Besides the Resolv Hack, This Type of DeFi Vulnerability Has Occurred Four Times Already

marsbitDipublikasikan tanggal 2026-03-24Terakhir diperbarui pada 2026-03-24

Abstrak

An attacker exploited a compromised off-chain signing key in the stablecoin protocol Resolv, minting 80 million USR tokens (pegged to USD) from a $100k–$200k USDC deposit within minutes. The stolen keys allowed unlimited minting due to a design flaw—lacking a minting cap—despite multiple audits. The attacker then converted USR to its wrapped version (wstUSR) and dumped it on DEXs, netting ~11,400 ETH (~$24M). This caused USR to depeg, trading at ~$0.25. The depeg triggered a second-phase crisis: lending markets (including Morpho and Fluid/Instadapp) using wstUSR as collateral relied on hardcoded oracles that priced it near $1 instead of its real market value. Arbitrageurs bought cheap wstUSR, used it as overvalued collateral to borrow stablecoins, and amplified losses. Fluid absorbed over $10M in bad debt; Morpho had 15 vaults exposed. This incident repeats a known DeFi pattern: similar oracle failures occurred with Usual Protocol (Jan 2025), Stream Finance (Nov 2025), and Moonwell (late 2025), where mispriced collateral led to massive bad debt. Critics highlight flawed incentives in the "curator" model (e.g., Gauntlet), where third-party vault managers prioritize high yields without adequate risk controls, and protocols outsource risk management without enforcing safeguards. The root cause is systemic: over-reliance on static oracles for volatile assets and insecure off-chain infrastructure.

On a quiet Sunday morning, someone turned $100,000 into $25 million in about 17 minutes.

The target was the yield-bearing stablecoin protocol Resolv. Before Resolv paused its contracts, its dollar-pegged stablecoin, USR, had fallen to a few cents. As of this writing, USR remains severely depegged, trading at around $0.25, down more than 70% this week.

The shockwaves extended far beyond Resolv itself. Fluid/Instadapp absorbed over $10 million in bad debt in a single day, experiencing a net outflow of over $300 million on the same day, a record single-day outflow in its history. 15 Morpho vaults were affected. Euler, Venus, Lista DAO, and Inverse Finance all subsequently suspended USR-related markets.

The mechanism that allowed this vulnerability's losses to spread—pricing a depegged stablecoin at $1 in lending markets—is not new. This has happened at least four times in the past 14 months.

How the Vulnerability Worked

USR minting followed a two-step off-chain process: Users deposited USDC via the `requestSwap` function, and a privileged off-chain signing key, `SERVICE_ROLE`, would then finalize the amount of USR to be issued via `completeSwap`.

The contract had a minimum output limit but no maximum limit. The contract executed whatever the key holder signed.

The attacker gained access to this key through Resolv's AWS Key Management Service. They submitted two USDC deposits totaling approximately $100,000 to $200,000, then used the stolen key to authorize the minting of 80 million USR in return. On-chain data shows two transactions of 50 million USR and 30 million USR, both completed within minutes.

"The Resolv USR exploit wasn't a bug—it was a feature operating as designed. That's the problem," said on-chain analyst Vadim (@zacodil).

The SERVICE_ROLE was a regular external owned address (EOA), not a multi-signature wallet. The admin key had multi-sig protection, but the minting key did not.

"Resolv underwent 18 audits," Vadim said, "One of the findings was literally named 'Missing Cap'."

The attacker exited: They first converted the minted USR to wstUSR (a staked wrapped version) to slow the market impact, then swapped it for ETH via Curve, Uniswap, and KyberSwap. The attacker's wallet holds approximately 11,400 ETH (around $24 million). The underlying ETH and BTC collateral pools supporting the entire system remained intact as the stablecoin collapsed.

How the Contagion Spread

The Resolv exploit was effectively two events stacked on top of each other. The first was the minting exploit, the second was the failure of connected lending markets.

When USR and wstUSR crashed, every lending market that accepted them as collateral faced the same problem: their oracles were still pricing wstUSR at close to $1.

Omer Goldberg, founder of risk analysis firm Chaos Labs, documented this mechanism. His key finding: "The oracle was hardcoded, so it never repriced. wstUSR was marked at $1.13, while trading on secondary markets for around $0.63."

