Turning 200,000 into Nearly 100 Million: DeFi Stablecoin Attacked Again

marsbitОпубліковано о 2026-03-22Востаннє оновлено о 2026-03-22

Анотація

DeFi stablecoin protocol Resolv Labs was exploited, resulting in a hacker minting 80 million USR tokens using only 200,000 USDC. The attacker’s address (starting with 0x04A2) first created 50 million USR with 100,000 USDC, and later minted another 30 million with an additional 100,000 USDC. This caused USR to depeg, dropping to around $0.25 before partially recovering to approximately $0.80. The incident also impacted related lending markets on Morpho and Lista DAO, which paused new borrowing requests. Additionally, RLP token holders, including Stream Finance—which holds over 13 million RLP tokens—face significant exposure, with estimated losses around $17 million. Initial analysis by DeFi community YAM suggests the exploit occurred because the protocol’s SERVICE_ROLE, which provides minting parameters, was compromised. The system fully trusted this role’s input without on-chain verification or minting limits, allowing the attacker to manipulate the mint amount. The project’s emergency response was also slow, taking nearly three hours to pause the protocol due to multi-signature delays. This attack highlights critical vulnerabilities in off-chain role trust and emergency mechanisms within DeFi protocols.

Written by: Eric, Foresight News

At approximately 10:21 Beijing time today, Resolv Labs, which issues the stablecoin USR using a Delta neutral strategy, was hacked. An address starting with 0x04A2 used 100,000 USDC to mint 50 million USR from the Resolv Labs protocol.

As the incident was exposed, USR plummeted to around $0.25, and as of writing, it has recovered to approximately $0.80. The price of the RESOLV token also saw a short-term drop of nearly 10%.

Subsequently, the hacker repeated the same method, using another 100,000 USDC to mint 30 million USR. As USR significantly depegged, arbitrage traders quickly took action. Many lending markets on Morpho that supported USR, wstUSR, and others as collateral were almost drained, and Lista DAO on BNB Chain also suspended new borrowing requests.

The impact was not limited to these lending protocols. In the Resolv Labs protocol design, users can also mint an RLP token, which has greater price volatility and higher returns but requires bearing compensation liability when the protocol incurs losses. Currently, the circulating supply of RLP tokens is nearly 30 million, with the largest holder, Stream Finance, holding over 13 million RLP, representing a net risk exposure of approximately $17 million.

Yes, Stream Finance, which was previously hit by the xUSD incident, may be hit again.

As of writing, the hacker has converted USR into USDC and USDT and continues to buy Ethereum, having purchased over 10,000 ETH so far. Using 200,000 USDC, the hacker extracted over $20 million in assets, finding their "hundred-fold coin" during the bear market.

Another Exploit Due to "Lack of Rigor"

The sharp drop on October 11 last year caused collateral losses for many stablecoins issued using Delta neutral strategies due to ADL (Auto-Deleveraging). Projects using altcoins as assets for strategy execution suffered even more severe losses, with some even directly absconding.

The attacked Resolv Labs also uses a similar mechanism to issue USR. The project announced in April 2025 that it had completed a $10 million seed round led by Cyber.Fund and Maven11, with participation from Coinbase Ventures, and launched the RESOLV token at the end of May/early June.

However, the reason for the attack on Resolv Labs was not extreme market conditions but rather a "lack of rigor" in the design of the USR minting mechanism.

No security firm or official has yet analyzed the cause of this hack. The DeFi community YAM preliminarily concluded through analysis that the attack was likely caused by the SERVICE_ROLE, used by the protocol's backend to provide parameters to the minting contract, being compromised by the hacker.

According to Grok's analysis, when a user mints USR, they initiate a request on-chain and call the contract's requestMint function, with parameters including:

_depositTokenAddress: the address of the deposited token;

_amount: the amount deposited;

_minMintAmount: the minimum expected amount of USR to receive (slippage protection).

Subsequently, the user deposits USDC or USDT into the contract. The project's backend SERVICE_ROLE monitors the request, uses the Pyth oracle to check the value of the deposited assets, and then calls the completeMint or completeSwap function to determine the actual amount of USR to mint.

The problem lies in the fact that the minting contract fully trusts the _mintAmount provided by the SERVICE_ROLE, assuming this number was verified off-chain by Pyth. Therefore, it did not set an upper limit restriction, nor did it perform on-chain oracle verification, and directly executed mint(_mintAmount).

Based on this, YAM suspects that the hacker gained control of the SERVICE_ROLE, which should have been controlled by the project team (possibly due to internal oracle failure, insider theft, or key compromise), and directly set the _mintAmount to 50 million during the minting process, achieving the attack of minting 50 million USR with 100,000 USDC.

In conclusion, Grok's assessment is that Resolv did not consider the possibility that the address (or contract) receiving user minting requests could be compromised by hackers when designing the protocol. When the USR minting request was submitted to the final USR minting contract, no maximum minting amount was set, nor did the minting contract perform secondary verification using an on-chain oracle; it simply trusted all parameters provided by the SERVICE_ROLE.

