Unauthorized mint of vsdCRV discovered on Arbitrum; core funds and most services remain unaffected.
Security & Exploits ·
An unauthorized minting of vsdCRV tokens on Arbitrum was discovered by Stake DAO, which issued a warning on May 27, 2026 advising users not to interact with the affected token. A preliminary investigation attributed the incident to an attacker who minted vsdCRV without authorization; however, the protocol's response contained the damage by securing vsdCRV backing on mainnet—preventing the attacker from seizing funds—and promptly closing the vsdCRV bridge to Arbitrum.
Most of Stake DAO's core services escaped impact from the exploit. Boosted yields, Liquid Lockers, Votemarket, and Stake DAO lending on Morpho remained unaffected by the incident. The Arbitrum asdCRV Llamalend market is being sunset as a precaution, with crvUSD depositors directed to relocate their holdings to other Llamalend markets.
Law enforcement and security partners are actively investigating the incident, though specific details on the attacker's identity or methods remain undisclosed. The full scope of the minting operation and any additional vulnerabilities are still under review.