Stake DAO Hack

TOTAL LOST $91K
Low Access Control Attacks arbitrum

What happened

On May 27, 2026, the DeFi protocol Stake DAO was exploited on the Arbitrum network following the compromise of a deployer private key. Due to the limited liquidity available for vsdCRV, the attacker was only able to realize roughly $91,170 in profit before swapping and bridging the funds to the Ethereum mainnet.

The incident was a direct result of a private key leakage and was not caused by a vulnerability in the protocol's smart contracts or the LayerZero infrastructure. The attacker gained access to a single Stake DAO deployer key on Arbitrum, which controlled privileged administrative configuration rights.

Using this key, the attacker altered the setPeer() configuration for the vsdCRV cross-chain bridge, effectively redirecting the protocol's trust to a contract they controlled on Ethereum. Approximately 25 seconds after this configuration change, the attacker's contract sent a malicious LayerZero message back to Arbitrum. Because the bridge routing had been altered, the Arbitrum vsdCRV contract accepted the message as an authentic bridging command and minted over 5.4 trillion tokens directly to the attacker’s address. While the nominal volume of these tokens was massive, the attacker could only swap 16.83 million vsdCRV for 43.78 ETH before completely exhausting the shallow liquidity pools.

Deployer Address (Compromised):

0x000755Fb…d1ff62

Case & protocol details

Classification Yield Aggregator / Key Compromise
Protocol Type Yield
Smart Contract Language Solidity
Official Website www.stakedao.org/
Protocol Twitter/X @StakeDAOHQ

Market Context at Time of Hack

Token Price at Hack $0.1183
Market Cap at Hack $8.0M
% of Market Cap Stolen 1.14%
Token Categories
Decentralized Finance (DeFi) Yield Farming Yield Aggregator Polygon Ecosystem Arbitrum Ecosystem Olympus Pro Ecosystem Ethereum Ecosystem Liquid Staking Governance Tokens

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.