Eksploit Resolv picu depeg USR setelah cetak $80 juta tanpa jaminan

ambcryptoPublished on 2026-03-23Last updated on 2026-03-23

Abstract

Eksploitasi Resolv memicu depeg USR setelah pelaku jahat mencetak $80 juta USR tanpa jaminan. Protokol ini dijeda karena kompromi kunci pribadi yang memungkinkan pencetakan token tidak sah, mengakibatkan inflasi pasokan dan penurunan kepercayaan pasar. USR kehilangan peg-nya, turun 56% menjadi sekitar $0.19. Tim Resolv membakar 9 juta USR milik penyerang dan menyatakan hanya $0.5 juta yang hilang dari penebusan sebelum jeda. Aset jaminan senilai $141 juta tetap utuh. Pemulihan fokus pada isolasi pasokan ilegal dan memulihkan integritas jaminan, menekankan risiko ketergantungan pada kontrol off-chain dalam sistem DeFi.

Resolv telah menjeda protokolnya setelah kompromi kunci pribadi memungkinkan pelaku jahat mencetak sekitar $80 juta USR tanpa jaminan. Ini memicu depeg tajam dan menimbulkan kekhawatiran tentang integritas stablecoin tersebut.

Dalam pembaruan yang dibagikan, tim mengatakan penyerang mendapatkan akses tidak sah ke infrastrukturnya dan mencetak token USR baru tanpa jaminan. Kontrak pintar segera dijeda, dan sekitar 9 juta USR yang dipegang penyerang sejak itu telah dibakar.

Resolv menyatakan bahwa jaminan dasarnya tidak langsung dikompromikan. Juga, satu-satunya kerugian yang dikonfirmasi sejauh ini adalah sekitar $0,5 juta dalam penebusan yang diproses sebelum jeda.

Eksploit menggelembungkan pasokan USR alih-alih menguras dana

Tidak seperti eksploit DeFi biasa yang menguras dana protokol, insiden Resolv berpusat pada inflasi pasokan.

Sebelum insiden, sekitar 102 juta USR beredar. Setelah eksploit, tambahan ~71 juta USR dicetak tanpa jaminan. Ini efektif mengencerkan pendukung stablecoin.

Ini mendorong total pasokan jauh di atas nilai aset protokol, mengubah hubungan antara pasokan dan jaminan.

Tim mengatakan eksploit diakibatkan oleh kunci pribadi yang dikompromikan terkait akses infrastruktur, bukan kegagalan sistem jaminan dasarnya.

Asumsi desain terbongkar dalam proses pencetakan

Sementara Resolv menyatakan pelanggaran karena akses tidak sah, insiden ini menarik perhatian pada bagaimana otoritas pencetakan disusun.

Eksploit dimungkinkan karena peran istimewa dapat mengotorisasi penerbitan token tanpa validasi on-chain yang cukup untuk jaminan pendukung.

Ini berarti begitu akses diperoleh, sejumlah besar USR dapat dicetak tanpa pemeriksaan terkait aset yang didepositkan.

Arsitektur seperti itu mengandalkan kontrol off-chain tepercaya untuk menegakkan batas — asumsi yang bisa gagal jika kontrol tersebut dikompromikan.

USR kehilangan peg saat kepercayaan pasar turun

Reaksi pasar terhadap eksploit cepat, dengan USR kehilangan peg dolarnya.

Pada saat penulisan, USR diperdagangkan mendekati $0,19, turun lebih dari 56% dalam 24 jam, menurut data CoinMarketCap. Penurunan tajam ini mencerminkan penetapan harga ulang token saat pasokan meluas melampaui basis jaminannya.

Sumber: CoinMarketCap

Aktivitas perdagangan juga melemah signifikan, dengan volume turun saat pengguna keluar dari posisi atau menghindari eksposur selama proses pemulihan.

Upaya pemulihan berlangsung saat penebusan direncanakan

Resolv mengatakan sedang mempersiapkan untuk mengaktifkan penebusan untuk pemegang USR pra-insiden, dimulai dengan pengguna yang diizinkan.

Protokol saat ini memegang sekitar $141 juta dalam aset, dan tim bekerja dengan mitra, firma analitik, dan penegak hukum untuk melacak dan menahan token yang dicetak secara tidak sah.

Pengguna disarankan untuk tidak memperdagangkan USR atau aset terkait selama fase pemulihan. Aktivitas pasca-eksploit dapat memengaruhi hasil proses.

