DeFi exploit hits Stake DAO as attacker swaps vsdCRV for ETH
Blockaid said the suspected root cause was a compromised Stake DAO deployer private key. According to the firm, the attacker used that access to reconfigure the LayerZero v2 OFT peer for the vsdCRV token contract. That change allegedly redirected trust from the legitimate Ethereum-side adapter to a malicious contract controlled by the attacker. The attacker then sent a forged cross-chain message that triggered the minting of roughly 5.44 trillion vsdCRV. BlockSec described the attack as a case where the attacker appeared to obtain the deployer‘s private key and set an arbitrary peer for vsdCRV. The firm said the forged message then caused unconditional minting to the attacker’s address. .@StakeDAOHQ was reportedly exploited via a deployer key compromise, resulting in ~5.44T $vsdCRV minted to the attacker. The attacker appears to have obtained the deployers private key and set an arbitrary peer for $vsdCRV. Using that peer, they forged a malicious message that… — BlockSec Phalcon (@Phalcon_xyz) May 27, 2026 The incident shows how privileged access remains a major risk in DeFi. Even when smart contract code works as designed, a compromised deployer key can give attackers the ability to change trusted settings and trigger losses. DeFi security concerns deepen The Stake DAO exploit follows a series of recent