Resolv exploit triggers USR depeg after $80M uncollateralized mint

ambcrypto發佈於 2026-03-23更新於 2026-03-23

文章摘要

Resolv protocol was exploited due to a private key compromise, leading to an unauthorized mint of approximately $80M in unbacked USR stablecoins. This inflated the total supply by 71M tokens, causing a severe depeg—USR fell 56% to around $0.19. The team paused contracts, burned 9M of the attacker’s tokens, and confirmed that underlying collateral remains intact with only $0.5M in losses from redemptions. Recovery efforts include allowlisted redemptions and tracing illicit tokens. The incident highlights risks from over-reliance on off-chain controls in DeFi minting mechanisms.

Resolv has paused its protocol after a private key compromise enabled a malicious actor to mint approximately $80M in uncollateralized USR. This triggered a sharp depeg and raised concerns about the stablecoin’s integrity.

In an update shared, the team said the attacker gained unauthorized access to its infrastructure and minted new USR tokens without backing. Smart contracts were quickly paused, and around 9M USR held by the attacker has since been burned.

Resolv stated that its underlying collateral was not directly compromised. Also, the only confirmed loss so far is roughly $0.5M in redemptions processed before the pause.

Exploit inflates USR supply rather than draining funds

Unlike typical DeFi exploits that drain protocol funds, the Resolv incident centers on supply inflation.

Before the incident, around 102M USR was in circulation. Following the exploit, an additional ~71M USR was minted without collateral. This effectively diluted the backing of the stablecoin.

This pushed total supply far above the value of the protocol’s assets, altering the relationship between supply and collateral.

The team said the exploit resulted from a compromised private key tied to infrastructure access, rather than a failure of its underlying collateral system.

Design assumptions exposed in minting process

While Resolv attributed the breach to unauthorized access, the incident has drawn attention to how minting authority was structured.

The exploit was made possible because a privileged role could authorize token issuance without sufficient on-chain validation of collateral backing.

This meant that once access was obtained, large amounts of USR could be minted without checks tied to deposited assets.

Such architecture relies on trusted off-chain controls to enforce limits — an assumption that can break down if those controls are compromised.

USR loses peg as market confidence drops

Market reaction to the exploit was swift, with USR losing its dollar peg.

At the time of writing, USR was trading near $0.19, down more than 56% over 24 hours, according to CoinMarketCap data. The sharp decline reflects a repricing of the token as supply expanded beyond its collateral base.

Source: CoinMarketCap

Trading activity has also weakened significantly, with volumes dropping as users exit positions or avoid exposure during the recovery process.

Recovery efforts underway as redemptions planned

Resolv said it is preparing to enable redemptions for pre-incident USR holders, starting with allowlisted users.

The protocol currently holds approximately $141M in assets, and the team is working with partners, analytics firms, and law enforcement to trace and contain illicitly minted tokens.

Users have been advised not to trade USR or related assets during the recovery phase. Post-exploit activity could impact the outcome of the process.

Stablecoin integrity under scrutiny

The incident highlights a broader risk in DeFi systems where critical safeguards depend on off-chain controls rather than enforced on-chain limits.

Although Resolv’s collateral pool remains intact, the ability to mint unbacked tokens has undermined confidence in the system’s accounting.

As the situation unfolds, the key challenge will be restoring trust in USR’s backing and stabilizing its supply.


Final Summary

  • The Resolv exploit inflated USR supply by $80M without draining collateral, exposing risks tied to off-chain control mechanisms.
  • USR’s sharp depeg reflects a loss of market confidence, with recovery now dependent on isolating illicit supply and restoring backing integrity.

相關問答

QWhat was the primary method used by the attacker to exploit the Resolv protocol?

AThe attacker gained unauthorized access to Resolv's infrastructure through a compromised private key, which allowed them to mint approximately $80M in uncollateralized USR tokens.

QHow did the exploit mechanism in this incident differ from a typical DeFi attack?

AUnlike typical DeFi exploits that drain protocol funds, this incident centered on supply inflation by minting new, unbacked tokens rather than stealing existing collateral.

QWhat was the immediate market consequence of the exploit on the USR stablecoin?

