Compromised Deployer Key Drains $1.14M From Steadefi Vaults
Steadefi, a yield farming protocol running on Arbitrum and Avalanche, lost roughly $1.14 million on Monday after the private key controlling its deployer address fell into an attacker's hands. Whether the key was obtained through a phishing scheme or leaked by someone with internal access remains unclear.
The team confirmed the breach on Twitter, warning: "NOTICE: Steadefi has been exploited and all funds are currently at risk."

Alongside the disclosure, Steadefi sent an on-chain message offering the attacker a bounty in exchange for returning the stolen assets — a follow-up transaction had to be sent shortly after to correct a typo in the negotiation email address included in the original message.
The proposed terms echoed the bounty structure used after the recent Curve pools exploit: the attacker was given a deadline to return 90% of the funds and would be allowed to keep the remainder. Should that deadline pass without a response, Steadefi said the retained 10% would instead be offered publicly as a reward for information leading to the person's identification and prosecution. It raises the question of whether this kind of arrangement could become a template other protocols adopt after future incidents — assuming it proves effective at all.
According to Steadefi's own account of events, the compromised deployer wallet held ownership over every vault contract in the protocol. That ownership let the attacker reassign control of the contracts to an address they controlled — visible, for instance, in the transaction transferring the Arbitrum USDC vault. From that position, Steadefi said the attacker "went on to take various owner-only actions such as allowing any wallet to be able to borrow any available funds from the lending vaults."
That single permission change let the attacker empty every lending vault available for borrowing on both chains. Deposits sitting in the protocol's separate "Depositor vaults" were the only funds left untouched. As a result, Steadefi's total value locked collapsed from north of $2 million to about $550,000.
Not all of the remaining balance is actually accessible, however. Steadefi noted that the attacker also paused the farms contract — meaning that anyone (which is to say, most depositors) holding svTokens or ibTokens in the farms cannot withdraw them right now. Notably, the attacker is locked out of those same funds as well.
The stolen assets were converted into approximately 625 ETH, bridged over to Ethereum mainnet, and then moved on to a separate wallet, where they have remained since.
The attacker's wallet, used across all three networks — Ethereum, Arbitrum, and Avalanche — is: 0x9cf71F2ff126B9743319B60d2D873F0E508810dc
Recent months have seen several projects get their stolen funds returned, and Steadefi may be counting on a similar outcome. That said, there's an important distinction worth noting: this wasn't a whitehat probing for smart-contract bugs, but an outright account compromise — a scenario that historically ends less amicably, particularly if state-sponsored actors of the kind rekt.news has previously covered turn out to be involved.

Still, the emergence of Arkham's public doxxing marketplace alongside Curve's own bounty offer suggests a new pattern of post-hack response may be taking shape. One self-styled bounty hunter connected to the Curve incident skipped the percentage-based offer entirely, instead threatening the hacker directly on-chain:
Hacker. I have your IP address. I give you until 08/10/23 8:00 AM UTC to return: 7,000,000 CRV and 7,000 WETH to this address: 0xC6a194f5F08352C6aD0B9Dcff1C7A5Ef9f8A7802. After this time I will reveal your IP address. This is your last chance to make the right choice.
An attempt to extort an extortionist — proof, perhaps, that there's no honor among thieves after all.
Get new scam files the moment we publish them — usually 2–3 emails a week.