Traders bought wstUSR cheaply on the open market, then used it as collateral on Morpho or Fluid at the oracle price of $1.13, borrowing USDC against it and walking away.

At Fluid, the team secured short-term loans to cover 100% of the bad debt and promised to make every user whole. At Morpho, co-founder Paul Frambot stated that about 15 vaults had significant exposure, all in high-risk, long-tail collateral strategies.

Prominent curator Gauntlet stated that "a few high-yield vaults had limited exposure."

But D2 Finance directly countered this, publishing on-chain data showing Gauntlet's flagship "USDC Core Vault" had allocated $4.95 million to the wstUSR/USDC market. Goldberg later stated that Gauntlet vaults constituted 98% of the lender liquidity in that market.

Frambot said in a written response to The Defiant: "We are constantly working on how to present various risks more comprehensively. However, we don't believe the core issue here is a lack of labeling."

Frambot added: "Morpho is oracle-agnostic, meaning it allows curators to choose any oracle they deem most suitable for a specific market. Morpho is open, permissionless infrastructure designed to outsource risk management to curators."

"It's difficult to enforce objectively 'correct' guardrails in all scenarios," Frambot said, "Imposing constraints at the protocol level also risks hindering legitimate strategies."

While the underlying protocol leaves risk management to curators, some in the industry believe the curators are not fulfilling their duty.

"I believe the curator industry is flawed by design because there is no real curation happening," Marc Zeller said on X.

At the time of publication, Resolv, Gauntlet, and Fluid had not responded to The Defiant's requests for comment.

A Recurring Failure Pattern

This is not a new type of attack. In January 2025, Usual Protocol's USD0++ was hardcoded at $1 by curator MEV Capital in a Morpho vault.

Usual then abruptly adjusted its redemption floor price to $0.87 without warning, locking lenders into the MEV Capital vault, whose utilization rate soared to 100%.

In November 2025, Stream Finance's xUSD collapsed after curators had routed USDC deposits into leverage loops backed by the synthetic stablecoin. When its oracle refused to update, an estimated $285 million to $700 million in assets were at risk on Morpho, Euler, and Silo.

Moonwell suffered two consecutive oracle failures in October and November 2025, resulting in over $5 million in bad debt combined.

What This Means for the Curator Model

Morpho's architecture outsources all risk decisions to third-party "curators," who build vaults, select collateral, set loan-to-value ratios, and choose oracles. The theory is that professional firms have deeper expertise, and competition leads to better risk management, with the protocol enforcing the rules.

But curators earn fees based on the yield generated, creating an incentive to accept higher-risk, higher-yielding collateral (like yield-bearing stablecoins). The problem is that when these stablecoins depeg, the losses are borne by the depositors, not the curators.

In the Resolv incident, some curators' automated bots continued pumping funds into the affected vaults for hours after the exploit, deepening the losses.

The reason for using hardcoded oracles for yield-bearing stablecoins is to prevent unnecessary liquidations triggered by short-term volatility. But this protection only works if the stablecoin remains stable.

On-chain analytics firm Chainalysis stated in a post-mortem that real-time on-chain detection capabilities are needed.

"The on-chain smart contracts were functioning perfectly. The issue clearly lay with the broader system design and off-chain infrastructure," the analytics firm said.

Kripto yang Sedang Tren

Pertanyaan Terkait

QWhat was the core mechanism that allowed the Resolv exploit to cause widespread contagion across multiple DeFi lending markets?

AThe core mechanism was that the oracles in the lending markets continued to price the depegged stablecoin, wstUSR, at or near its intended $1 peg value, even after it had collapsed in value on the open market. This allowed attackers to buy the cheap stablecoin and use it as overvalued collateral to borrow other assets.

QHow did the attacker initially obtain the ability to mint a massive amount of USR tokens?

AThe attacker gained access to the `SERVICE_ROLE` signing key, which was an external private key (not a multi-sig) used to authorize the `completeSwap` function. This access was obtained through a compromise of Resolv's AWS Key Management Service.

QAccording to the article, this type of vulnerability has occurred at least four times in the past 14 months. Name one other protocols mentioned that suffered from a similar oracle pricing failure.

AThe article mentions that a similar failure occurred with Usual Protocol's USD0++ in January 2025 and with Stream Finance's xUSD in November 2025.

