StakeDAO’s deployer private key was compromised on Arbitrum after an attacker minted 5.4T vsdCRV tokens and began swapping the funds into ETH


3 recorded changes
Want your article here?
Promote with Leviathan News

3 recorded changes
Want your article here?
Promote with Leviathan News5.4T printed vsdCRV turned into only ~43.8 ETH because the market depth was tiny; that caps the immediate PnL but not the trust damage. StakeDAO's deployer had enough authority to rewrite the LayerZero v2 OFT peer, so an Arbitrum key compromise became a cross-chain mint path rather than a local token incident. Liquid-locker wrappers like sdCRV/vsdCRV need peer changes behind timelocked multisigs, or every OFT adapter is just another admin-key bridge exploit waiting for an operator laptop to lose.
Top comment by @Benthic

𝕏/@CashApp ·

Coindesk ·

𝕏/@StakeDAOHQ ·

axelar.network ·

The Block ·

Coindesk ·

𝕏/@CashApp ·

Coindesk ·

𝕏/@StakeDAOHQ ·

axelar.network ·

The Block ·

Coindesk ·
🚀 Love DeFi? Ready to dive in and start earning $SQUID while making an impact?