StakeDAO was compromised on May 27, 2026, when an attacker stole the deployer EOA private key, leading to the forging of unbacked vsdCRV tokens and draining approximately $91K from a Curve pool. The core contracts were not at risk, and the product was deprecated.
Stake DAO's Votemarket module was exploited via a cross-chain bridge vulnerability, leading to fabricated L1 block data and forged vote proofs. Approximately $176,000 in campaign incentive rewards were drained across 54 campaigns. The incident was resolved as a white-hat event with most funds recovered.