Stake DAO was exploited on Arbitrum after an attacker reportedly obtained the protocol’s deployer private key and changed the LayerZero v2 peer configuration for vsdCRV. By setting an arbitrary peer, the attacker forged a malicious cross-chain message that triggered the unconditional minting of roughly 5.44 trillion vsdCRV tokens to their wallet. Blockchain security firm Blockaid said the attacker already swapped part of the tokens for around 43.78 ETH and bridged funds to Ethereum. Users have been urged to revoke approvals while the team investigates the breach.








