DeFi’s automated yield protocols were built for retail, now they just add another layer of risk
Automated yield protocols built DeFis most persuasive retail pitch that depositing into a vault was all a user needed to do, with the protocol handling everything else. For users wanting exposure to Curves boosted yields without manually managing CRV locks, vote power, wrappers, gauges, and incentives, Stake DAO offered a product that packaged the full stack behind a simple interface and, in doing so, also packaged what could break. According to Blockaid, an attacker minted over 5.4 trillion vsdCRV on Arbitrum through a suspected compromise of a deployer key and began swapping tokens for ETH. The attacker altered LayerZero-related peer configuration to forge a cross-chain message before minting 5,446,744,073,709 vsdCRV, converting a portion into roughly 43.78 ETH, with liquidity constraining realized extraction far below the nominal mint. Stake DAO told users not to interact with vsdCRV while the situation was active. The incident spread to Curve, which warned users in an affected Arbitrum LlamaLend market, and Beefy Finance paused a connected vault with exposure to Curve and Convex. Stake DAOs Liquid Lockers let users deposit governance tokens like CRV, receive liquid sdTokens, and access boosted yield and governance exposure without managing the Curve-locking stack directly. The vault interface hides all of that and, in doing so,