Low Key compromise Source: SlowMist Hacked

Stake DAO hacked

StakeDAO was compromised on May 27, 2026, when an attacker stole the deployer EOA private key, leading to the forging of unbacked vsdCRV tokens and draining approximately $91K from a Curve pool. The core contracts were not at risk, and the product was deprecated.

Estimated loss
$91,000
Protocols
StakeDAO, Curve
Chains
Arbitrum
Confidence
High
First seen
27 May 2026, 00:00 UTC

Read the original report ↗ (opens in a new tab)