Inadequate Prevention

In addition to speculating on the cause of the hack, YAM also pointed out the project's lack of preparedness in crisis response.

YAM stated on X that Resolv Labs only paused the protocol 3 hours after the hacker's first attack was completed, with about 1 hour of delay coming from collecting the 4 signatures required for the multisig transaction. YAM believes that an emergency pause should require only one signature, and the authority should be assigned to team members as much as possible, or to trusted external operators, to increase attention to on-chain anomalies, improve the possibility of quick pauses, and better cover different time zones.

Although the suggestion of requiring only a single signature to pause the protocol is somewhat radical,确实 requiring multiple signatures across different time zones to pause the protocol can indeed cause significant delays when emergencies occur. Introducing trusted third parties who continuously monitor on-chain behavior, or using monitoring tools with emergency protocol pause permissions, are lessons learned from this incident.

Hacker attacks on DeFi protocols have long gone beyond contract vulnerabilities. The Resolv Labs incident serves as a warning to project teams: the assumption in protocol security should be to trust no single link; all parameter-related links must undergo at least secondary verification, even if it's the project's own operational backend.

Пов'язані питання

QWhat was the main reason behind the Resolv Labs hack according to the DeFi community YAM's analysis?

AThe hack was likely due to the SERVICE_ROLE, which provides parameters to the minting contract, being controlled by the hacker. The minting contract fully trusted the _mintAmount parameter provided by SERVICE_ROLE without setting a maximum limit or performing a secondary on-chain oracle verification.

QHow much initial capital did the hacker use, and what was the approximate value of the assets they obtained?

AThe hacker used 200,000 USDC to mint a large amount of USR and subsequently obtained assets worth over 20 million US dollars.

QWhich protocols or platforms were affected beyond Resolv Labs itself due to this attack?

AMorpho's lending markets that accepted USR and wstUSR as collateral were almost drained, and Lista DAO on BNB Chain paused new borrowing requests. Additionally, RLP token holders, like Stream Finance, faced significant risk exposure.

QWhat specific flaw in the protocol's design allowed the hacker to mint an excessive amount of USR?

AThe protocol's design did not consider the possibility that the address (or contract) receiving user minting requests could be compromised. The minting contract lacked a maximum mint amount limit and did not use an on-chain oracle for secondary verification, blindly trusting all parameters from the SERVICE_ROLE.

QWhat criticism did YAM level against Resolv Labs' emergency response measures?

AYAM criticized that it took Resolv Labs 3 hours to pause the protocol after the first attack, with about an hour of that delay attributed to collecting 4 signatures required for the multisig transaction. They suggested emergency pauses should require only one signature and be assigned to team members or trusted external operators for faster response.

Пов'язані матеріали

The AI Investment Landscape Is Being Reshaped: Beyond the 'Magnificent Seven', What Opportunities Lie in the Semiconductor Supply Chain?

AI Investment Map is Reshaping: Opportunities Beyond the 'Magnificent Seven' Since ChatGPT ignited the AI wave, investment initially focused on the "Magnificent Seven" tech giants dominating cloud infrastructure. However, the rise of DeepSeek and debates on AI capital expenditure effectiveness are shifting this dynamic. Investors now recognize opportunities deeper in the supply chain—the companies providing the essential "picks and shovels." Early concerns about an AI investment "arms race" and potential low returns were partly alleviated by strong Q1 earnings from cloud providers, validating robust compute demand. This has highlighted a more certain investment thesis: regardless of which AI applications ultimately win, massive capital expenditure will first fuel demand for semiconductors and related components. This "pick-and-shovel" logic has driven semiconductor ETFs to record highs. Key beneficiaries include: * **Memory Chipmakers (e.g., SK Hynix, Samsung, Micron)**: High Bandwidth Memory (HBM) is a critical bottleneck for AI training. * **Photonics Companies**: Crucial for high-speed data transfer within AI data centers. * **The Broader "AI-11" Semiconductor Ecosystem**: This encompasses foundries & lithography (TSMC, ASML), logic & custom chips (AMD, Broadcom, Intel, Marvell), and enterprise storage (SanDisk, Western Digital). Every dollar of AI infrastructure spending flows through this chain. While the "Magnificent Seven" remain dominant in market size, their earnings growth premium over the rest of the S&P 500 ("S&P 493") is narrowing. Market attention and marginal investment are shifting towards the expanding semiconductor supply chain. The investment narrative is evolving from "betting on the ultimate AI winner" to "investing in the certainty of the infrastructure build-out." Understanding this shift from the demand side to the supply side is key to identifying future AI investment opportunities.

marsbit3 хв тому

The AI Investment Landscape Is Being Reshaped: Beyond the 'Magnificent Seven', What Opportunities Lie in the Semiconductor Supply Chain?