Integritas Stablecoin di bawah pengawasan

Insiden ini menyoroti risiko lebih luas dalam sistem DeFi di mana pengamanan kritis bergantung pada kontrol off-chain daripada batas yang ditegakkan on-chain.

Meskipun kolateral Resolv tetap utuh, kemampuan untuk mencetak token tanpa jaminan telah merusak kepercayaan pada akuntansi sistem.

Seiring situasi berkembang, tantangan utama adalah memulihkan kepercayaan pada jaminan USR dan menstabilkan pasokannya.


Ringkasan Akhir

  • Eksploit Resolv menggelembungkan pasokan USR sebesar $80 juta tanpa menguras jaminan, mengekspos risiko terkait mekanisme kontrol off-chain.
  • Depeg tajam USR mencerminkan hilangnya kepercayaan pasar, dengan pemulihan sekarang bergantung pada mengisolasi pasokan tidak sah dan memulihkan integritas jaminan.

Related Questions

QApa yang menyebabkan eksploitasi pada protokol Resolv?

AEksploitasi terjadi karena kompromi kunci pribadi yang memberikan akses tidak sah ke infrastruktur protokol, memungkinkan pelaku jahat mencetak sekitar $80 juta USR tanpa jaminan kolateral.

QBagaimana dampak eksploitasi terhadap nilai tukar USR?

AUSR kehilangan peg terhadap dolar dan mengalami depeg tajam, diperdagangkan sekitar $0.19 atau turun lebih dari 56% dalam 24 jam karena kepercayaan pasar menurun.

QApa perbedaan utama eksploitasi ini dibanding serangan DeFi pada umumnya?

ABerbeda dengan serangan yang biasanya menguras dana protokol, eksploitasi ini memicu inflasi pasokan dengan mencetak token USR baru tanpa kolateral, mengencerkan nilai jaminannya.

QApa upaya pemulihan yang dilakukan tim Resolv?

ATim membakar 9 juta USR milik penyerang, mempersiapkan proses penebusan untuk pemegang USR pra-kejadian, dan berkolaborasi dengan pihak penegak hukum untuk melacak token yang dicetak secara ilegal.

QApa kelemahan desain yang terungkap dari insiden ini?

ADesain protokol mengandalkan kontrol off-chain yang terpercaya untuk otorisasi pencetakan token, tanpa validasi on-chain yang memadai untuk memastikan jaminan kolateral, sehingga rentan jika kontrol tersebut disusupi.

Related Reads

Dalio's Latest Warning: Don't Get Carried Away by AI, Real Returns on US Stocks in the Next 5-10 Years Could Be -5% to -10%

Ray Dalio, founder of Bridgewater Associates, warns investors against excessive concentration in AI stocks. He argues the current market, dominated by a few AI giants, mirrors historical patterns where revolutionary new technologies lead to high risk, volatility, and uncertainty. While acknowledging AI's transformative potential, Dalio emphasizes that most investors fail at this stage of the cycle by over-concentrating in a handful of leading companies. He cites inherent risks: companies cannot accurately forecast investment needs or external shocks (e.g., monetary policy, geopolitics, taxes), face potential disruption from future technologies and international competition (notably from China), and experience significant price swings. Dalio's core advice is diversification, calling it his "Holy Grail of Investing." He presents a mathematical case that a well-diversified portfolio of 15-20 uncorrelated, good bets offers a superior risk-adjusted return compared to a concentrated position. Dalio also offers a cautious outlook, suggesting U.S. stocks may deliver real returns of -5% to -10% over the next 5-10 years based on valuation and bubble indicators. He concludes that in the face of high uncertainty, the prudent strategy is not to avoid betting entirely, but to avoid large, concentrated bets where one lacks sufficient informational edge. Instead, investors should build a strategically balanced, diversified portfolio.

marsbit49m ago

Dalio's Latest Warning: Don't Get Carried Away by AI, Real Returns on US Stocks in the Next 5-10 Years Could Be -5% to -10%

marsbit49m ago

Rain Valuation Approaches $20 Billion: The Battle for U-Cards Extends to Rewards Systems

