Turning 200,000 into Nearly 100 Million: DeFi Stablecoin Attacked Again

marsbitОпубликовано 2026-03-22Обновлено 2026-03-22

Введение

DeFi stablecoin protocol Resolv Labs was exploited, resulting in a hacker minting 80 million USR tokens using only 200,000 USDC. The attacker’s address (starting with 0x04A2) first created 50 million USR with 100,000 USDC, and later minted another 30 million with an additional 100,000 USDC. This caused USR to depeg, dropping to around $0.25 before partially recovering to approximately $0.80. The incident also impacted related lending markets on Morpho and Lista DAO, which paused new borrowing requests. Additionally, RLP token holders, including Stream Finance—which holds over 13 million RLP tokens—face significant exposure, with estimated losses around $17 million. Initial analysis by DeFi community YAM suggests the exploit occurred because the protocol’s SERVICE_ROLE, which provides minting parameters, was compromised. The system fully trusted this role’s input without on-chain verification or minting limits, allowing the attacker to manipulate the mint amount. The project’s emergency response was also slow, taking nearly three hours to pause the protocol due to multi-signature delays. This attack highlights critical vulnerabilities in off-chain role trust and emergency mechanisms within DeFi protocols.

Written by: Eric, Foresight News

At approximately 10:21 Beijing time today, Resolv Labs, which issues the stablecoin USR using a Delta neutral strategy, was hacked. An address starting with 0x04A2 used 100,000 USDC to mint 50 million USR from the Resolv Labs protocol.

As the incident was exposed, USR plummeted to around $0.25, and as of writing, it has recovered to approximately $0.80. The price of the RESOLV token also saw a short-term drop of nearly 10%.

Subsequently, the hacker repeated the same method, using another 100,000 USDC to mint 30 million USR. As USR significantly depegged, arbitrage traders quickly took action. Many lending markets on Morpho that supported USR, wstUSR, and others as collateral were almost drained, and Lista DAO on BNB Chain also suspended new borrowing requests.

The impact was not limited to these lending protocols. In the Resolv Labs protocol design, users can also mint an RLP token, which has greater price volatility and higher returns but requires bearing compensation liability when the protocol incurs losses. Currently, the circulating supply of RLP tokens is nearly 30 million, with the largest holder, Stream Finance, holding over 13 million RLP, representing a net risk exposure of approximately $17 million.

Yes, Stream Finance, which was previously hit by the xUSD incident, may be hit again.

As of writing, the hacker has converted USR into USDC and USDT and continues to buy Ethereum, having purchased over 10,000 ETH so far. Using 200,000 USDC, the hacker extracted over $20 million in assets, finding their "hundred-fold coin" during the bear market.

Another Exploit Due to "Lack of Rigor"

The sharp drop on October 11 last year caused collateral losses for many stablecoins issued using Delta neutral strategies due to ADL (Auto-Deleveraging). Projects using altcoins as assets for strategy execution suffered even more severe losses, with some even directly absconding.

The attacked Resolv Labs also uses a similar mechanism to issue USR. The project announced in April 2025 that it had completed a $10 million seed round led by Cyber.Fund and Maven11, with participation from Coinbase Ventures, and launched the RESOLV token at the end of May/early June.

However, the reason for the attack on Resolv Labs was not extreme market conditions but rather a "lack of rigor" in the design of the USR minting mechanism.

No security firm or official has yet analyzed the cause of this hack. The DeFi community YAM preliminarily concluded through analysis that the attack was likely caused by the SERVICE_ROLE, used by the protocol's backend to provide parameters to the minting contract, being compromised by the hacker.

According to Grok's analysis, when a user mints USR, they initiate a request on-chain and call the contract's requestMint function, with parameters including:

_depositTokenAddress: the address of the deposited token;

_amount: the amount deposited;

_minMintAmount: the minimum expected amount of USR to receive (slippage protection).

