Close Menu
    Instagram
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    Instagram
    Crypto Celtic
    • Home
    • Crypto News
      • Bitcoin
      • Ethereum
      • Altcoins
      • Blockchain
      • DeFi
    • AI News
    • Stock News
    • Learn
      • Crypto for Beginners
      • AI for Beginners
      • AI Tips
      • Make Money with AI
    • Reviews
    • Tools
      • Best AI Tools
      • Crypto Market Cap List
      • Stock Market Overview
      • Market Heatmap
    • Contact
    Crypto Celtic
    Home»Crypto News»DeFi»StakeDAO vsdCRV Attacker Limited to $91K By Thin Liquidity
    Cointelegraph
    DeFi

    StakeDAO vsdCRV Attacker Limited to $91K By Thin Liquidity

    May 27, 20262 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email
    kraken


    An attacker minted more than 5.4 trillion vsdCRV on Arbitrum after a suspected compromise of a StakeDAO-linked deployer key, though thin liquidity limited the realized proceeds to about $91,000.

    Blockchain security firm PeckShield said Wednesday the attacker swapped part of the minted vsdCRV for 43.7 Ether (ETH), worth about $91,000, and bridged the funds to Ethereum. Onchain analyst EmberCN said the attacker swapped about 16.83 million vsdCRV, while the remaining tokens had little meaningful liquidity to exit.

    EmberCN estimated the 5.4 trillion vsdCRV at about $763 billion on paper, though the figure does not represent the attacker’s realized profit or the protocol’s confirmed loss.

    The incident highlights the gap between nominal token values and extractable value in decentralized finance exploits, where attackers can mint enormous token amounts but only cash out what available liquidity allows. In this case, the attacker’s proceeds were limited by the small size of vsdCRV liquidity pools.

    kukoin

    StakeDAO said it was aware of the incident and warned its users not to interact with vsdCRV.

    Stake DAO said it was aware of the incident. Source: Stake DAO

    Incident points to a deployer-key compromise 

    Shalev Keren, chief product officer and co-founder of crypto key-management firm Sodot, told Cointelegraph that the StakeDAO incident was “structurally similar” to other deployer-key compromises seen this year, including the Wasabi incident last month, which drained about $5.5 million in crypto. 

    Keren said a single StakeDAO deployer key on Arbitrum was used to repoint the vsdCRV cross-chain bridge configuration to an attacker-controlled contract on Ethereum. About 25 seconds later, that contract sent a LayerZero message back to Arbitrum, causing the legitimate Arbitrum token to mint more than 5 trillion vsdCRV to the attacker.

    Related: Crypto hackers stole $17B over past 10 years: DefiLlama

    “There is no smart contract bug here and no flaw in LayerZero,” Keren said. “There is one private key, controlling one privileged configuration function, with no multi-signature and no delay between the configuration change going through and the mint clearing onchain.” 

    Keren said the broader issue for DeFi protocols in 2026 is no longer only whether contracts are audited, but whether the operational keys behind those contracts remain single points of failure. 

    Magazine: ETH bears growling, Tom Lee’s buying, XRP to ‘explode’: Market Moves



    Source link

    coinbase
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    ‘All Of DeFi Unsafe,’ Developer Warns As AI Agents Reshape Security Threats

    May 28, 2026

    Kelp DAO Says rsETH Fully Restored 5 Weeks After Hack

    May 26, 2026

    Multiple ETH Data Points Suggest Altcoin Is Good Longterm Buy: Analyst

    May 23, 2026

    DeFi Hacks Shake Institutional Confidence as Risks Outpace Yields

    May 22, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    kukoin
    Latest Posts

    ERC-7943 Author Says Institutions Can’t Play Defi’s ‘Pirate Game’

    May 28, 2026

    Soybeans Starting Thursday with Gains

    May 28, 2026

    Bitcoin Late Longs Washed Out as BTC Price Slipped Below $73K

    May 28, 2026

    ‘All Of DeFi Unsafe,’ Developer Warns As AI Agents Reshape Security Threats

    May 28, 2026

    Another Set of Long-Silent Bitcoin Wallets Move Millions During BTC Decline

    May 27, 2026
    kukoin
    LEGAL INFORMATION
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    Top Insights

    Perplexity AI Open-Sources Unigram Tokenizer That Achieves 5x Lower p50 Latency Than Hugging Face tokenizers Crate

    May 28, 2026

    Master AI Films In 9 Minutes (AI Filmmaking Tutorial)

    May 28, 2026
    kukoin
    Instagram
    © 2026 CryptoCeltic.com - All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.