Connect with us
DAPA Banner

Crypto World

Resolv Protocol Hacked: $25 Million Drained Through USR Stablecoin Vulnerability

Published

on

Brian Armstrong's Bold Prediction: AI Agents Will Soon Dominate Global Financial

Key Highlights

  • A sophisticated attacker leveraged a vulnerability in Resolv’s USR minting mechanism, generating approximately 80 million unbacked tokens from an initial deposit of just $200,000 in USDC
  • The hacker successfully extracted 11,409 ETH, valued at approximately $25 million
  • USR’s value plummeted to $0.025 on Curve Finance before staging a partial recovery to roughly $0.85
  • Resolv has suspended all protocol operations; while the team claims the collateral pool remains secure, USR token holders sustained significant losses due to supply inflation
  • Major DeFi platforms including Morpho, Lido, and Aave quickly responded to assess and mitigate their exposure

A critical security breach struck Resolv’s USR stablecoin on Sunday, with an attacker exploiting vulnerabilities in the minting infrastructure to generate approximately 80 million unbacked tokens, ultimately draining roughly $25 million worth of Ether from the protocol.

The malicious activity commenced around 2:21 a.m. UTC. The perpetrator initiated the attack by depositing 100,000 USDC into Resolv’s USR Counter contract, receiving an astronomical 50 million USR in return — approximately 500 times the legitimate amount. A follow-up transaction produced an additional 30 million tokens.

Following the unauthorized minting, the attacker systematically exchanged the fraudulent USR for USDC and USDT through various decentralized exchanges, subsequently consolidating the proceeds into ETH. The attacker’s wallet currently contains 11,409 ETH, representing approximately $23.7 million in current market value.

USR, engineered to maintain a $1 price peg, catastrophically collapsed to $0.025 on Curve Finance merely 17 minutes after the initial minting transaction. While the token experienced a partial rebound to approximately $0.85, it remained significantly depegged as of Sunday morning.

Resolv Labs announced on X that all protocol operations had been temporarily suspended. The development team emphasized that the collateral pool “remains fully intact” with “no underlying assets” compromised. They characterized the vulnerability as “isolated to USR issuance mechanics.”

Despite these assurances, blockchain analysts highlighted that existing USR holders suffered substantial damage. The massive influx of 80 million newly minted tokens severely diluted the circulating supply, while the attacker’s aggressive selling depleted available pool liquidity. Any investors holding USR during the incident experienced immediate portfolio losses.

Security Flaws Traced to Inadequate Access Management

Blockchain security analyst Andrew Hong identified the breach’s origin as a privileged account designated as the SERVICE_ROLE. This critical account was controlled by a single externally owned account rather than a more secure multisignature wallet. The minting contract lacked essential safeguards including oracle verification, amount validation protocols, and maximum minting thresholds.

Pashov, a security firm that previously audited Resolv’s staking module in July 2025, informed Cointelegraph that the fundamental issue appears to stem from a private key compromise rather than inherent weaknesses in the protocol’s architectural design.

Advertisement

Cyvers CEO Deddy Lavid emphasized: “Audits alone are not enough. If you’re not monitoring minting and supply in real time, you’re blind when it matters most.”

Resolv’s official website documents 14 separate audit engagements conducted by five distinct security firms, a $500,000 bug bounty program hosted on Immunefi, and ongoing smart contract surveillance systems.

DeFi Ecosystem Responds to Contain Fallout

Numerous DeFi platforms implemented rapid response measures following the exploit. Lido confirmed that user funds deposited in Lido Earn remained secure. Aave founder Stani Kulechov stated the platform maintained no direct USR exposure and confirmed Resolv was actively repaying outstanding debt. Morpho co-founder Merlin Egalite clarified that only specific vaults had USR exposure.

