Stake DAO Hack
What happened
On May 27, 2026, the DeFi protocol Stake DAO was exploited on the Arbitrum network following the compromise of a deployer private key. Due to the limited liquidity available for vsdCRV, the attacker was only able to realize roughly $91,170 in profit before swapping and bridging the funds to the Ethereum mainnet.
The incident was a direct result of a private key leakage and was not caused by a vulnerability in the protocol's smart contracts or the LayerZero infrastructure. The attacker gained access to a single Stake DAO deployer key on Arbitrum, which controlled privileged administrative configuration rights.
Using this key, the attacker altered the setPeer() configuration for the vsdCRV cross-chain bridge, effectively redirecting the protocol's trust to a contract they controlled on Ethereum. Approximately 25 seconds after this configuration change, the attacker's contract sent a malicious LayerZero message back to Arbitrum. Because the bridge routing had been altered, the Arbitrum vsdCRV contract accepted the message as an authentic bridging command and minted over 5.4 trillion tokens directly to the attacker’s address. While the nominal volume of these tokens was massive, the attacker could only swap 16.83 million vsdCRV for 43.78 ETH before completely exhausting the shallow liquidity pools.
Case & protocol details
Market Context at Time of Hack
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- report Report x.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.