Rain, a stablecoin payments infrastructure company, is shifting the competitive focus for U Cards from simple issuance to user retention and repeated usage. On June 15, Rain launched "Rain Rewards," an embedded loyalty program capability within its card-issuing infrastructure. This allows partner businesses—like fintech platforms and neobanks—to configure branded loyalty points, earning rules, redemptions, and merchant promotions directly within their card products. The system, built from the 2025 acquisition of Uptop, ensures points are only issued upon final transaction settlement, preventing liabilities from refunds. Trials, such as with Avalanche Card, reportedly boosted spending by 25% among enrolled users. Founded by Farooq Malik and Charles Yoo-Naut, Rain evolved from a tool for managing Web3 company expenses into a full-stack enterprise platform. It is a Principal Member of Visa and Mastercard, enabling partners to issue stablecoin-backed cards and wallets while leveraging traditional payment networks. Notably, the popular U Card Plasma One is issued by Rain under Visa's authority. Rain also integrates with Visa's stablecoin settlement pilot, using USDC for network settlement. Rain's rapid funding reflects growing institutional interest in stablecoin payment infrastructure. It raised a $245 million Series A in March 2025, a $58 million Series B in August 2025, and a $250 million Series C in January of this year, reaching a $19.5 billion valuation. Annualized transaction volume exceeds $3 billion, serving over 200 partners including Western Union and Nuvei. Beyond cards, Rain is expanding into programmable payments. Its June 2026 "Agent Control Layer" allows businesses to set spending rules—like merchant categories, amounts, and frequency—for AI agents before transactions occur. This positions Rain not as a single product but as an operating system for stablecoin payments, handling everything from card issuance and wallet management to rewards, on/off-ramps, and automated compliance. The goal is to enable seamless, often invisible, real-world spending of on-chain assets.

Foresight News53m ago

Rain Valuation Approaches $20 Billion: The Battle for U-Cards Extends to Rewards Systems

Foresight News53m ago

Google TPU Shipments Revised Up by 50%

Recent industry research indicates a significant upward revision in the shipments of Google's TPU (Tensor Processing Unit) chips. Previous expectations for 2027 were set at around 10 million units, but new estimates now point to 15 million units, a 50% increase. This substantial boost directly translates to higher demand across the entire supporting supply chain. Google's TPU clusters utilize a standardized all-optical interconnect architecture. Consequently, key hardware components are deeply integrated and scaled in fixed ratios with the chips. The 15 million TPU target will drive corresponding demand increases for NPO optical engines (roughly a 1:1 match), 1.6T optical modules, OCS optical switches, high-end server power supplies, fiber optics & MPO connectors, and liquid cooling solutions. Among these, liquid cooling is highlighted as the sector experiencing the most significant transformation and offering the most stable potential for excess returns. As next-generation TPU chips reach power levels where traditional air cooling is insufficient, liquid cooling becomes essential. 2026 is forecasted as the first year of substantial adoption for Google's liquid cooling solutions. This shift, coupled with delivery and capacity bottlenecks faced by incumbent overseas manufacturers, is creating a prime window for domestic Chinese suppliers to enter and secure Google's core supply chain. The market size for Google-specific liquid cooling is projected to potentially triple from a baseline of hundreds of billions to around 300 billion units by 2028. The logic for the fiber optic sector is also being rewritten. Once considered a cyclical commodity tied to telecom operator procurement, fiber is now a strategic and scarce resource for AI Data Centers (AIDC). A severe supply-demand imbalance, driven by the long lead time for preform production (18-24 months) and surging demand from cloud giants, is supporting strong performance. Chinese fiber manufacturers are well-positioned to capture a significant share of global AIDC demand, with exports potentially reaching 200-300 million core kilometers in 2026. Overall, the investment focus within the AI computing industry is shifting from pure "chip performance speculation" towards the more certain incremental growth in computing infrastructure and its supporting ecosystem. The upward revision in Google TPU shipments, along with the potential for further doubling by 2028, is seen as solidifying performance visibility for the entire supporting supply chain over the next two years.

marsbit2h ago

Google TPU Shipments Revised Up by 50%

marsbit2h ago

Trading

Spot
Futures

Hot Articles

How to Buy RESOLV

Welcome to HTX.com! We've made purchasing Resolv (RESOLV) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy Resolv (RESOLV) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your Resolv (RESOLV)After purchasing your Resolv (RESOLV), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade Resolv (RESOLV)Easily trade Resolv (RESOLV) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

4.7k Total ViewsPublished 2025.06.11Updated 2026.06.02

How to Buy RESOLV

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of RESOLV (RESOLV) are presented below.

活动图片