Subsequently, the user deposits USDC or USDT into the contract. The project's backend SERVICE_ROLE monitors the request, uses the Pyth oracle to check the value of the deposited assets, and then calls the completeMint or completeSwap function to determine the actual amount of USR to mint.

The problem lies in the fact that the minting contract fully trusts the _mintAmount provided by the SERVICE_ROLE, assuming this number was verified off-chain by Pyth. Therefore, it did not set an upper limit restriction, nor did it perform on-chain oracle verification, and directly executed mint(_mintAmount).

Based on this, YAM suspects that the hacker gained control of the SERVICE_ROLE, which should have been controlled by the project team (possibly due to internal oracle failure, insider theft, or key compromise), and directly set the _mintAmount to 50 million during the minting process, achieving the attack of minting 50 million USR with 100,000 USDC.

In conclusion, Grok's assessment is that Resolv did not consider the possibility that the address (or contract) receiving user minting requests could be compromised by hackers when designing the protocol. When the USR minting request was submitted to the final USR minting contract, no maximum minting amount was set, nor did the minting contract perform secondary verification using an on-chain oracle; it simply trusted all parameters provided by the SERVICE_ROLE.

Inadequate Prevention

In addition to speculating on the cause of the hack, YAM also pointed out the project's lack of preparedness in crisis response.

YAM stated on X that Resolv Labs only paused the protocol 3 hours after the hacker's first attack was completed, with about 1 hour of delay coming from collecting the 4 signatures required for the multisig transaction. YAM believes that an emergency pause should require only one signature, and the authority should be assigned to team members as much as possible, or to trusted external operators, to increase attention to on-chain anomalies, improve the possibility of quick pauses, and better cover different time zones.

Although the suggestion of requiring only a single signature to pause the protocol is somewhat radical,确实 requiring multiple signatures across different time zones to pause the protocol can indeed cause significant delays when emergencies occur. Introducing trusted third parties who continuously monitor on-chain behavior, or using monitoring tools with emergency protocol pause permissions, are lessons learned from this incident.

Hacker attacks on DeFi protocols have long gone beyond contract vulnerabilities. The Resolv Labs incident serves as a warning to project teams: the assumption in protocol security should be to trust no single link; all parameter-related links must undergo at least secondary verification, even if it's the project's own operational backend.

Связанные с этим вопросы

QWhat was the main reason behind the Resolv Labs hack according to the DeFi community YAM's analysis?

AThe hack was likely due to the SERVICE_ROLE, which provides parameters to the minting contract, being controlled by the hacker. The minting contract fully trusted the _mintAmount parameter provided by SERVICE_ROLE without setting a maximum limit or performing a secondary on-chain oracle verification.

QHow much initial capital did the hacker use, and what was the approximate value of the assets they obtained?

AThe hacker used 200,000 USDC to mint a large amount of USR and subsequently obtained assets worth over 20 million US dollars.

QWhich protocols or platforms were affected beyond Resolv Labs itself due to this attack?

AMorpho's lending markets that accepted USR and wstUSR as collateral were almost drained, and Lista DAO on BNB Chain paused new borrowing requests. Additionally, RLP token holders, like Stream Finance, faced significant risk exposure.

QWhat specific flaw in the protocol's design allowed the hacker to mint an excessive amount of USR?

AThe protocol's design did not consider the possibility that the address (or contract) receiving user minting requests could be compromised. The minting contract lacked a maximum mint amount limit and did not use an on-chain oracle for secondary verification, blindly trusting all parameters from the SERVICE_ROLE.

QWhat criticism did YAM level against Resolv Labs' emergency response measures?

AYAM criticized that it took Resolv Labs 3 hours to pause the protocol after the first attack, with about an hour of that delay attributed to collecting 4 signatures required for the multisig transaction. They suggested emergency pauses should require only one signature and be assigned to team members or trusted external operators for faster response.

