Incident case file
Sign in to watchStake DAO (vsdCRV) — Deployer Key Compromise + LayerZero v2 OFT setPeer() Abuse
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0xeF3C054d8F7eD0a7D61c8da56ff55F090577aa25 (recipient of the 5.44T vsdCRV mint and bridge proceeds, per EmberCN and Cryip). Compromised Stake DAO deployer key: 0x000755Fbe4A24d7478bfcFC1E561AfCE82d1ff62 (Blockaid).
Timeline: On 27 May 2026 at 09:17:58 UTC (Arbitrum block 467160931), an attacker who had compromised Stake DAO's deployer private key (0x000755Fb...1ff62) reconfigured the vsdCRV LayerZero v2 OFT via setPeer() to point at an attacker-controlled peer contract on Ethereum, then forged a cross-chain message that triggered an unconditional mint of 5,446,744,073,709 vsdCRV (nominal ~$763 billion) to 0xeF3C054d...aa25. Because vsdCRV liquidity is extremely thin, the attacker could only swap about 16.83M vsdCRV on Curve and KyberSwap for 43.78 ETH (~$91,170), which was bridged back to Ethereum. Blockaid raised the alert within minutes (~09:25-09:30 UTC), BlockSec Phalcon and PeckShield corroborated, and Stake DAO acknowledged the situation around 10:30 UTC, advising users not to interact with vsdCRV. By 28 May the team confirmed contributors had secured the vsdCRV backing on mainnet (no funds seizable by the attacker) and permanently closed the vsdCRV bridge, containing impact to Arbitrum; the Arbitrum asdCRV Llamalend market was sunset while Boosted yields, Liquid Lockers, Votemarket and Stake DAO lending on Morpho were unaffected. There was no smart-contract bug and no LayerZero protocol flaw; the sole point of failure was a single privileged deployer EOA with no multisig or timelock on setPeer. TVL was about $151M, with only a small portion exposed on Arbitrum. NOTE: this is distinct from the unrelated 'Stake DAO -- Oracle Message Spoofing' incident of 12 March 2026.
Sources and coverage
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/05/28/stake-dao-assures-users-after-vsdcrv-exploit-and-bridge-shutdown/
- Articlebeincrypto.comhttps://beincrypto.com/stake-dao-exploit-deployer-key-vsdcrv/
- Articlex.comhttps://x.com/PeckShieldAlert/status/2059578749352640679
- Articlenftplazas.comhttps://nftplazas.com/stake-dao-exploit-lets-attacker-mint-5-4t-vsdcrv-on-arbitrum/
- Articleinvezz.comhttps://invezz.com/news/2026/05/27/arbitrum-based-stakedao-contract-hit-by-5-4t-vsdcrv-exploit/
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)