Skip to main content
Important: We do not provide financial advice or custody funds. All transactions occur on third-party platforms.
Back to news
securitymedium impact

StakeDAO Exploit Minted 5.4 Trillion Tokens — But the Attacker Only Walked Away With $91K. Here's Why

77d ago · 1 source

An attacker exploited a vulnerability in StakeDAO's vsdCRV token contract, minting a staggering 5.4 trillion tokens. Despite the astronomical number of tokens created, the exploit only netted approximately $91,000 due to limited liquidity available to cash out against.

WHY IT MATTERS

Imagine someone found a way to print 5.4 trillion counterfeit dollars — but the only store they could spend them at had just $91,000 worth of goods on the shelves. That's essentially what happened here. In DeFi (decentralized finance), tokens can be swapped for other tokens in digital 'pools' of money. The attacker minted a massive number of fake tokens, but there wasn't enough real money in the pool to trade them against, so they could only steal a relatively small amount. This is a good example of why 'liquidity' — the amount of real money available for trading — matters so much in crypto. It also shows that even protocols built on top of well-known projects like Curve can have security flaws, which is why doing your own research before depositing funds is crucial.

Read the full analysis with a CryptoBipto membership

Create a free account and subscribe to unlock deep-dive analysis on every story.

Get started

SOURCES

RELATED

CRVDeFi ExploitsSmart Contract VulnerabilityLiquidityCurve EcosystemStakeDAO

Educational only — not financial advice.