:31ZScore: 46 → 46 (no score change)This is a thin page: with section body text absent from the reviewed snapshot, only 11 checkable atomic claims exist, all drawn from the summary and timeline. The three security incidents (Nov 2023 CAKE bug, March 2026 Votemarket oracle exploit, May 2026 vsdCRV deployer-key exploit) are all confirmed with figures, dates, and mechanisms matching primary and independent sources closely. The two weakest points are the SDT all-time-high and all-time-low price claims, which do not match the page's own cited CoinGecko source and, in the all-time-low case, are also stale given a new lower low set after the 2026 exploits. Two timeline dates (2022-01-01, 2023-01-01) bear the hallmarks of rounded placeholders rather than sourced exact dates, though the underlying year/quarter is directionally correct.anchoranchored
- chain
- ●mainnet-betaslot 443,525,330
- sig
25AimPZakjVW…WkyWKH9Kexplorer ↗- hash
EGB73CfsXnPg…cuoK1Uyxsha256 → base58
verifying row…full verify ↗canonical bytes (1147 B) ▸
{"actor":"reviewer","decided_at":"2026-08-27T10:41:30.520Z","decision":"review","investigation_id":"22690c77-993d-44f5-aa47-0b2304ade6c1","new_score":46,"page_slug":"stake-dao","prev_score":46,"reason":"This is a thin page: with section body text absent from the reviewed snapshot, only 11 checkable atomic claims exist, all drawn from the summary and timeline. The three security incidents (Nov 2023 CAKE bug, March 2026 Votemarket oracle exploit, May 2026 vsdCRV deployer-key exploit) are all confirmed with figures, dates, and mechanisms matching primary and independent sources closely. The two weakest points are the SDT all-time-high and all-time-low price claims, which do not match the page's own cited CoinGecko source and, in the all-time-low case, are also stale given a new lower low set after the 2026 exploits. Two timeline dates (2022-01-01, 2023-01-01) bear the hallmarks of rounded placeholders rather than sourced exact dates, though the underlying year/quarter is directionally correct.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision 13f4bea5-4dd1-400d-a994-ea01d1d5dcfc - #3review reviseby judgejudge2026-08-27 10:41:31ZScore: 46 → 36 (-10)The math on disputed claims alone is favorable: 1 of 11 checkable claims (9.1%) was disputed, and the page's core risk content -- three security incidents (claim_findings[1], [2], [3]) -- was independently confirmed in precise detail against primary sources. However, two factors keep this out of a clean approve. First, claim_findings[8] shows the page's stated SDT all-time-low price and date directly contradict the page's own cited CoinGecko source, and that figure is also outdated following a new low set after the 2026 exploits; claim_findings[7] shows a similar mismatch on the all-time-high figure. Second, coverage_gaps[0] found that all seven of the page's content sections were empty in the reviewed state, meaning the vast majority of the page's substantive prose was never actually checkable -- a high-priority gap that limits how much confidence an 'approve' can carry. Together these push the page into a light revision cycle rather than a pass or a serious denial.anchoranchored
- chain
- ●mainnet-betaslot 443,525,333
- sig
3J4wRpCW2SJR…TADiFDuJexplorer ↗- hash
AhUSnz9tiFkW…PxUh4WNCsha256 → base58
verifying row…full verify ↗canonical bytes (1332 B) ▸
{"actor":"judge","decided_at":"2026-08-27T10:41:30.520Z","decision":"review_revise","investigation_id":"22690c77-993d-44f5-aa47-0b2304ade6c1","new_score":36,"page_slug":"stake-dao","prev_score":46,"reason":"The math on disputed claims alone is favorable: 1 of 11 checkable claims (9.1%) was disputed, and the page's core risk content -- three security incidents (claim_findings[1], [2], [3]) -- was independently confirmed in precise detail against primary sources. However, two factors keep this out of a clean approve. First, claim_findings[8] shows the page's stated SDT all-time-low price and date directly contradict the page's own cited CoinGecko source, and that figure is also outdated following a new low set after the 2026 exploits; claim_findings[7] shows a similar mismatch on the all-time-high figure. Second, coverage_gaps[0] found that all seven of the page's content sections were empty in the reviewed state, meaning the vast majority of the page's substantive prose was never actually checkable -- a high-priority gap that limits how much confidence an 'approve' can carry. Together these push the page into a light revision cycle rather than a pass or a serious denial.","score_delta":-10,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision 90d8ee1e-de26-49b3-80be-00798784bb9d
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.