StakeDAO — vsdCRV Deployer Key Exploit (May 2026)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·5AFpnx…HYVqSummary
On May 27, 2026, a threat actor compromised a StakeDAO deployer private key that had retained owner privileges on the vsdCRV LayerZero v2 OFT contract on Arbitrum since March 2024, enabling the minting of 5.44 trillion unbacked vsdCRV tokens within 25 seconds. Despite the astronomically large nominal mint, thin DEX liquidity limited the attacker's realized gain to approximately 43.78 ETH (~$91,000), which was subsequently laundered via Tornado Cash. StakeDAO passed a voluntary governance proposal (SDGP-70) to compensate 242 affected addresses with 1,535,421.76 sdCRV and filed a criminal complaint with Swiss authorities.
Connected Entities
1 entitiesTimeline(9 events)
March 2024
StakeDAO deployer wallet (0x000755Fbe4A24d7478bfcFC1E561AfCE82d1ff62) deploys vsdCRV LayerZero OFT contract on Arbitrum and retains owner privileges rather than transferring to governance multisig — the operational failure that later enabled the exploit.
CryptoTimes post-mortem coverage12 March 2026
Separate StakeDAO oracle message spoofing incident on Arbitrum and Base chains results in an alleged $176,000 loss — a distinct vulnerability class from the May deployer key exploit.
Smart Contract Hacking incident database27 May 2026
Attacker, having funded preparation wallets via Tornado Cash, uses the compromised StakeDAO deployer key to call setPeer() on the vsdCRV LayerZero v2 OFT contract on Arbitrum, redirecting trusted peers to a malicious contract. A forged cross-chain message mints 5,446,744,073,709 vsdCRV tokens to attacker wallet 0xeF3C054d8F7eD0a7D61c8da56ff55F090577aa25 within 25 seconds. The attacker swaps approximately 16.83 million vsdCRV across Curve and KyberSwap DEX pools, extracting 43.78 ETH (~$91,000), draining 321,143 CRV and 7.5 ETH from the Curve pool.
The Block, AMBCrypto, CryptoTimes27 May 2026
Blockaid publicly flags the exploit in progress. PeckShield and BlockSec confirm the attack vector. StakeDAO warns users not to interact with vsdCRV. Curve Finance warns LlamaLend users to withdraw. Beefy Finance pauses Arbitrum vaults.
Crypto Briefing, CryptoTimes27 May 2026
StakeDAO contributors secure mainnet vsdCRV backing within 47 minutes of the forged mint, preventing additional collateral loss. Arbitrum bridge permanently closed. Deployer owner privileges revoked and transferred to governance multisig same day.
CryptoTimes post-mortem, Stake DAO Assures Users31 May 2026
Attacker deposits extracted ETH proceeds into Tornado Cash in multiple transactions on Ethereum mainnet.
AMBCrypto9 June 2026
Stake DAO publishes detailed post-mortem and SDGP-70 governance proposal for voluntary ex gratia compensation of 1,535,421.76 sdCRV (~$173,000) to 242 affected addresses. Stake DAO also confirms it has filed a criminal complaint with Swiss authorities.
CryptoTimes, Stake DAO GovernanceJuly 2026
SDGP-70 compensation claims become available via Merkle tree contract on Ethereum mainnet through the Stake DAO portfolio interface, with a six-month claim window.
Stake DAO Governance SDGP-703 August 2026
SDGP-75 voting concludes, extending ex gratia compensation to Arbitrum asdCRV LlamaLend market borrowers unfairly liquidated during the vsdCRV price collapse on May 27.
Stake DAO Governance SDGP-75Decision Log
- hash: 7f4iLRPWmQ6vrJYmpWGQA9HMBV5mRreEv18ywR3LvhCK
- hash: HJkMFoYJW4hcVcBJfnhRNeRLRndwrs3eusj5JA81Vb9S
- hash: DmynN5Py4hbpV1Kx64dizcwQAW8FjnhH23KyyWXkZEfk
This investigation is cryptographically anchored to the Solana blockchain (3 events). 16 of 18 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/8/2026, 5:15:25 PM
last updated: 9/1/2026, 4:46:46 AM
4 viewsavoid.net — verified advice for a post-truth world