Похожее

When LPs Teach Me Investment with Doubao: A Self-Narrative of a Private Equity GP Switching Careers

When LPs Use Doubao to Teach Investing: A Transition Story of a Private Equity GP AI is making life increasingly difficult for small private equity fund managers, as a former GP of an offshore dollar fund reveals. The fund, managing tens of millions in US stocks, outperformed the Nasdaq but struggled with fundraising. Its traditional Cayman SPC/BVI structure failed to attract major Asian LPs, who now prefer Hong Kong LPF or Singapore VCC frameworks. The rise of AI-powered quantitative strategies has further squeezed the space for funds like his, which relied on subjective, discretionary investing. AI tools have leveled the information playing field, empowering LPs—often high-net-worth individuals, entrepreneurs, or family offices—to analyze investments themselves using chatbots like Doubao. This has eroded trust in GPs' expertise, leading to more frequent challenges over investment decisions and even withdrawals, especially during market rallies when retail investors sometimes outperform funds. Friction arises not necessarily from AI's capabilities but from how LPs use it. Many rely on conversational AI for validation rather than rigorous analysis, sometimes receiving misleading or hallucinated advice. While AI democratizes research, effective investing still requires discerning real insight from plausible-sounding output. Ultimately, AI is unlikely to fully replace GPs. Asset management remains a trust-based service. However, the industry must adapt. The future may see "human私募" (private equity) learning from AI and focusing more on providing value beyond pure analysis—perhaps by mastering the emotional intelligence and trust-building that machines cannot replicate.

Odaily星球日报16 мин. назад

When LPs Teach Me Investment with Doubao: A Self-Narrative of a Private Equity GP Switching Careers

Odaily星球日报16 мин. назад

Wang Chuan: After Investing in Storage Stocks and Seeing a Thirty-Fold Return, How to Remain Unanxious (Part 7) - A Quarter-Century Cycle

Wang Chuan: Reflections on Investment Anxiety and Market Cycles After Observing a 30x Gain in a Storage Stock (Part 7) – A Quarter-Century Cycle This article examines the cyclical nature and inherent risks in technology hardware investments, using the storage and semiconductor sectors as examples. It criticizes the misleading practice of "annualized" Net Dollar Retention (NDR) rates, where short-term growth is extrapolated unrealistically. A key concept explored is "reflexivity" – demand driven by panic, exploration, and liquidity during market booms, which can vanish just as quickly when conditions reverse. This reflexivity exists both in product demand and among speculative stock buyers, creating powerful feedback loops that inflate prices during upturns and exacerbate crashes during downturns. The author highlights a major risk for hardware sectors: unlike assets with defined cycles (e.g., Bitcoin's halving), there's no guarantee of a swift recovery post-crash. Companies like Micron, Intel, and Cisco took roughly a quarter-century to surpass their 2000 highs, enduring drawdowns exceeding 80%. This is attributed to the "bullwhip effect" in supply chains, where demand collapses instantly but过剩产能 persists, and a migration of narrative-driven capital. High-valuation stories吸引 speculative funds during growth phases, but these funds quickly depart for the next hot narrative once growth slows, leaving behind stronger companies with much lower valuations. The piece warns of dangerous mental models formed during bull markets: 1) equating current strong demand with perpetual high growth, and 2) believing that making fast, large profits is easy. Citing巴菲特, the author notes that easy money undermines rationality, likening speculators to Cinderella at a ball with a clock that has no hands. The current phase presents an asymmetric risk-reward scenario: potential for further gains exists, but the downside risk is an 80%+ drawdown and a multi-decade wait for breakeven, which reflexive speculators cannot tolerate. The hypothetical investor "老王" (Lao Wang), who achieved a 30x return, is used to illustrate potential pitfalls. Leverage could lead to a wipeout during a sharp correction. Even without leverage, ingrained beliefs in easy money would likely lead him to double down after losses, expecting a quick rebound. Instead, he might face a protracted decline, depleting his resources through frantic trading as the high-growth narrative fades. The conclusion references Schopenhauer, comparing those who have seen multiple market cycles to an audience seeing the same magic trick repeatedly—once the illusion is understood, its power is gone.