marsbit3 хв тому

600 People, $66 Billion: The First Major Cash-Out in the Era of Large Models

The first systematic "big cash-out" of the AI era occurred in October 2025, when over 600 current and former OpenAI employees sold a total of $6.6 billion in shares via a secondary market. Approximately 75 individuals maxed out a $30 million per-person sale limit, while around 525 others cashed out an average of $8.3 million each. This event, exceeding the scale of any 2024 US IPO, functioned as a "shadow IPO." It marked a radical departure from the traditional Silicon Valley path of waiting for a public listing, instead allowing employees to convert equity to cash after just two years of tenure—a direct retention tool in a fiercely competitive talent market where rivals like Meta have offered packages worth hundreds of millions. This massive liquidity event presents a dual-edged sword for OpenAI. While it helps retain talent, it also risks triggering a brain drain as newly wealthy employees may depart. Furthermore, it creates a dilemma for those who sold: they forfeited potential future gains as the company's valuation soared from $400 billion to $852 billion within months. In stark contrast, employees at rival Anthropic demonstrated greater reluctance to sell during their own secondary offering. The financial narratives of the two labs also diverge sharply. OpenAI, while achieving over $20 billion in annualized revenue by 2025, faces massive projected losses (up to $14 billion in 2026), a long path to cash flow positivity, and significant revenue-sharing payments to Microsoft. Anthropic reports rapid revenue growth, improving gross margins, and a faster path to profitability. OpenAI's trajectory is thus balanced precariously between skyrocketing valuation based on funding narratives and the pressures of sustained financial losses post-cash-out. The event underscores that the AI race has evolved into a capital and human experiment, where immense wealth crystallizes the complex calculations of greed, fear, and ambition within the industry.

marsbit23 хв тому

600 People, $66 Billion: The First Major Cash-Out in the Era of Large Models

marsbit23 хв тому

NVIDIA Begins Adding Soap to the Bubble

NVIDIA is taking on a dual role: not just as a leading chip supplier, but as a massive capital allocator across the entire AI supply chain. In 2026, the company has committed over $40 billion in investments within five months, targeting everything from optical fiber manufacturing and data center operations to foundational AI model development. This investment spree, described as a systematic "sprinkler" approach, primarily funds companies that are major buyers of NVIDIA's own GPUs. Critics, including analysts from Goldman Sachs, label this a "circular revenue" loop—comparable to a supplier financing a customer to buy more of its products. A prominent example is NVIDIA's investment in OpenAI, which is expected to generate around $13 billion in revenue for NVIDIA, much of which may be reinvested back into OpenAI. While CEO Jensen Huang dismisses the "circular financing" critique as "absurd," arguing the investments are confidence votes in long-term generational shifts, some analysts express discomfort. They note that while investments in critical supply chain components like optics are strategically sound, funding new cloud providers like CoreWeave feels like "pre-paying for your own GPUs." The strategy carries significant risks. If the AI investment cycle turns, the market may question how much demand is genuine versus artificially sustained by NVIDIA's own balance sheet. Despite posting record-breaking earnings—$215.9 billion in annual revenue and $120 billion in net profit for FY2026—NVIDIA's stock fell after its report, signaling that "beating expectations" may no longer be enough to assure investors about the duration of the AI spending boom. The article concludes that while a bubble isn't necessarily a fraud, NVIDIA's actions resemble adding soap to a bubble—making it appear more robust and durable. This creates a complex scenario requiring extreme冷静 from investors to distinguish between real structural growth and financial engineering.

marsbit40 хв тому

NVIDIA Begins Adding Soap to the Bubble

marsbit40 хв тому

Short Positions Have Been Squeezed Out: Will the Next Leg of the U.S. Stock AI Rally Continue in Seoul?

"Short Squeeze Exhausted: Will the Next Leg of the AI Rally Continue in Seoul?" A Nomura report suggests the US AI stock rally, which saw the S&P 500 rise ~16.6% in 28 days largely driven by 10 key stocks, may be pausing. The fuel from short covering, CTA fund positioning, and volatility-control strategies is nearing its limit. For the rally to continue, new momentum from retail and sentiment-driven FOMO (Fear Of Missing Out) is needed. South Korea's market provided a potential answer on the very day the report was published. The KOSPI index surged 4.32%, triggering a buy-side circuit breaker, led by massive gains in chip giants SK Hynix (+11.98%) and Samsung. This surge is characterized by retail "hynix FOMO" and overseas funds precisely buying into AI themes via chip-focused ETFs, shifting from broad Korean market ETFs. The Korean rally is a high-beta extension of the US AI capital expenditure story, as major cloud providers plan massive infrastructure spending, directly benefiting memory chip leaders. However, this linkage also implies vulnerability. The sustainability of this next leg depends on whether US tech stocks correct, the trajectory of US inflation (with upcoming CPI data key), and geopolitical tensions around the Strait of Hormuz. Seoul has emerged as the new epicenter of the AI trade, but its fate remains tied to these broader macro and market dynamics.

marsbit45 хв тому

Short Positions Have Been Squeezed Out: Will the Next Leg of the U.S. Stock AI Rally Continue in Seoul?

marsbit45 хв тому

Торгівля

Спот
Ф'ючерси
活动图片