Resolv exploit triggers USR depeg after $80M uncollateralized mint

ambcryptoPubblicato 2026-03-23Pubblicato ultima volta 2026-03-23

Introduzione

Resolv protocol was exploited due to a private key compromise, leading to an unauthorized mint of approximately $80M in unbacked USR stablecoins. This inflated the total supply by 71M tokens, causing a severe depeg—USR fell 56% to around $0.19. The team paused contracts, burned 9M of the attacker’s tokens, and confirmed that underlying collateral remains intact with only $0.5M in losses from redemptions. Recovery efforts include allowlisted redemptions and tracing illicit tokens. The incident highlights risks from over-reliance on off-chain controls in DeFi minting mechanisms.

Resolv has paused its protocol after a private key compromise enabled a malicious actor to mint approximately $80M in uncollateralized USR. This triggered a sharp depeg and raised concerns about the stablecoin’s integrity.

In an update shared, the team said the attacker gained unauthorized access to its infrastructure and minted new USR tokens without backing. Smart contracts were quickly paused, and around 9M USR held by the attacker has since been burned.

Resolv stated that its underlying collateral was not directly compromised. Also, the only confirmed loss so far is roughly $0.5M in redemptions processed before the pause.

Exploit inflates USR supply rather than draining funds

Unlike typical DeFi exploits that drain protocol funds, the Resolv incident centers on supply inflation.

Before the incident, around 102M USR was in circulation. Following the exploit, an additional ~71M USR was minted without collateral. This effectively diluted the backing of the stablecoin.

This pushed total supply far above the value of the protocol’s assets, altering the relationship between supply and collateral.

The team said the exploit resulted from a compromised private key tied to infrastructure access, rather than a failure of its underlying collateral system.

Design assumptions exposed in minting process

While Resolv attributed the breach to unauthorized access, the incident has drawn attention to how minting authority was structured.

The exploit was made possible because a privileged role could authorize token issuance without sufficient on-chain validation of collateral backing.

This meant that once access was obtained, large amounts of USR could be minted without checks tied to deposited assets.

Such architecture relies on trusted off-chain controls to enforce limits — an assumption that can break down if those controls are compromised.

USR loses peg as market confidence drops

Market reaction to the exploit was swift, with USR losing its dollar peg.

At the time of writing, USR was trading near $0.19, down more than 56% over 24 hours, according to CoinMarketCap data. The sharp decline reflects a repricing of the token as supply expanded beyond its collateral base.

Source: CoinMarketCap

Trading activity has also weakened significantly, with volumes dropping as users exit positions or avoid exposure during the recovery process.

Recovery efforts underway as redemptions planned

Resolv said it is preparing to enable redemptions for pre-incident USR holders, starting with allowlisted users.

The protocol currently holds approximately $141M in assets, and the team is working with partners, analytics firms, and law enforcement to trace and contain illicitly minted tokens.

Users have been advised not to trade USR or related assets during the recovery phase. Post-exploit activity could impact the outcome of the process.

Stablecoin integrity under scrutiny

The incident highlights a broader risk in DeFi systems where critical safeguards depend on off-chain controls rather than enforced on-chain limits.

Although Resolv’s collateral pool remains intact, the ability to mint unbacked tokens has undermined confidence in the system’s accounting.

As the situation unfolds, the key challenge will be restoring trust in USR’s backing and stabilizing its supply.


Final Summary

  • The Resolv exploit inflated USR supply by $80M without draining collateral, exposing risks tied to off-chain control mechanisms.
  • USR’s sharp depeg reflects a loss of market confidence, with recovery now dependent on isolating illicit supply and restoring backing integrity.

Crypto di tendenza

Domande pertinenti

QWhat was the primary method used by the attacker to exploit the Resolv protocol?

AThe attacker gained unauthorized access to Resolv's infrastructure through a compromised private key, which allowed them to mint approximately $80M in uncollateralized USR tokens.

QHow did the exploit mechanism in this incident differ from a typical DeFi attack?

AUnlike typical DeFi exploits that drain protocol funds, this incident centered on supply inflation by minting new, unbacked tokens rather than stealing existing collateral.

QWhat was the immediate market consequence of the exploit on the USR stablecoin?

AThe USR stablecoin lost its dollar peg, trading near $0.19 at the time of writing, which represents a decline of more than 56% over 24 hours.

QWhat key vulnerability in the protocol's design did this exploit expose?

