//Stake DAO
B-

Stake DAOMicro-cap

Risk Score 30/100·CValue
Compare
$104MTVL·$5MFDV·YieldWebsite →

Moderate risk — mature yield infrastructure with active governance, tempered by two 2026 security incidents revealing operational key management gaps and peripheral oracle vulnerabilities.

Risk Breakdown

Top Risks

1

Two security incidents in Q1-Q2 2026: a Votemarket oracle spoofing exploit (~$176K drained, refunded from treasury) and a deployer private key compromise that enabled minting of 5.4T vsdCRV tokens on Arbitrum (~$91K extracted, cross-chain bridge permanently closed), indicating systemic key management and peripheral infrastructure risk.

2

Liquid Lockers (sdCRV, sdBAL, etc.) create liquid wrappers around vote-escrowed tokens, which defeats the alignment incentive of locking and enables governance extractable value through bribery markets.

3

Protocol revenue heavily depends on the Curve/Convex ecosystem and gauge vote economics; a structural decline in Curve's relevance would reduce Stake DAO's competitive moat.

4

Multi-protocol yield strategies compound smart contract risk across Curve, Balancer, Pendle, and other integrated protocols.

Frequently Asked Questions

Is Stake DAO safe to use?
Stake DAO receives a B- risk grade (30/100) from Hindenrank, where lower scores indicate lower risk. Moderate risk — mature yield infrastructure with active governance, tempered by two 2026 security incidents revealing operational key management gaps and peripheral oracle vulnerabilities. Stake DAO is a non-custodial yield optimization protocol that provides liquid wrappers for locked governance tokens (sdCRV, sdBAL) and automated yield strategies across DeFi. With ~$103M in TVL and 5+ years of operation, its B- grade reflects a mature protocol that experienced two security incidents in Q1-Q2 2026 — a Votemarket oracle spoofing exploit ($176K, refunded) and a deployer key compromise ($91K, vsdCRV Arbitrum bridge permanently closed) — alongside ongoing governance extractable value dynamics in the Curve ecosystem.
What are the main risks of using Stake DAO?
The key risks identified for Stake DAO are: (1) Two security incidents occurred in 2026: a Votemarket oracle spoofing attack (~$176K, refunded from treasury) and a deployer private key compromise that enabled minting of 5.4T vsdCRV tokens (~$91K extracted, cross-chain bridge permanently closed). Both indicate key management and peripheral infrastructure risk. (2) Liquid Lockers create tradeable versions of locked governance tokens, which can enable vote buying through bribery markets. This is a known dynamic in the Curve ecosystem and affects how protocol rewards are distributed. (3) Revenue depends heavily on the Curve Finance ecosystem. If Curve loses market share to newer DEX designs, Stake DAO's yields and competitive advantage would decline proportionally.
What is Stake DAO's risk score breakdown?
Stake DAO scores 30/100 across eight risk dimensions: Mechanism Novelty: 3/15, Interaction Severity: 5/20, Oracle Surface: 2/10, Documentation Gaps: 2/10, Track Record: 8/15, Scale Exposure: 5/10, Regulatory Risk: 2/10, Vitality Risk: 3/10. The highest risk area is Track Record at 8/15.
How does Stake DAO compare to other Yield protocols?
Among 121 rated Yield protocols on Hindenrank, Stake DAO ranks #26 by safety (lowest risk score = safest). Its 30/100 risk score and B- grade place it among the safer Yield protocols.
Has Stake DAO ever been hacked or exploited?
Stake DAO scores 8/15 on the Track Record risk dimension, indicating some history of security incidents or exploits. Higher scores reflect more severe or frequent incidents. Review the full risk report for details.

Incident History

1incident|$91,000total losses
Last scanned 2026-06-07

Get risk alerts before it's too late

Weekly grade changes, downgrade alerts, and new protocol risk findings. Free.