QWhat is the fundamental criticism of the 'curator model' used by protocols like Morpho, as highlighted by the Resolv incident?

AThe fundamental criticism is that the incentives for curators are misaligned. Curators earn fees based on the yield their vaults generate, which incentivizes them to accept higher-risk, higher-yielding collateral (like yield-bearing stablecoins). However, when those assets depeg and cause losses, the losses are borne by the depositors/lenders, not the curators.

QWhat did the post-incident analysis from Chainalysis identify as the root of the problem, rather than a smart contract bug?

AChainalysis stated that the problem was not a smart contract bug, as the contracts were 'functioning exactly as designed.' They identified the root of the problem as 'broader system design and off-chain infrastructure.'

Bacaan Terkait

Memberi "Noise" ke AI Juga Bisa Meningkatkan Skor, Karya Ini Membuat Noise Mencapai Transfer Positif

Dalam bidang transfer learning, sumber data biasanya berupa gambar, teks, atau audio. Namun, penelitian "Semi-Supervised Noise Adaptation (SSNA)" menunjukkan bahwa **noise acak yang tidak memiliki makna semantik**—dihasilkan dari distribusi Gaussian—juga dapat meningkatkan performa model dalam skenario semi-supervised dengan sedikit data berlabel. Metode ini menggunakan **Kerangka Adaptasi Noise (Noise Adaptation Framework, NAF)**. NAF membuat struktur kategori diskriminatif dalam domain noise acak, lalu mentransfer **struktur** ini ke data target nyata untuk memberikan batas klasifikasi yang lebih jelas. Model memproyeksikan domain noise dan target ke ruang representasi bersama dan menyelaraskannya pada tingkat kategori. Dalam eksperimen, dengan hanya 4 sampel berlabel per kelas, NAF meningkatkan akurasi secara signifikan dibandingkan baseline ERM pada dataset seperti CIFAR-10 (+12.35%), CIFAR-100 (+7.61%), dan lainnya. Peningkatan juga terlihat pada dataset skala besar seperti ImageNet-1K dan tugas klasifikasi teks. Kunci keberhasilan ini bukanlah sifat acak noise itu sendiri, melainkan **struktur kategori yang dapat dipisahkan** yang dibentuknya dalam ruang representasi. Eksperimen ablasi menunjukkan bahwa jika semua noise dikompresi menjadi satu titik (tanpa struktur), kinerja justru menurun drastis. Sebaliknya, memperlebar jarak antara pusat kategori noise meningkatkan akurasi. Penelitian ini menawarkan perspektif baru: dalam transfer learning, pengetahuan yang dapat ditransfer bisa berupa **cara data diorganisasikan dalam ruang representasi**, bukan hanya konten semantiknya. Ini membuka kemungkinan untuk skenario di mana data sumber asli tidak tersedia karena masalah privasi, hak cipta, atau keterbatasan akses. Noise sintetis dapat menjadi alternatif sumber daya yang efektif dan rendah biaya.

marsbit1m yang lalu

Memberi "Noise" ke AI Juga Bisa Meningkatkan Skor, Karya Ini Membuat Noise Mencapai Transfer Positif

marsbit1m yang lalu

Operator Teleprompter "Khusus" Gedung Putih Raup Lebih dari $100.000 dengan Prediksi Berbasis Informasi Orang Dalam