AThe USR stablecoin lost its dollar peg, trading near $0.19 at the time of writing, which represents a decline of more than 56% over 24 hours.

QWhat key vulnerability in the protocol's design did this exploit expose?

AThe exploit exposed a vulnerability where a privileged role could authorize token issuance without sufficient on-chain validation of collateral backing, relying instead on trusted off-chain controls.

QWhat are the main steps Resolv is taking for recovery according to the article?

AResolv has paused the protocol, burned approximately 9M USR held by the attacker, is preparing to enable redemptions for pre-incident holders, and is working with partners and law enforcement to trace illicitly minted tokens.

你可能也喜歡

XRP Ledger 发布 3.2.0 版本升级并启用 XRPLd 新品牌名

XRP Ledger发布了3.2.0版本,这是对其底层区块链基础设施的一次重要升级。本次更新的核心是将运行网络的软件名称从“rippled”更名为“xrpld”,以更好地反映整个项目生态。 与此前侧重于前端功能的版本不同,3.2.0版本优先进行了后端升级和效率提升,旨在增强网络性能并为未来的扩展做准备。关键改进包括内存优化措施,预计可节省高达40%的服务器内存使用。 此次升级引入了名为“fixCleanup3_2_0”的修改,为单资产金库、借贷协议、权限系统、去中心化交易所、多用途代币和权限域等多个模块带来了安全性增强。开发团队还新增了不变性检查,以确保已删除账户不会在账本上留下不一致的数据,从而加强整个网络的完整性和可靠性。 对于开发者而言,新版本增加了一项重要功能:应用程序无需连接服务器即可检索XRP Ledger协议和服务器定义信息,这将极大便利钱包、区块链浏览器和API等的开发工作。 在可扩展性和稳定性方面,更新包括可配置的区块大小、通过nuDB实现的高效数据库存储,以及将gRPC服务器的TLS/双向TLS支持改为可选,以提升企业用户的性能和连接性。此外,默认对等端口从51235更改为2459,并修复了涉及自动做市商、支付、代币托管、多用途代币、订单簿和RPC等多个方面的问题。出于性能考虑,3.2.0版本暂时禁用了交易不变性检查,但开发团队表示这不会构成安全威胁。

TheNewsCrypto6 小時前

XRP Ledger 发布 3.2.0 版本升级并启用 XRPLd 新品牌名

TheNewsCrypto6 小時前

交易

現貨
合約

熱門文章

如何購買RESOLV

歡迎來到HTX.com!在這裡,購買Resolv (RESOLV)變得簡單而便捷。跟隨我們的逐步指南,放心開始您的加密貨幣之旅。第一步:創建您的HTX帳戶使用您的 Email、手機號碼在HTX註冊一個免費帳戶。體驗無憂的註冊過程並解鎖所有平台功能。立即註冊第二步:前往買幣頁面,選擇您的支付方式信用卡/金融卡購買:使用您的Visa或Mastercard即時購買Resolv (RESOLV)。餘額購買:使用您HTX帳戶餘額中的資金進行無縫交易。第三方購買:探索諸如Google Pay或Apple Pay等流行支付方式以增加便利性。C2C購買:在HTX平台上直接與其他用戶交易。HTX 場外交易 (OTC) 購買:為大量交易者提供個性化服務和競爭性匯率。第三步:存儲您的Resolv (RESOLV)購買Resolv (RESOLV)後,將其存儲在您的HTX帳戶中。您也可以透過區塊鏈轉帳將其發送到其他地址或者用於交易其他加密貨幣。第四步:交易Resolv (RESOLV)在HTX的現貨市場輕鬆交易Resolv (RESOLV)。前往您的帳戶,選擇交易對,執行交易,並即時監控。HTX為初學者和經驗豐富的交易者提供了友好的用戶體驗。

428 人學過發佈於 2025.06.11更新於 2026.06.02

如何購買RESOLV

相關討論

歡迎來到 HTX 社群。在這裡,您可以了解最新的平台發展動態並獲得專業的市場意見。 以下是用戶對 RESOLV (RESOLV)幣價的意見。

活动图片