Contagion Effects Spread Through Lending Ecosystems

Both USR and its staked derivative wstUSR were approved as collateral assets on platforms such as Morpho and Gauntlet. Market analysts observed that opportunistic traders may have acquired USR at its severely discounted price and leveraged it to borrow USDC at the full $1 valuation, effectively draining liquidity reserves from affected vaults.

Resolv’s junior insurance tranche, RLP, also faces potential capital impairment. Stream Finance, holding a substantial 13.6 million RLP position valued at approximately $17 million, could transmit additional losses to its depositor base. Stream previously disclosed a $93 million loss in November 2025.

Advertisement

The RESOLV governance token declined approximately 8.5% in the 24-hour period following the security breach.

This Resolv incident exemplifies a broader industry pattern. According to a recent Immunefi report, the average cryptocurrency hack now inflicts damages of approximately $25 million, with the five largest exploits during 2024–2025 representing 62% of total stolen funds.

Advertisement

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

Sweden’s H100 to Buy Two Bitcoin Treasury Companies, Surpass 3,500 BTC

Published

on

Sweden's H100 to Buy Two Bitcoin Treasury Companies, Surpass 3,500 BTC

Sweden-listed health-tech and Bitcoin treasury company H100 Group has entered into a letter of intent (LOI) with the shareholders of privately-held Norwegian Bitcoin companies Moonshot and Never Say Die to acquire all shares of the target companies in exchange for newly issued H100 stock.

The proposed transaction would be completed with newly issued H100 shares and no cash consideration, a structure intended to preserve the sellers’ Bitcoin exposure while moving the assets into a larger listed vehicle, according to a Monday press release.

A definitive agreement is expected by April 22, with closing targeted after H100’s annual general meeting. H100’s public materials currently show inconsistent AGM dates: its investor-relations calendar lists April 21, while a March 12 company notice referred to an AGM on May 21.

If the deal goes ahead, it would make H100 the second-largest listed Bitcoin treasury company in Europe behind Germany’s Bitcoin Group, which holds 3,605 BTC. H100 currently holds 1,051 Bitcoin, while the target companies hold about 2,450 BTC, bringing H100’s total to 3,501 BTC (worth around $239.7 million at current prices) after the deal, the release states.

Advertisement

H100 is the 44th largest Bitcoin treasury company worldwide. The deal would mean the company would rise to 27th in the rankings, above Cango Inc and France-based Capital B, according to Bitcointreasuries data.

The Norway deal follows H100’s completed acquisition of Switzerland-based Future Holdings AG.

Top Bitcoin treasury firms by total BTC holdings. Source: Bitcointreasuries.net

“Scale, credibility and access to capital markets are increasingly important in the Bitcoin space, and this transaction would significantly strengthen H100 in all these areas,” said Sander Andersen, chairman of H100.

The “challenging” market environment makes the acquisition a welcome opportunity that strengthens the company’s Bitcoin position in a capital-efficient manner, Andersen told Cointelegraph, pledging future BTC purchases.

Related: Bitcoin whales shift $100M+ as oil spike rattles markets

Advertisement

Bitcoin treasury stocks remain under pressure

H100’s stock price has been declining. It fell by over 74% in the past nine months and over 26% year-to-date in 2026, Yahoo Finance data shows.

H100 stock price, all-time chart. Source: Yahoo Finance

The weakness mirrors broader pressure across Bitcoin treasury stocks as Bitcoin remains well below its October 2025 all-time high.

Related: Morgan Stanley files amended S-1 for MSBT Bitcoin ETF

European Bitcoin treasury companies are continuing to accumulate BTC. Earlier on Monday, treasury company Capital B announced the acquisition of 44 Bitcoin for 2.7 million euros ($3.1 million), topping 2,888 in total BTC holdings at an average cost basis of $106,662 per coin.

H100’s average cost basis is $114,615 per BTC, Bitcointreasuries data shows.

Advertisement

Magazine: Bitcoin’s ‘biggest bull catalyst’ would be Saylor’s liquidation — Santiment founder