Futuros
Acesse centenas de contratos perpétuos
CFD
Ouro
Plataforma única para ativos tradicionais globais
Opções
Hot
Negocie opções vanilla no estilo europeu
Conta unificada
Maximize sua eficiência de capital
Negociação demo
Introdução à negociação de futuros
Prepare-se para sua negociação de futuros
Eventos de futuros
Participe de eventos e ganhe recompensas
Negociação demo
Use fundos virtuais para experimentar negociações sem riscos
Lançamento
CandyDrop
Colete candies para ganhar airdrops
Launchpool
Staking rápido, ganhe novos tokens em potencial
HODLer Airdrop
Possua GT em hold e ganhe airdrops massivos de graça
Pre-IPOs
Desbloqueie o acesso completo a IPO de ações globais
Pontos Alpha
Negocie on-chain e receba airdrops
Pontos de futuros
Ganhe pontos de futuros e colete recompensas em airdrop
Investimento
Simple Earn
Ganhe juros com tokens ociosos
Autoinvestimento
Invista automaticamente regularmente
Investimento duplo
Lucre com a volatilidade do mercado
Soft Staking
Ganhe recompensas com stakings flexíveis
Empréstimo de criptomoedas
0 Fees
Penhore uma criptomoeda para pegar outra emprestado
Centro de empréstimos
Centro de empréstimos integrado
Centro de riqueza VIP
Planos premium de crescimento de patrimônio
Gestão privada de patrimônio
Alocação premium de ativos
Fundo Quantitativo
Estratégias quant de alto nível
Apostar
Faça staking de criptomoedas para ganhar em produtos PoS
Alavancagem Inteligente
Alavancagem sem liquidação
Cunhagem de GUSD
Cunhe GUSD para retornos em RWA
Promoções
Centro de atividade
Participe de atividades e ganhe recompensas
Indicação
20 USDT
Convide amigos para recompensas de ind.
Programa de afiliados
Ganhe recomp. de comissão exclusivas
Gate Booster
Aumente a influência e ganhe airdrops
Anúncio
Atualizações na plataforma em tempo real
Blog da Gate
Artigos do setor de criptomoedas
Serviços VIP
Grandes Descontos nas Taxas
Gerenciamento de ativos
Solução completa de gerenciamento de ativos
Institucional
Soluções de ativos digitais para empresas
Desenvolvedores (API)
Conecta-se ao ecossistema de aplicativos da Gate
Transferência Bancária OTC
Deposite e retire moedas fiat
Programa de corretoras
Mecanismos de grandes descontos via API
AI
Gate AI
Seu parceiro de IA conversacional para todas as horas
Gate AI Bot
Use o Gate AI diretamente no seu aplicativo social
GateClaw
Gate Blue Lobster, pronto para usar
Gate for AI Agent
Infraestrutura de IA, Gate MCP, Skills e CLI
Gate Skills Hub
10K+ habilidades
Do escritório à negociação: um hub completo de habilidades para turbinar o uso da IA
GateRouter
Escolha inteligentemente entre mais de 40 modelos de IA, com 0% de taxas extras
DeFi voltou a explodir! Chave privada do implantador do StakeDAO vazou, o atacante está forjando 5,4 trilhões de vsdCRV no Arbitrum do nada e trocando por ETH
Blockchain security company Blockaid detected that Stake DAO on Arbitrum is under attack, with the attacker exploiting a leaked deployer private key to mint over 5.4 trillion vsdCRV (Vote Boosted sdCRV) tokens via the LayerZero v2 OFT cross-chain protocol out of thin air, and is currently exchanging them for ETH. Blockaid indicated that the suspected root cause is the private key leak, and the attack is ongoing.
(Background: OpenZeppelin co-founder called for all DeFi to be abandoned: AI has disrupted the balance of attack and defense, even blue-chip Aave is unsafe)
(Additional background: Kelp DAO announced full recovery of rsETH: stolen 293 million dollars by North Korean hackers 5 weeks ago)
Key Summary
Blockchain security company Blockaid issued an alert, detecting that DeFi yield protocol Stake DAO on Arbitrum is under ongoing attack. The attacker minted over 5.4 trillion vsdCRV (Vote Boosted sdCRV) tokens and is in the process of exchanging them for ETH.
Blockaid determined that the root cause was the StakeDAO deployer private key (0x000755F…1ff62) being leaked. After obtaining the private key, the attacker called the setPeer function on the vsdCRV token contract to reconfigure the LayerZero v2 OFT (Omnichain Fungible Token) cross-chain peer node settings, redirecting the trust relationship from the legitimate vsdCRVOFTAdapter on the Ethereum mainnet to a malicious contract deployed by the attacker. After completing the trust redirection, the attacker performed cross-chain minting on Arbitrum, creating a large amount of vsdCRV out of thin air and starting to sell.
Another LayerZero-related cross-chain vulnerability
This is not the first time this year that LayerZero’s cross-chain architecture has become an attack vector. In April, Kelp DAO was hacked by North Korean hackers, stealing 293 million USD, exploiting weaknesses in LayerZero’s cross-chain verification mechanism. The difference is that Kelp DAO’s single point verifier in the DVN (Decentralized Verification Network) was compromised, whereas StakeDAO’s private key itself was leaked, allowing the attacker to directly modify contract settings.
StakeDAO’s vsdCRV is a governance token in the Curve ecosystem, allowing sdCRV holders to boost voting power via delegated veSDT. The attack is still ongoing, and the final loss amount depends on how much ETH the attacker can extract from liquidity pools.
Blockaid urges all users to suspend all StakeDAO-related operations.
Today, OpenZeppelin co-founder Manuel Araoz publicly stated, “All DeFi is unsafe,” and the private key leak of StakeDAO’s deployer further confirms his judgment.
Frequently Asked Questions
What is the method of this StakeDAO attack?
After obtaining the StakeDAO deployer’s private key, the attacker used the permission to reconfigure the LayerZero v2 OFT cross-chain contract’s peer nodes (setPeer), redirecting trust from the legitimate Ethereum contract to a malicious one, then minted over 5.4 trillion vsdCRV on Arbitrum out of thin air and exchanged for ETH.
What is vsdCRV?
vsdCRV is the “Vote Boosted sdCRV” token of Stake DAO, part of the Curve ecosystem governance system. Holders can delegate veSDT to increase voting weight, used for Curve-related liquidity incentive voting. The minted tokens are the cross-chain version on Arbitrum.