Connect with us
DAPA Banner

Crypto World

Resolv Protocol Hacked: $25 Million Drained Through USR Stablecoin Vulnerability

Published

on

Brian Armstrong's Bold Prediction: AI Agents Will Soon Dominate Global Financial

Key Highlights

  • A sophisticated attacker leveraged a vulnerability in Resolv’s USR minting mechanism, generating approximately 80 million unbacked tokens from an initial deposit of just $200,000 in USDC
  • The hacker successfully extracted 11,409 ETH, valued at approximately $25 million
  • USR’s value plummeted to $0.025 on Curve Finance before staging a partial recovery to roughly $0.85
  • Resolv has suspended all protocol operations; while the team claims the collateral pool remains secure, USR token holders sustained significant losses due to supply inflation
  • Major DeFi platforms including Morpho, Lido, and Aave quickly responded to assess and mitigate their exposure

A critical security breach struck Resolv’s USR stablecoin on Sunday, with an attacker exploiting vulnerabilities in the minting infrastructure to generate approximately 80 million unbacked tokens, ultimately draining roughly $25 million worth of Ether from the protocol.

The malicious activity commenced around 2:21 a.m. UTC. The perpetrator initiated the attack by depositing 100,000 USDC into Resolv’s USR Counter contract, receiving an astronomical 50 million USR in return — approximately 500 times the legitimate amount. A follow-up transaction produced an additional 30 million tokens.

Following the unauthorized minting, the attacker systematically exchanged the fraudulent USR for USDC and USDT through various decentralized exchanges, subsequently consolidating the proceeds into ETH. The attacker’s wallet currently contains 11,409 ETH, representing approximately $23.7 million in current market value.

USR, engineered to maintain a $1 price peg, catastrophically collapsed to $0.025 on Curve Finance merely 17 minutes after the initial minting transaction. While the token experienced a partial rebound to approximately $0.85, it remained significantly depegged as of Sunday morning.

Resolv Labs announced on X that all protocol operations had been temporarily suspended. The development team emphasized that the collateral pool “remains fully intact” with “no underlying assets” compromised. They characterized the vulnerability as “isolated to USR issuance mechanics.”

Despite these assurances, blockchain analysts highlighted that existing USR holders suffered substantial damage. The massive influx of 80 million newly minted tokens severely diluted the circulating supply, while the attacker’s aggressive selling depleted available pool liquidity. Any investors holding USR during the incident experienced immediate portfolio losses.

Security Flaws Traced to Inadequate Access Management

Blockchain security analyst Andrew Hong identified the breach’s origin as a privileged account designated as the SERVICE_ROLE. This critical account was controlled by a single externally owned account rather than a more secure multisignature wallet. The minting contract lacked essential safeguards including oracle verification, amount validation protocols, and maximum minting thresholds.

Pashov, a security firm that previously audited Resolv’s staking module in July 2025, informed Cointelegraph that the fundamental issue appears to stem from a private key compromise rather than inherent weaknesses in the protocol’s architectural design.

Advertisement

Cyvers CEO Deddy Lavid emphasized: “Audits alone are not enough. If you’re not monitoring minting and supply in real time, you’re blind when it matters most.”

Resolv’s official website documents 14 separate audit engagements conducted by five distinct security firms, a $500,000 bug bounty program hosted on Immunefi, and ongoing smart contract surveillance systems.

DeFi Ecosystem Responds to Contain Fallout

Numerous DeFi platforms implemented rapid response measures following the exploit. Lido confirmed that user funds deposited in Lido Earn remained secure. Aave founder Stani Kulechov stated the platform maintained no direct USR exposure and confirmed Resolv was actively repaying outstanding debt. Morpho co-founder Merlin Egalite clarified that only specific vaults had USR exposure.

Contagion Effects Spread Through Lending Ecosystems

Both USR and its staked derivative wstUSR were approved as collateral assets on platforms such as Morpho and Gauntlet. Market analysts observed that opportunistic traders may have acquired USR at its severely discounted price and leveraged it to borrow USDC at the full $1 valuation, effectively draining liquidity reserves from affected vaults.

