StakeDAO Hit After Deployer Key Leak Lets Attacker Mint 5.4 Trillion vsdCRV on Arbitrum

StakeDAO Hit After Deployer Key Leak Lets Attacker Mint 5.4 Trillion vsdCRV on Arbitrum

N
News Editor 01
2026-07-23 14:20:15
Blockaid said a leaked StakeDAO deployer key was used to reconfigure LayerZero v2 OFT peers, enabling the attacker to mint more than 5.4 trillion vsdCRV on Arbitrum and swap the tokens for ETH.
StakeDAOArbitrumLayerZerovsdCRVDeFi security

StakeDAO is under active attack on Arbitrum after an attacker minted more than 5.4 trillion vsdCRV and began swapping the tokens for ETH. Blockchain security firm Blockaid said the suspected root cause is a compromised deployer private key, and the incident was still unfolding at the time of the alert.

Compromised deployer key used to rewrite trusted cross-chain peers

According to Blockaid, the exposed deployer key was 0x000755F…1ff62. After obtaining that access, the attacker called the setPeer function on the vsdCRV token contract and changed the LayerZero v2 OFT peer configuration. The trusted Ethereum mainnet endpoint, the legitimate vsdCRVOFTAdapter, was redirected to a malicious contract controlled by the attacker.

That change opened the door to minting on Arbitrum. Once the trust mapping had been altered, the attacker carried out cross-chain minting and created a massive amount of vsdCRV with no legitimate backing, then started selling the tokens into ETH. The mechanics were straightforward. The impact was not.

LayerZero v2 OFT setup became the path for unauthorized minting

The report points to LayerZero v2 OFT, short for Omnichain Fungible Token, as the framework involved in the exploit. This was not a case of tokens being accumulated through open-market purchases. The attacker first inserted a malicious contract into the trusted peer setup, then used that position to mint at scale on Arbitrum. Blockaid described the exploit as ongoing and urged users to pause all StakeDAO-related activity.

vsdCRV, or Vote Boosted sdCRV, is part of StakeDAO’s governance design in the Curve ecosystem. Holders can delegate veSDT to increase voting weight. In this case, the asset being minted was the cross-chain version on Arbitrum. The final loss had not been established in the source material, which said the outcome would depend on how much ETH the attacker could extract from liquidity pools.

Another LayerZero-linked attack route, but a different failure point

The article also noted that this is not the first LayerZero-related attack vector seen this year. In April, Kelp DAO lost $293 million to North Korean hackers in an incident tied to weaknesses in LayerZero’s cross-chain verification flow. The two cases were different, though. Kelp DAO involved a compromised single validator in the DVN, or Decentralized Verifier Network, while the StakeDAO case stems from a leaked deployer key that allowed direct contract reconfiguration.

Earlier the same day, OpenZeppelin co-founder Manuel Araoz publicly said that “all DeFi is unsafe.” The StakeDAO incident has now added another example centered on private key security, cross-chain permissions, and the fragility of governance-linked assets.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
600

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.