StakeDAO’s vsdCRV token took a hit after an exploit that minted an absurd amount of supply.
According to PeckShield, the attacker minted trillions of vsdCRV, then bridged 43.7 ETH to Ethereum. The scale described by Cointelegraph is 5.4 trillion vsdCRV created in the incident.
What happened
PeckShield’s account frames the attacker’s path in two steps. First came the mint. Then came the exit move, bridging value to Ethereum after minting those huge volumes.
EmberCN’s response adds a key limiter. It said most of the remaining vsdCRV tokens had insufficient liquidity to sell.
That liquidity gap is why the exploit did not translate into a proportional payout.
Why it matters
A mint-and-dump scenario is the nightmare script for DeFi security teams. But EmberCN’s liquidity observation suggests this case behaved differently. Even with an inflated asset in circulation, the ability to convert it into real funds depends on market depth.
For asset holders and risk teams, the practical takeaway is uncomfortable but useful. Token quantity alone does not equal extractable value. Liquidity and market access can cap an attacker’s reachable profit.
Market impact
Cointelegraph reports the attacker netted only about $91K. That figure aligns with EmberCN’s point that most of the minted vsdCRV could not be sold due to thin liquidity.
This doesn’t make the exploit harmless. A supply shock can still damage trust, affect integrations, and trigger downstream depeg or collateral stress depending on how vsdCRV is used. But the “why so little profit” question matters because it points to what defenses and monitoring should prioritize.
| Fact | Detail |
|---|---|
| Incident type | StakeDAO exploit involving vsdCRV minting |
| Minted supply | 5.4 trillion vsdCRV |
| Exit step | 43.7 ETH bridged to Ethereum after mint |
| Liquidity constraint | EmberCN says most tokens had insufficient liquidity to sell |
| Reported proceeds | About $91K net to the attacker |
What to watch next
Two follow-ups stand out from the limited details in the reporting. First, whether the project and auditors can pinpoint how the minting worked in the first place. Cointelegraph’s extract only covers the attacker’s actions and the liquidity outcome.
Second, whether liquidity providers or markets for vsdCRV change after the exploit. EmberCN’s observation implies a selling bottleneck. If market conditions later improve, the same class of minting weakness could become more dangerous in a repeat incident.
Until more technical details are published, the story reads like this. The attacker found a minting route, converted part of it into ETH, then hit a liquidity wall that kept the cashout small.