Close Menu
    Facebook X (Twitter) Instagram
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    Facebook X (Twitter) Instagram
    Fintech Fetch
    • Home
    • Crypto News
      • Bitcoin
      • Ethereum
      • Altcoins
      • Blockchain
      • DeFi
    • AI News
    • Stock News
    • Learn
      • AI for Beginners
      • AI Tips
      • Make Money with AI
    • Reviews
    • Tools
      • Best AI Tools
      • Crypto Market Cap List
      • Stock Market Overview
      • Market Heatmap
    • Contact
    Fintech Fetch
    Home»Crypto News»DeFi»StakeDAO vsdCRV Attacker Limited to $91K By Thin Liquidity
    Cointelegraph
    DeFi

    StakeDAO vsdCRV Attacker Limited to $91K By Thin Liquidity

    May 28, 20263 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email
    ledger

    rewrite this content and keep HTML tags as is. This is content from rss feed and I don’t need their *Daily Debrief Newsletter*, their tags from bottom like this *Share this articleCategoriesTags*, Editorial Process section, phrases like *Featured image from Peakpx, chart from Tradingview.com*, SPECIAL OFFERS and similar sections – just remove such sections and save only article itself:

    An attacker minted more than 5.4 trillion vsdCRV on Arbitrum after a suspected compromise of a StakeDAO-linked deployer key, though thin liquidity limited the realized proceeds to about $91,000.

    Blockchain security firm PeckShield said Wednesday the attacker swapped part of the minted vsdCRV for 43.7 Ether (ETH), worth about $91,000, and bridged the funds to Ethereum. Onchain analyst EmberCN said the attacker swapped about 16.83 million vsdCRV, while the remaining tokens had little meaningful liquidity to exit.

    EmberCN estimated the 5.4 trillion vsdCRV at about $763 billion on paper, though the figure does not represent the attacker’s realized profit or the protocol’s confirmed loss.

    The incident highlights the gap between nominal token values and extractable value in decentralized finance exploits, where attackers can mint enormous token amounts but only cash out what available liquidity allows. In this case, the attacker’s proceeds were limited by the small size of vsdCRV liquidity pools.

    synthesia

    StakeDAO said it was aware of the incident and warned its users not to interact with vsdCRV.

    Stake DAO said it was aware of the incident. Source: Stake DAO

    Incident points to a deployer-key compromise 

    Shalev Keren, chief product officer and co-founder of crypto key-management firm Sodot, told Cointelegraph that the StakeDAO incident was “structurally similar” to other deployer-key compromises seen this year, including the Wasabi incident last month, which drained about $5.5 million in crypto. 

    Keren said a single StakeDAO deployer key on Arbitrum was used to repoint the vsdCRV cross-chain bridge configuration to an attacker-controlled contract on Ethereum. About 25 seconds later, that contract sent a LayerZero message back to Arbitrum, causing the legitimate Arbitrum token to mint more than 5 trillion vsdCRV to the attacker.

    Related: Crypto hackers stole $17B over past 10 years: DefiLlama

    “There is no smart contract bug here and no flaw in LayerZero,” Keren said. “There is one private key, controlling one privileged configuration function, with no multi-signature and no delay between the configuration change going through and the mint clearing onchain.” 

    Keren said the broader issue for DeFi protocols in 2026 is no longer only whether contracts are audited, but whether the operational keys behind those contracts remain single points of failure. 

    Magazine: ETH bears growling, Tom Lee’s buying, XRP to ‘explode’: Market Moves

    binance
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Fintech Fetch Editorial Team
    • Website

    Related Posts

    DeFi

    ‘All Of DeFi Unsafe,’ Developer Warns As AI Agents Reshape Security Threats

    May 28, 2026
    Cointelegraph

    South Korea Makes First Arrest Tied to Memecoin Rug Pull: report

    May 27, 2026
    Cointelegraph

    Kelp DAO Says rsETH Fully Restored 5 Weeks After Hack

    May 26, 2026
    Cointelegraph

    DeFi Hacks Shake Institutional Confidence as Risks Outpace Yields

    May 23, 2026
    Add A Comment

    Comments are closed.

    Join our email newsletter and get news & updates into your inbox for free.


    Privacy Policy

    Thanks! We sent confirmation message to your inbox.

    synthesia
    Latest Posts
    shopper looks at paint color samples at home improvement store

    rewrite this title in other words: If I Could Only Buy and Hold a Single Stock, This Would Be It

    May 28, 2026
    Building AI models that understand chemical principles | MIT News

    Building AI models that understand chemical principles | MIT News

    May 28, 2026
    Cointelegraph

    StakeDAO vsdCRV Attacker Limited to $91K By Thin Liquidity

    May 28, 2026
    Cointelegraph

    rewrite this title in other words: Bitcoin, Altcoins Selloff Amid Rising ETF Outflows

    May 27, 2026
    Cointelegraph

    South Korea Makes First Arrest Tied to Memecoin Rug Pull: report

    May 27, 2026
    changelly
    LEGAL INFORMATION
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    Top Insights
    DeFi

    ‘All Of DeFi Unsafe,’ Developer Warns As AI Agents Reshape Security Threats

    May 28, 2026
    Bitcoin

    rewrite this title in other words: Major Bitcoin Players Drop Over A Billion In Sell-Offs While Euphoria Rocks Retail

    May 28, 2026
    kraken
    Facebook X (Twitter) Instagram Pinterest
    © 2026 FintechFetch.com - All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.