Artikel berjudul "Operator Teleprompter Gedung Putih Dapatkan Lebih dari $100.000 dengan Informasi Orang Dalam" mengungkap kasus insider trading di pasar prediksi oleh Gabriel Perez, asisten teknis dan operator teleprompter untuk mantan Presiden AS Donald Trump. Perez, yang memiliki akses ke naskah pidato Trump sebelum disampaikan, menggunakan informasi orang dalam ini untuk bertaruh pada kata-kata spesifik yang akan disebutkan Trump dalam berbagai pidato di platform prediksi Kalshi. Dalam sekitar tiga bulan, ia mendapat untung lebih dari $100.000. Namun, platform Kalshi mendeteksi aktivitas mencurigakan, membekukan dana sekitar $90.000, dan melaporkannya ke CFTC. Akibatnya, Perez diberhentikan sementara tanpa gaji oleh Trump. Meski mengembalikan keuntungan dan berjanji tidak mengulangi pelanggaran, ia tidak menghadapi tuntutan pidana karena dianggap tidak membocorkan informasi rahasia negara. Kasus ini menyoroti kerentanan pasar prediksi "sebutan" terhadap manipulasi, di mana orang dalam atau pembicara sendiri dapat dengan mudah mempengaruhi hasil. Insiden serupa sebelumnya melibatkan tentara dan insinyur Google. Sebagai tanggapan, platform seperti Kalshi mulai memperketat aturan, termasuk mengharuskan pengguna mengungkapkan tempat kerja. Artikel menyimpulkan bahwa meskipun pembersihan perdagangan orang dalam membuat pasar prediksi lebih patuh, hal itu juga menjauhkannya dari tujuan awalnya sebagai pengejawantahan kebijaksanaan kolektif, menjadikannya lebih mirip kasino biasa.

marsbit1j yang lalu

Operator Teleprompter "Khusus" Gedung Putih Raup Lebih dari $100.000 dengan Prediksi Berbasis Informasi Orang Dalam

marsbit1j yang lalu

Operator Teleprompter "Khusus" Gedung Putih, Meraup Lebih dari 100 Ribu Dolar AS dengan Prediksi Menggunakan Informasi Orang Dalam

Sebuah staf Gedung Putih yang bertugas mengoperasikan teleprompter (penyusun teks pidato) untuk mantan Presiden AS Donald Trump, Gabriel Perez, telah diduga melakukan perdagangan orang dalam (insider trading) di pasar prediksi. Perez, yang memiliki akses ke naskah pidato Trump sebelum disampaikan, dilaporkan memanfaatkan informasi non-publik tersebut untuk bertaruh pada kata-kata spesifik yang akan disebutkan Trump dalam berbagai pidatonya di platform prediksi Kalshi. Dalam kurun waktu sekitar tiga bulan, ia dikabarkan memperoleh keuntungan lebih dari $100,000. Kalshi kemudian mendeteksi aktivitas transaksi yang tidak biasa dan membekukan lebih dari $90,000 di akun Perez sebelum melaporkan kasus ini kepada Commodity Futures Trading Commission (CFTC). Atas insiden tersebut, Perez diberhentikan sementara dari tugasnya tanpa gaji oleh Trump. Berbeda dengan dua kasus insider trading sebelumnya di pasar prediksi yang melibatkan seorang tentara dan insinyur Google, Perez tidak menghadapi tuntutan pidana. CFTC dikabarkan sedang dalam proses penyelesaian damai yang mewajibkannya mengembalikan keuntungannya dan berhenti melakukan transaksi serupa. Kasus ini menyoroti kerentanan pasar prediksi "sebutan" (mention markets) terhadap manipulasi, di mana individu dengan informasi orang dalam atau bahkan pembicara itu sendiri dapat dengan mudah memengaruhi hasilnya. Beberapa contoh, seperti CEO Coinbase yang dengan sengaja menyebut semua opsi taruhan dalam sebuah konferensi, mengilustrasikan masalah ini. Menanggapi hal tersebut, Kalshi telah memperketat kebijakan dengan mewajibkan pengguna mengungkapkan tempat kerja mereka untuk mencegah penyalahgunaan informasi orang dalam. Insiden Perez menandai langkah lain dalam pembersihan perdagangan orang dalam di industri pasar prediksi, sekaligus mempertanyakan keandalan pasar tersebut sebagai cerminan kebijaksanaan kolektif.

Odaily星球日报1j yang lalu

Operator Teleprompter "Khusus" Gedung Putih, Meraup Lebih dari 100 Ribu Dolar AS dengan Prediksi Menggunakan Informasi Orang Dalam

