A suspected deployer-key compromise let an attacker mint 5,446,744,073,709 vsdCRV on Arbitrum, manipulating LayerZero peer configuration to forge a cross-chain message before converting a portion into roughly 43.78 ETH. Liquidity constraints capped realized losses well below the nominal mint, but the incident forced Stake DAO to warn users off vsdCRV, prompted Curve to flag an affected Arbitrum LlamaLend market, and pushed Beefy Finance to pause a connected vault with Curve and Convex exposure.
The exploit traveled through the exact infrastructure that automated yield protocols hide from users: deployer keys, cross-chain messaging trust, wrapper-token accounting, and oracle dependencies.
CryptoSlate