AThe exploit exposed a vulnerability where a privileged role could authorize token issuance without sufficient on-chain validation of collateral backing, relying instead on trusted off-chain controls.

QWhat are the main steps Resolv is taking for recovery according to the article?

AResolv has paused the protocol, burned approximately 9M USR held by the attacker, is preparing to enable redemptions for pre-incident holders, and is working with partners and law enforcement to trace illicitly minted tokens.

Letture associate

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

Coldcard Hardware Wallet Hacked: Losses Mount Due to Vulnerable Seed Generation A critical vulnerability in Coldcard hardware wallets has led to a continued wave of fund thefts. According to Galaxy Research, the total stolen has reached 1,367.05 BTC (approx. $88.6 million) from 4,585 addresses, a significant increase from the initial 594.5 BTC reported on July 30, 2026. Most of the stolen funds remain on the attackers' addresses. The issue is not with the current firmware, which Coinkite has updated, but with seed phrases generated on vulnerable devices between March 2021 and the release of fixed firmware versions. Due to a programmer error, devices switched from using a hardware random number generator to the software-based Yasmarang generator, which was initialized with publicly accessible data like the chip's serial number. This made the seed phrases predictable through offline brute-force attacks, meaning wallets remain at risk until funds are moved to a new wallet generated with the patched firmware. Affected devices include Mk2/Mk3 with firmware 4.0.1–4.1.9 (and up to 5.0.3), Mk4/Mk5 up to version 5.6.0, and Q models up to 1.5.0Q. The only exceptions are seeds created with a high-entropy method like at least 50 independent dice rolls or a strong unique BIP-39 passphrase. All other owners must generate a new seed on the fixed firmware and transfer their assets. A case highlighting the human impact involves a 39-year-old long-term investor who lost 2 BTC (approx. $130,000) in minutes. He had accumulated the Bitcoin over eight years through physical labor, viewing it as a financial lifeline and a retirement plan in a country suffering from hyperinflation. His story underscores that even conservative "buy and hold in cold storage" strategies can be compromised by such underlying technical flaws. From a technical perspective, this incident echoes historical failures where weak random number generators undermined cryptographic security, challenging the assumption that offline storage is automatically foolproof.

cryptonews.ru1 h fa

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

cryptonews.ru1 h fa

Trading

Spot

Articoli Popolari

Come comprare RESOLV

Benvenuto in HTX.com! Abbiamo reso l'acquisto di Resolv (RESOLV) semplice e conveniente. Segui la nostra guida passo passo per intraprendere il tuo viaggio nel mondo delle criptovalute.Step 1: Crea il tuo Account HTXUsa la tua email o numero di telefono per registrarti il tuo account gratuito su HTX. Vivi un'esperienza facile e sblocca tutte le funzionalità,Crea il mio accountStep 2: Vai in Acquista crypto e seleziona il tuo metodo di pagamentoCarta di credito/debito: utilizza la tua Visa o Mastercard per acquistare immediatamente ResolvRESOLV.Bilancio: Usa i fondi dal bilancio del tuo account HTX per fare trading senza problemi.Terze parti: abbiamo aggiunto metodi di pagamento molto utilizzati come Google Pay e Apple Pay per maggiore comodità.P2P: Fai trading direttamente con altri utenti HTX.Over-the-Counter (OTC): Offriamo servizi su misura e tassi di cambio competitivi per i trader.Step 3: Conserva Resolv (RESOLV)Dopo aver acquistato Resolv (RESOLV), conserva nel tuo account HTX. In alternativa, puoi inviare tramite trasferimento blockchain o scambiare per altre criptovalute.Step 4: Scambia Resolv (RESOLV)Scambia facilmente Resolv (RESOLV) nel mercato spot di HTX. Accedi al tuo account, seleziona la tua coppia di trading, esegui le tue operazioni e monitora in tempo reale. Offriamo un'esperienza user-friendly sia per chi ha appena iniziato che per i trader più esperti.

273 Totale visualizzazioniPubblicato il 2025.06.11Aggiornato il 2026.06.02

Come comprare RESOLV

Discussioni

Benvenuto nella Community HTX. Qui puoi rimanere informato sugli ultimi sviluppi della piattaforma e accedere ad approfondimenti esperti sul mercato. Le opinioni degli utenti sul prezzo di RESOLV RESOLV sono presentate come di seguito.

活动图片