Odaily星球日报1j yang lalu

Tambang Bitcoin Berubah Menjadi Pabrik AI

Tambang Bitcoin Berubah Menjadi Pabrik AI Di Texas, AS, proyek kampus besar pertama OpenAI "Stargate" dibangun di atas lahan bekas penambangan Bitcoin oleh Crusoe, perusahaan yang awalnya memanfaatkan gas alam terbuang untuk menambang kripto. Ini mencerminkan tren transformasi besar: infrastruktur dan sumber daya dari era Crypto kini dialirkan ke industri AI. Pilar utama transformasi ini adalah: 1. **Tambang ke Pusat Data AI:** Perusahaan penambangan seperti Bitdeer, CoreWeave (dulunya Atlantic Crypto), TeraWulf, dan Hut 8 menjual atau mengalihkan kapasitas pusat data mereka yang sudah memiliki akses listrik, lahan, dan izin ke perusahaan AI seperti Anthropic dan AWS. Kontrak jangka panjang bernilai miliaran dolar ini lebih menguntungkan dibandingkan pendapatan menambang Bitcoin yang menurun. 2. **Talenta Crypto ke Startup AI:** Mantan eksekutif dan insinyur Crypto membawa keahlian mereka ke bidang AI. Contohnya, Alex Atallah (co-founder OpenSea) mendirikan OpenRouter, sebuah platform agregator untuk ratusan model AI. Burkay Gur (eks Coinbase) mendirikan Fal.ai, infrastruktur untuk inferensi media generatif. 3. **Modal Crypto Mendanai AI:** Kekayaan yang terakumulasi dari pasar Crypto digunakan untuk membiayai ekosistem AI. Jed McCaleb (pendiri Ripple/Stellar) mendanai Voltage Park, penyewa GPU skala besar. Venture capital Crypto seperti Paradigm berinvestasi dalam startup AI seperti Nous Research (pengembang model Hermes). Bahkan investasi awal SBF (FTX) di Anthropic dan Anysphere (penghasil Cursor) menunjukkan aliran modal ini. Intinya, industri Crypto tidak menghilang, tetapi aset-aset berharganya—infrastruktur listrik/pusat data, talenta teknis, dan modal—ditempatkan kembali untuk membangun fondasi industri AI berikutnya.

链捕手1j yang lalu

Tambang Bitcoin Berubah Menjadi Pabrik AI

链捕手1j yang lalu

Trading

Spot

Artikel Populer

Cara Membeli RESOLV

Selamat datang di HTX.com! Kami telah membuat pembelian Resolv (RESOLV) menjadi mudah dan nyaman. Ikuti panduan langkah demi langkah kami untuk memulai perjalanan kripto Anda.Langkah 1: Buat Akun HTX AndaGunakan alamat email atau nomor ponsel Anda untuk mendaftar akun gratis di HTX. Rasakan perjalanan pendaftaran yang mudah dan buka semua fitur.Dapatkan Akun SayaLangkah 2: Buka Beli Kripto, lalu Pilih Metode Pembayaran AndaKartu Kredit/Debit: Gunakan Visa atau Mastercard Anda untuk membeli Resolv (RESOLV) secara instan.Saldo: Gunakan dana dari saldo akun HTX Anda untuk melakukan trading dengan lancar.Pihak Ketiga: Kami telah menambahkan metode pembayaran populer seperti Google Pay dan Apple Pay untuk meningkatkan kenyamanan.P2P: Lakukan trading langsung dengan pengguna lain di HTX.Over-the-Counter (OTC): Kami menawarkan layanan yang dibuat khusus dan kurs yang kompetitif bagi para trader.Langkah 3: Simpan Resolv (RESOLV) AndaSetelah melakukan pembelian, simpan Resolv (RESOLV) di akun HTX Anda. Selain itu, Anda dapat mengirimkannya ke tempat lain melalui transfer blockchain atau menggunakannya untuk memperdagangkan mata uang kripto lainnya.Langkah 4: Lakukan trading Resolv (RESOLV)Lakukan trading Resolv (RESOLV) dengan mudah di pasar spot HTX. Cukup akses akun Anda, pilih pasangan perdagangan, jalankan trading, lalu pantau secara real-time. Kami menawarkan pengalaman yang ramah pengguna baik untuk pemula maupun trader berpengalaman.

460 Total TayanganDipublikasikan pada 2025.06.11Diperbarui pada 2026.06.02

Cara Membeli RESOLV

Diskusi

Selamat datang di Komunitas HTX. Di sini, Anda bisa terus mendapatkan informasi terbaru tentang perkembangan platform terkini dan mendapatkan akses ke wawasan pasar profesional. Pendapat pengguna mengenai harga RESOLV (RESOLV) disajikan di bawah ini.

活动图片