Resolv exploit triggers USR depeg after $80M uncollateralized mint

ambcrypto发布于2026-03-23更新于2026-03-23

文章摘要

Resolv protocol was exploited due to a private key compromise, leading to an unauthorized mint of approximately $80M in unbacked USR stablecoins. This inflated the total supply by 71M tokens, causing a severe depeg—USR fell 56% to around $0.19. The team paused contracts, burned 9M of the attacker’s tokens, and confirmed that underlying collateral remains intact with only $0.5M in losses from redemptions. Recovery efforts include allowlisted redemptions and tracing illicit tokens. The incident highlights risks from over-reliance on off-chain controls in DeFi minting mechanisms.

Resolv has paused its protocol after a private key compromise enabled a malicious actor to mint approximately $80M in uncollateralized USR. This triggered a sharp depeg and raised concerns about the stablecoin’s integrity.

In an update shared, the team said the attacker gained unauthorized access to its infrastructure and minted new USR tokens without backing. Smart contracts were quickly paused, and around 9M USR held by the attacker has since been burned.

Resolv stated that its underlying collateral was not directly compromised. Also, the only confirmed loss so far is roughly $0.5M in redemptions processed before the pause.

Exploit inflates USR supply rather than draining funds

Unlike typical DeFi exploits that drain protocol funds, the Resolv incident centers on supply inflation.

Before the incident, around 102M USR was in circulation. Following the exploit, an additional ~71M USR was minted without collateral. This effectively diluted the backing of the stablecoin.

This pushed total supply far above the value of the protocol’s assets, altering the relationship between supply and collateral.

The team said the exploit resulted from a compromised private key tied to infrastructure access, rather than a failure of its underlying collateral system.

Design assumptions exposed in minting process

While Resolv attributed the breach to unauthorized access, the incident has drawn attention to how minting authority was structured.

The exploit was made possible because a privileged role could authorize token issuance without sufficient on-chain validation of collateral backing.

This meant that once access was obtained, large amounts of USR could be minted without checks tied to deposited assets.

Such architecture relies on trusted off-chain controls to enforce limits — an assumption that can break down if those controls are compromised.

USR loses peg as market confidence drops

Market reaction to the exploit was swift, with USR losing its dollar peg.

At the time of writing, USR was trading near $0.19, down more than 56% over 24 hours, according to CoinMarketCap data. The sharp decline reflects a repricing of the token as supply expanded beyond its collateral base.

Source: CoinMarketCap

Trading activity has also weakened significantly, with volumes dropping as users exit positions or avoid exposure during the recovery process.

Recovery efforts underway as redemptions planned

Resolv said it is preparing to enable redemptions for pre-incident USR holders, starting with allowlisted users.

The protocol currently holds approximately $141M in assets, and the team is working with partners, analytics firms, and law enforcement to trace and contain illicitly minted tokens.

Users have been advised not to trade USR or related assets during the recovery phase. Post-exploit activity could impact the outcome of the process.

Stablecoin integrity under scrutiny

The incident highlights a broader risk in DeFi systems where critical safeguards depend on off-chain controls rather than enforced on-chain limits.

Although Resolv’s collateral pool remains intact, the ability to mint unbacked tokens has undermined confidence in the system’s accounting.

As the situation unfolds, the key challenge will be restoring trust in USR’s backing and stabilizing its supply.


Final Summary

  • The Resolv exploit inflated USR supply by $80M without draining collateral, exposing risks tied to off-chain control mechanisms.
  • USR’s sharp depeg reflects a loss of market confidence, with recovery now dependent on isolating illicit supply and restoring backing integrity.

热门币种推荐

相关问答

QWhat was the primary method used by the attacker to exploit the Resolv protocol?

AThe attacker gained unauthorized access to Resolv's infrastructure through a compromised private key, which allowed them to mint approximately $80M in uncollateralized USR tokens.

QHow did the exploit mechanism in this incident differ from a typical DeFi attack?

AUnlike typical DeFi exploits that drain protocol funds, this incident centered on supply inflation by minting new, unbacked tokens rather than stealing existing collateral.

QWhat was the immediate market consequence of the exploit on the USR stablecoin?

AThe USR stablecoin lost its dollar peg, trading near $0.19 at the time of writing, which represents a decline of more than 56% over 24 hours.

