StakeDAO is under active attack on Arbitrum after an attacker minted more than 5.4 trillion vsdCRV and began swapping the tokens for ETH. Blockchain security firm Blockaid said the suspected root cause is a compromised deployer private key, and the incident was still unfolding at the time of the alert.
Compromised deployer key used to rewrite trusted cross-chain peers
According to Blockaid, the exposed deployer key was 0x000755F…1ff62. After obtaining that access, the attacker called the setPeer function on the vsdCRV token contract and changed the LayerZero v2 OFT peer configuration. The trusted Ethereum mainnet endpoint, the legitimate vsdCRVOFTAdapter, was redirected to a malicious contract controlled by the attacker.
That change opened the door to minting on Arbitrum. Once the trust mapping had been altered, the attacker carried out cross-chain minting and created a massive amount of vsdCRV with no legitimate backing, then started selling the tokens into ETH. The mechanics were straightforward. The impact was not.
LayerZero v2 OFT setup became the path for unauthorized minting
The report points to LayerZero v2 OFT, short for Omnichain Fungible Token, as the framework involved in the exploit. This was not a case of tokens being accumulated through open-market purchases. The attacker first inserted a malicious contract into the trusted peer setup, then used that position to mint at scale on Arbitrum. Blockaid described the exploit as ongoing and urged users to pause all StakeDAO-related activity.
vsdCRV, or Vote Boosted sdCRV, is part of StakeDAO’s governance design in the Curve ecosystem. Holders can delegate veSDT to increase voting weight. In this case, the asset being minted was the cross-chain version on Arbitrum. The final loss had not been established in the source material, which said the outcome would depend on how much ETH the attacker could extract from liquidity pools.
Another LayerZero-linked attack route, but a different failure point
The article also noted that this is not the first LayerZero-related attack vector seen this year. In April, Kelp DAO lost $293 million to North Korean hackers in an incident tied to weaknesses in LayerZero’s cross-chain verification flow. The two cases were different, though. Kelp DAO involved a compromised single validator in the DVN, or Decentralized Verifier Network, while the StakeDAO case stems from a leaked deployer key that allowed direct contract reconfiguration.
Earlier the same day, OpenZeppelin co-founder Manuel Araoz publicly said that “all DeFi is unsafe.” The StakeDAO incident has now added another example centered on private key security, cross-chain permissions, and the fragility of governance-linked assets.

