StakeDAO deployer key compromised on Arbitrum, attacker mints 5.4T vsdCRV
Security & Exploits ·
An attacker gained control of StakeDAO's deployer private key on Arbitrum and minted 5.4 trillion vsdCRV tokens before beginning to swap the proceeds into ETH.
Security researchers flagged the activity as an ongoing exploit, with The Block reporting on the incident as it was identified. The compromise centers on the deployer key tied to StakeDAO's Arbitrum deployment, which allowed the attacker to mint the vsdCRV tokens outside of normal protocol issuance.
Multiple reports corroborate the same core details: a compromised deployer private key on Arbitrum, a mint of 5.4 trillion vsdCRV tokens, and subsequent conversion of the minted supply into ETH. One account of the incident put the swapped amount at roughly 43 ETH worth of the minted tokens, though the full scope of funds moved has not been confirmed across all reports.
The exploit was also surfaced by security alert accounts on X, which tracked the suspicious minting and swap activity in near real time. On-chain activity tied to the incident can be traced through the relevant Arbitrum address, where the mint and subsequent transfers are recorded.
A compromised deployer key represents a fundamental breach of the permissions typically reserved for contract upgrades or parameter changes, rather than token issuance, which is why the ability to mint at this scale drew immediate attention from researchers monitoring StakeDAO's contracts.
It remains unclear how the deployer key was obtained, the total value of ETH acquired through the swaps, and whether StakeDAO has paused affected contracts or issued a formal response. The extent of user funds at risk, if any beyond the minted vsdCRV, has also not been detailed in the reports so far.