Moderate risk — mature yield infrastructure with active governance, tempered by two 2026 security incidents revealing operational key management gaps and peripheral oracle vulnerabilities.
Risk Breakdown
Top Risks
Two security incidents in Q1-Q2 2026: a Votemarket oracle spoofing exploit (~$176K drained, refunded from treasury) and a deployer private key compromise that enabled minting of 5.4T vsdCRV tokens on Arbitrum (~$91K extracted, cross-chain bridge permanently closed), indicating systemic key management and peripheral infrastructure risk.
Liquid Lockers (sdCRV, sdBAL, etc.) create liquid wrappers around vote-escrowed tokens, which defeats the alignment incentive of locking and enables governance extractable value through bribery markets.
Protocol revenue heavily depends on the Curve/Convex ecosystem and gauge vote economics; a structural decline in Curve's relevance would reduce Stake DAO's competitive moat.
Multi-protocol yield strategies compound smart contract risk across Curve, Balancer, Pendle, and other integrated protocols.
Frequently Asked Questions
Is Stake DAO safe to use?
What are the main risks of using Stake DAO?
What is Stake DAO's risk score breakdown?
How does Stake DAO compare to other Yield protocols?
Has Stake DAO ever been hacked or exploited?
Incident History
Get risk alerts before it's too late
Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.