Resolv’s junior insurance tranche, RLP, also faces potential capital impairment. Stream Finance, holding a substantial 13.6 million RLP position valued at approximately $17 million, could transmit additional losses to its depositor base. Stream previously disclosed a $93 million loss in November 2025.

Advertisement

The RESOLV governance token declined approximately 8.5% in the 24-hour period following the security breach.

This Resolv incident exemplifies a broader industry pattern. According to a recent Immunefi report, the average cryptocurrency hack now inflicts damages of approximately $25 million, with the five largest exploits during 2024–2025 representing 62% of total stolen funds.

Advertisement

Source link

Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Crypto World

Bitmine (BMNR) buys 65,341 ETH worth $138 million betting on crypto slump ending

Published

on

Bitmine (BMNR) buys 65,341 ETH worth $138 million betting on crypto slump ending

Bitmine Immersion Technologies (BMNR) said Monday it bought 65,341 ether (ETH) last week, extending a recent surge in purchases as the firm continues to lean into the market downturn.

The latest acquisition, worth roughly $138 million at current ETH prices, lifted the firm’s total holdings above 4.66 million tokens, cornering 3.86% of ETH’s circulating supply, according to a Monday update.

Bitmine has now increased its pace of buying for three consecutive weeks, stepping up from a prior average of around 50,000 tokens per week. Meanwhile, the firm also increased its cash holdings to $1.1 billion.

Chairman Thomas “Tom” Lee said the increase in buying pace reflects the firm’s view that crypto markets are nearing the end of a prolonged slump.

Advertisement

“Our base case is ETH is in the final stages of the ‘mini-crypto winter,’ he said in a statement.

The firm is still sitting on an estimated $7 billion unrealized loss on its ether purchases, DropsTab data shows, as crypto prices tumbled over the past months.

Source link

Advertisement
Continue Reading

Crypto World

Coinbase users blast ‘March Madness’ push notifications

Published

on

Coinbase users blast 'March Madness' push notifications

Coinbase users are complaining about receiving multiple push notifications per day urging them to “predict” sports gameplay during “March Madness” college basketball.

Indeed, so many complaints were reported via X that it became a trending topic yesterday.

Many customers, echoing allegations by state attorneys general in Michigan and Arizona, described the annoying promotions as de facto advertisements to gamble on sports.

Coinbase, is one of the longest continually-operated bitcoin (BTC) exchanges which safeguards billions of dollars’ worth of assets for customers.

However, rather than focus on long-term investments like BTC, Coinbase regularly floods its app with short-term promotions, all-or-nothing predictions, memecoins, leveraged derivatives, and other high-risk wagers. 

Advertisement

Full-screen promotions tempt many users into risky trades while many customers don’t see a single mention of BTC during their entire Coinbase app experience.

Indeed, the homepage of the app as of Protos’ last check, featured a “March Madness” advertisement at the top of the homescreen with no mention of BTC above the fold.

One customer and Coinbase stockholder posted screenshots of the basketball notifications, which arrived several times daily. “This is essentially encouraging me to gamble,” he wrote.

‘Very bad for our industry’

CEO Brian Armstrong responded the same afternoon, calling it “a fair point” and promising customization options. However, the concession only drew sharper criticism.

Advertisement

Alexander Leishman, founder of BTC exchange River, replied to Armstrong: “It’s long term very bad for our industry to be pushing sports betting. The blowback will impact all of us.”

Days earlier, a Messari researcher had posted a nearly identical complaint. “Why am I getting notifications from Coinbase about betting odds for college basketball games?” he wrote.

“This is just reinforcing the notion that crypto is just another gambling product, and not an actual investment to be taken seriously.”

Crypto attorney Ariel Givner compared the moment to Juul’s rise and fall.

Advertisement

Other users were more blunt. “Every time I open your d*** app, I’m getting bombarded with gambling notifications,” one wrote, tagging Coinbase directly.

