A smart contract vulnerability in Stake DAO is being actively exploited on Arbitrum, allowing an attacker to mint approximately 5.4 trillion vsdCRV tokens — a figure far exceeding any legitimate supply. Security researchers flagged the attack as ongoing, noting the exploiter is already converting the artificially minted tokens into ether, suggesting an attempt to extract real value before the protocol can respond. The vsdCRV token is tied to Stake DAO's vote-locked CRV mechanism, which is used to boost Curve Finance yields. Unlimited minting exploits of this type typically target flaws in token minting logic or access controls. The full extent of financial losses had not been confirmed at the time of reporting, but the active token-to-ETH swaps indicate funds are being drained in real time.


Read the original article →

— Sponsored —

Trade smarter on BYDFI

Get a bonus on your first deposit — from $50 at $100, up to $2,000 at $20k. 200x leverage, 600+ perpetuals, deep liquidity.

Claim your bonus →