marsbit39 мин. назад

Wang Chuan: After Investing in Storage Stocks and Seeing a Thirty-Fold Return, How to Remain Unanxious (Part 7) - A Quarter-Century Cycle

marsbit39 мин. назад

US Stocks Too Expensive? This Top CIO Scoured the Globe and Found 5 Stocks More Attractive Than NVIDIA

Summary: Main Street Research CIO James Demmert maintains his bullish 8,100 target for the S&P 500 but argues that greater opportunities now lie overseas. He identifies five international stocks with superior valuations poised to benefit from the AI revolution, suggesting international markets will outperform the US for years. Key Recommendations: 1. **ASML (Netherlands):** A foundational chip manufacturing technology provider, offering crucial AI exposure and geographic diversification. Demmert's top long-term pick. 2. **HSBC (UK/Asia):** A global bank with a 9x P/E ratio, better growth prospects than US peers like JPMorgan, and strong Asian presence. 3. **Siemens Energy (Germany):** A direct play on global power grid expansion driven by AI, crypto, and EV electricity demand. 4. **BHP Group (Australia):** A "hidden AI play" and "second derivative" of the trend due to massive copper demand for data centers. Trades at a 16x P/E. 5. **AstraZeneca (UK):** An undervalued healthcare stock with a strong pipeline (18x P/E, >20% growth), expected to benefit from AI's impact on medicine. Core Thesis: International outperformance is driven by both attractive valuations and a major policy shift. While the US tightens fiscal policy, Europe and Japan are launching unprecedented stimulus, reigniting growth. Demmert recommends allocating 45% of a portfolio internationally, citing excessive US investor conservatism as a key mistake.

marsbit44 мин. назад

US Stocks Too Expensive? This Top CIO Scoured the Globe and Found 5 Stocks More Attractive Than NVIDIA

marsbit44 мин. назад

a16z Partner: Three Paths for Crypto Projects to Find PMF

Author: Jason Rosenthal. Compiler: Shenchao TechFlow. Finding Product-Market Fit (PMF) is the most critical variable for a company's survival. In the crypto space, misaligned growth hacking and airdrops often mask the absence of true PMF. However, leading teams are now finding PMF faster. Here are three proven paths for crypto projects to achieve PMF: 1. **Co-build with Anchor Clients:** Partner with the most sophisticated potential clients in your field and develop the product based on their specific needs. Their adoption serves as the strongest validation, more valuable than media coverage or TVL metrics. This approach is shaping current product roadmaps, as seen in collaborations between crypto startups and traditional finance. 2. **Position Ahead of an Exponential Curve:** Identify and position yourself ahead of a major emerging trend before the market fully realizes it. The most evident current curve is the rise of AI Agents as autonomous economic actors. Projects like AgentCash by Merit Systems, which enables AI Agents to pay for API access with crypto, are building foundational payment rails for the impending Agent economy. 3. **Be Your Own First and Best Customer:** The most enduring infrastructure companies don't wait for external validation. They first build and prove their technology by using it to power their own applications at scale before offering it to others. Matter Labs exemplifies this by anchoring its ZKsync technology in a concrete application, Cari Network, which enables U.S. regional banks to conduct real-time, on-chain interbank transfers of tokenized deposits. The underlying logic is consistent: the fastest path to PMF involves choosing the right battlefield and executing with conviction—by co-building with clients whose validation compounds, positioning ahead of the curve before consensus forms, or becoming your own best case study.

marsbit44 мин. назад

a16z Partner: Three Paths for Crypto Projects to Find PMF

marsbit44 мин. назад

Торговля

Спот
Фьючерсы
活动图片