Low Smart contract exploit Source: DeFiLlama Hacks

Stake DAO — Caller Impersonation

Stake DAO's Votemarket module was exploited via a cross-chain bridge vulnerability, leading to fabricated L1 block data and forged vote proofs. Approximately $176,000 in campaign incentive rewards were drained across 54 campaigns. The incident was resolved as a white-hat event with most funds recovered.

Estimated loss
$176,000
Protocols
Stake DAO
Chains
Arbitrum, Base
Confidence
High
First seen
12 Mar 2026, 00:00 UTC

Read the original report ↗ (opens in a new tab)