Stake DAO hit by 5.4T vsdCRV exploit, $91K drained

Stake DAO was exploited on Arbitrum after a private key compromise let an attacker mint 5.4 trillion vsdCRV, swap for ETH, and drain $91,000. Users are warned not to interact with vsdCRV.

Stake DAO, a DeFi protocol operating on Arbitrum, recently suffered a significant exploit. An attacker compromised the deployer’s private key, allowing them to mint approximately 5.4 trillion vsdCRV tokens. These tokens, intended to boost governance voting power, were quickly swapped for ether, draining around $91,000 from liquidity pools. Security firms Blockaid and PeckShield confirmed the exploit, explaining that the attacker exploited a contract vulnerability to mint the tokens and bridge the proceeds to Ethereum. Stake DAO has acknowledged the incident and strongly advised users not to interact with vsdCRV tokens. The root cause was a critical failure in the token’s minting or validation process, leading to artificial inflation. This incident highlights persistent security challenges in DeFi. The exploit appears limited to Stake DAO’s vsdCRV contract, with no evidence of impact on other Curve-based vaults.

Related Tokens

Related News