QWhat key vulnerability in the protocol's design did this exploit expose?

AThe exploit exposed a vulnerability where a privileged role could authorize token issuance without sufficient on-chain validation of collateral backing, relying instead on trusted off-chain controls.

QWhat are the main steps Resolv is taking for recovery according to the article?

AResolv has paused the protocol, burned approximately 9M USR held by the attacker, is preparing to enable redemptions for pre-incident holders, and is working with partners and law enforcement to trace illicitly minted tokens.

你可能也喜欢

通过掷骰子离线保管比特币密钥:并非人人愿意为之

文章探讨了通过投掷骰子生成比特币钱包种子短语的安全方法及其现实挑战。核心观点如下: **1. 骰子提供物理熵源** 骰子结果由众多微小变量决定,理论上虽可预测,但实践中无法被攻击者复制或计算,从而提供高质量的随机性。每个六面骰子投掷约产生2.585比特熵,50次投掷即可满足典型12词助记词(128比特熵)的安全需求。 **2. Coldcard漏洞事件凸显手工熵源的价值** 近期Coldcard硬件钱包因固件漏洞导致其内部随机数生成器存在缺陷,致使约1128枚比特币被盗。但那些**完全**通过足量骰子投掷生成种子短语的用户未受此漏洞影响,因为他们的主密钥未使用有缺陷的生成器。 **3. 重要警示:手工种子并非万能保护** 安全研究员指出,即使用户使用骰子生成了安全的种子,若他们使用了Coldcard的其他功能(如生成纸钱包、克隆密钥、共享签名密钥、密码等),这些**衍生密钥**仍可能调用有漏洞的随机数生成器,从而存在风险。安全种子不保证设备生成的所有秘密都安全。 **4. 手工生成熵源的现实局限性** 尽管数学上可靠,但该方法对大多数用户并不友好: * **过程繁琐易错**:需投掷50-99次,精确记录,任何输入错误都会导致钱包完全不同。 * **引入新风险**:用户可能在记录、转换过程中泄露信息,或使用有偏的骰子/投掷方式。 * **用户体验差**:难以想象大规模推广需要用户手动投掷近百次骰子。安全措施需适应现实生活场景和普通用户的知识水平。 **5. 给用户的建议** 受影响的Coldcard用户应: * 更新固件至最新版。 * 检查是否使用过有漏洞的功能生成了次级密钥或密码,如有则需立即更换。 * 考虑采用多签方案,使用不同厂商的设备分散风险。 **结论**:手工投掷骰子生成熵源是技术娴熟用户的一个有效安全选项,但其过程复杂、容易出错,不适合作为主流用户的默认方法。长远目标是依赖安全、透明且无需专业知识的硬件/软件随机数生成方案。

cryptonews.ru2小时前

通过掷骰子离线保管比特币密钥:并非人人愿意为之

cryptonews.ru2小时前

交易

现货

热门文章

如何购买RESOLV

欢迎来到HTX.com!我们已经让购买Resolv(RESOLV)变得简单而便捷。跟随我们的逐步指南,放心开始您的加密货币之旅。第一步:创建您的HTX账户使用您的电子邮件、手机号码注册一个免费账户在HTX上。体验无忧的注册过程并解锁所有平台功能。立即注册第二步:前往买币页面,选择您的支付方式信用卡/借记卡购买:使用您的Visa或Mastercard即时购买Resolv(RESOLV)。余额购买:使用您HTX账户余额中的资金进行无缝交易。第三方购买:探索诸如Google Pay或Apple Pay等流行支付方法以增加便利性。C2C购买:在HTX平台上直接与其他用户交易。HTX场外交易台(OTC)购买:为大量交易者提供个性化服务和竞争性汇率。第三步:存储您的Resolv(RESOLV)购买完您的Resolv(RESOLV)后,将其存储在您的HTX账户钱包中。您也可以通过区块链转账将其发送到其他地方或者用于交易其他加密货币。第四步:交易Resolv(RESOLV)在HTX的现货市场轻松交易Resolv(RESOLV)。访问您的账户,选择您的交易对,执行您的交易,并实时监控。HTX为初学者和经验丰富的交易者提供了友好的用户体验。

933人学过发布于 2025.06.11更新于 2026.06.02

如何购买RESOLV

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对RESOLV(RESOLV)币价的意见。

活动图片