Read more: NHS exec warns that crypto trading could fuel problem gambling

Coinbase sports ‘event contracts’

Coinbase launched prediction markets in all 50 states in January 2026 through a partnership with Kalshi.

Users can place “prediction” trades on sports, politics, and culture outcomes, funding trades with cash or USDC. Under federal law, these are legally “event contracts,” not sports bets.

Advertisement

Coinbase has sued regulators in Connecticut, Michigan, and Illinois who disagree.

The legal distinction hasn’t convinced everyone.

Nevada, Illinois, and Connecticut have all argued these contracts are functionally gambling while a class action lawsuit in New York alleged that Kalshi “dupes consumers… when they are actually gambling against the house.”

Illinois regulators stated plainly that athletic competitions aren’t economic instruments. Chris Christie told CNBC, “If it looks like a duck and quacks like a duck, it’s a duck. It’s a sports bet.”

Advertisement

Coinbase disagrees entirely and is suing various regulators who have likened its prediction markets to gambling.

Got a tip? Send us an email securely via Protos Leaks. For more informed news, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.

Advertisement

Source link

Continue Reading

Crypto World

Stablecoins Key Role in Agentic AI, Despite Limited Adoption: Bernstein

Published

on

Stablecoins Key Role in Agentic AI, Despite Limited Adoption: Bernstein

Stablecoins could benefit from the rise of AI-driven payments over time, even as early adoption remains limited and contested, according to a new report from Bernstein.

In a Monday note shared with Cointelegraph, the broker said stablecoins could help unlock machine-to-machine payments by making microtransactions viable and enabling programmable, conditional payments between software agents without a human in the loop.

But Bernstein said traction so far has been limited. The note said Stripe and Tempo’s machine payments protocol recorded about $5,000 in stablecoin volume in its first week, while Coinbase’s x402 protocol handled no more than $25 million over the last 30 days.

Bernstein’s chart put x402 volume at about $24 million over that period. x402 is a payment standard developed by Coinbase that lets AI agents automatically make payments over the internet.

Advertisement

The bigger point for Bernstein was that stablecoins do not need machine payments to succeed in order to keep growing. The note said stablecoin demand is already being driven by cross-border business payments, remittances, card-linked products and neobanking, making AI payments an upside case rather than the core thesis.

The report follows growing interest in autonomous payment solutions. On Thursday, Visa’s crypto division launched a tool allowing AI agents to make same-day payments, while Stripe-backed Tempo launched its blockchain and payment protocol.

X402 protocol payment flow. Source: Bernstein

Bernstein said broader payment use cases are still the real growth engine for stablecoins. Its note estimated total stablecoin payment volume rose to $375 billion in 2025 from $213 billion in 2024, led by consumer-to-consumer flows, while business-to-consumer, business-to-business and consumer-to-business activity also increased.

Related: Stablecoin issuers and fintechs race to own payment rails

Coinbase, Circle remain best “proxies” for stablecoin adoption

Cryptocurrency exchange Coinbase and stablecoin issuer Circle remain the “best proxies for stablecoin upside” due to their USDC (USDC) partnership, according to Bernstein.

Advertisement

It also argued that USDC is likely to capture a dominant share of machine-payment activity because it is the most liquid and regulated stablecoin among likely candidates.

So far in 2026, USDC recorded $2.4 trillion in adjusted transaction volume while Tether’s USDt (USDT) recorded $1.4 trillion.

Total adjusted stablecoin transaction volume, in trillion. Source: Bernstein

Wash trading concerns cloud early metrics

Some of the headline machine-payment numbers have already drawn skepticism.

AI Agent payment volume on x402 only amounted to $1.6 million after applying the wash trading filter developed by Artemis Analytics, which is significantly lower than the initial $24 million reported by news outlet Bloomberg, according to a16z partner Noah Levine.

Source: Noah Levine

“$1.6 million is not a big number. But the infrastructure being built around it is,” wrote Levine in a March 11 X post, adding that x402 was already integrated by the likes of Stripe, Cloudflare, Vercel and Google’s agent payments protocol.