← Radar

Incident case file

Sign in to watch

Stake DAO (vsdCRV) — Deployer Key Compromise + LayerZero v2 OFT setPeer() Abuse

Incident date May 27, 2026

0 views

ContainedArbitrumPrivate key compromise / cross-chain mintCluster: SDAO-KEY-2026-05

Estimated loss

$91.2K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

90%

Facts and investigation

Attacker: 0xeF3C054d8F7eD0a7D61c8da56ff55F090577aa25 (recipient of the 5.44T vsdCRV mint and bridge proceeds, per EmberCN and Cryip). Compromised Stake DAO deployer key: 0x000755Fbe4A24d7478bfcFC1E561AfCE82d1ff62 (Blockaid).

Funds moved to: 16.83M of the 5.44 trillion minted vsdCRV swapped on Curve then KyberSwap for 43.78 ETH (~$91,170), bridged back to Ethereum mainnet and retained by the attacker. The remaining nominal supply was unsellable due to thin liquidity.
Compromised deployer key: 0x000755Fbe4A24d7478bfcFC1E561AfCE82d1ff62. Attacker recipient: 0xeF3C054d8F7eD0a7D61c8da56ff55F090577aa25. Mint occurred at Arbitrum block 467160931 at 09:17:58 UTC on 27 May 2026 (5,446,744,073,709 vsdCRV, nominal ~$763B). No retail user wallets were drained; the mainnet vsdCRV backing was secured before the attacker could seize it, and the vsdCRV bridge was permanently closed, capping realised damage at the 43.78 ETH the attacker extracted from thin Arbitrum liquidit

Timeline: On 27 May 2026 at 09:17:58 UTC (Arbitrum block 467160931), an attacker who had compromised Stake DAO's deployer private key (0x000755Fb...1ff62) reconfigured the vsdCRV LayerZero v2 OFT via setPeer() to point at an attacker-controlled peer contract on Ethereum, then forged a cross-chain message that triggered an unconditional mint of 5,446,744,073,709 vsdCRV (nominal ~$763 billion) to 0xeF3C054d...aa25. Because vsdCRV liquidity is extremely thin, the attacker could only swap about 16.83M vsdCRV on Curve and KyberSwap for 43.78 ETH (~$91,170), which was bridged back to Ethereum. Blockaid raised the alert within minutes (~09:25-09:30 UTC), BlockSec Phalcon and PeckShield corroborated, and Stake DAO acknowledged the situation around 10:30 UTC, advising users not to interact with vsdCRV. By 28 May the team confirmed contributors had secured the vsdCRV backing on mainnet (no funds seizable by the attacker) and permanently closed the vsdCRV bridge, containing impact to Arbitrum; the Arbitrum asdCRV Llamalend market was sunset while Boosted yields, Liquid Lockers, Votemarket and Stake DAO lending on Morpho were unaffected. There was no smart-contract bug and no LayerZero protocol flaw; the sole point of failure was a single privileged deployer EOA with no multisig or timelock on setPeer. TVL was about $151M, with only a small portion exposed on Arbitrum. NOTE: this is distinct from the unrelated 'Stake DAO -- Oracle Message Spoofing' incident of 12 March 2026.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)