todayonchain.com

Stake DAO Exploit Shows Why “Audited” Doesn’t Mean Safe In DeFi

BeInCrypto
The Stake DAO exploit, caused by a compromised deployer key rather than code vulnerabilities, highlights the limitations of smart contract audits in DeFi.

Summary

The Stake DAO protocol was recently compromised when an attacker gained access to its Arbitrum deployer key. By resetting the LayerZero v2 bridge peer, the attacker forged messages to mint 5.4 trillion vsdCRV tokens and swapped them for Ether, bypassing all smart contract security measures. This incident underscores that even audited protocols remain vulnerable if operational keys are not protected by multisig security, a recurring pattern in recent DeFi hacks.

(Source:BeInCrypto)