Resolv USR Exploit Triggers Depeg After $80M Unbacked Mint

2026-03-23 08:10:42
Attackers exploited a vulnerability in the USR stablecoin minting mechanism of the DeFi protocol Resolv, generating substantial uncollateralized tokens and rapidly converting them to cash. This led to a sharp market price depeg, affecting several DeFi platforms. The event underscores the inherent risks in stablecoin architecture and protocol permission management.

Resolv USR Stablecoin Hit by Major Exploit

Early Sunday morning, a vulnerability exploit targeting the Resolv protocol rocked the DeFi market. Several blockchain security firms confirmed that the attacker exploited a flaw in the USR stablecoin minting contract, creating roughly 80 million unbacked USR tokens and extracting about $25 million in assets from the market.

The attack occurred around 02:21 UTC and was first detected by the on-chain monitoring account YieldsAndMore, which spotted abnormal transactions.

Attack Details: Small Deposits Yield Massive Token Output

On-chain transaction data shows the attacker initially deposited 100,000 USDC into Resolv’s USR Counter contract. Theoretically, this should have only returned the equivalent amount of USR.

However, the actual outcome was a severe anomaly:

  • The first transaction minted about 50 million USR
  • The second transaction minted another 30 million USR

The total output was around 500 times the expected value.

USR Price Collapses Rapidly

USR is a stablecoin pegged to the US dollar, but instead of fiat reserves, it uses a combination of ETH and BTC with a delta-neutral hedging strategy. When a large volume of unbacked tokens was minted, the market price quickly spiraled out of control.

Market reactions included:

  • In the Curve Finance liquidity pool
  • The price fell to $0.025 within 17 minutes

(Source: DEXSCREENER)

Although the price briefly rebounded to about $0.85, it failed to restore its $1 peg.

Attacker’s Fund Movements

The attacker’s address, starting with 0x04A2, conducted a series of arbitrage operations:

  1. Swapped the minted USR for USDC and USDT
  2. Sold these assets through multiple decentralized exchanges
  3. Ultimately converted the proceeds to ETH

On-chain data shows:

  • The main wallet holds 11,409 ETH
  • Valued at approximately $23.7 million

Another address still holds about $1.1 million in wstUSR.

Resolv’s Response: Collateral Assets Intact

After the incident surfaced, Resolv Labs announced on social media:

  • All protocol functions have been suspended
  • The collateral asset pool remains intact
  • The issue is confined to the USR minting process

(Source: ResolvLabs)

Analysts noted that, although the collateral assets were not directly stolen, the market losses remain severe.

Inadequate Permission and Verification Mechanisms

On-chain analyst Andrew Hong identified the core issue as the SERVICE_ROLE permission account, which processes swap requests but is controlled by a standard EOA wallet instead of a multisig.

The minting contract also lacked several critical safeguards:

  • No oracle price verification
  • No cap on the amount minted
  • No check on minting requests or execution amounts

DeFi investment firm D2 Finance outlined three possible causes:

  1. Manipulation of the price oracle
  2. Compromise of the offline signing account
  3. Absence of a minting amount verification mechanism

(Source: D2_Finance)

DeFi Ecosystem Ripple Effects

The USR collapse impacted not only token holders but also the DeFi lending market. USR and its staked version, wstUSR, had been used as collateral on platforms such as Morpho and Gauntlet.

Some traders took advantage of USR’s price dropping below $1:

  • Bought USR at a discount
  • Used it as collateral at the system’s fixed $1 valuation
  • Borrowed USDC

This could quickly drain liquidity from lending pools.

Insurance Pool and Liquidity Layer Also at Risk

Resolv’s liquidity protection mechanism, the Resolv Liquidity Pool (RLP), is designed to absorb losses and protect USR. Prior to the attack, RLP’s circulating value was about $38.6 million, with the largest holder being yield protocol Stream Finance. Stream Finance previously suffered a $93 million loss from asset misappropriation in 2025 and now faces renewed risk.

Regulatory Pressure Mounts

This incident coincides with the US Congress debating stablecoin regulations, including the GENIUS Act, which aims to regulate yield-bearing stablecoins. The American Bankers Association has warned that such products could draw deposits away from traditional banks.

Conclusion

The Resolv USR incident underscores that stablecoin risks originate not only from collateral assets, but also from flaws in contract design and permission management. Even when underlying assets remain untouched, unchecked supply expansion and loss of market confidence can inflict significant losses. As the DeFi market grows, building robust monitoring, permission management, and risk control mechanisms will be essential for the evolution of stablecoins and on-chain finance.

Disclaimer
* The information is not intended to be and does not constitute financial advice or any other recommendation of any sort offered or endorsed by Gate.
* This article may not be reproduced, transmitted or copied without referencing Gate. Contravention is an infringement of Copyright Act and may be subject to legal action.

Share

Crypto Calendar
Tokenların Kilidini Aç
Wormhole, 3 Nisan'da 1.280.000.000 W token açacak ve bu, mevcut dolaşımdaki arzın yaklaşık %28,39'unu oluşturacak.
W
-7.32%
2026-04-02
Tokenların Kilidini Aç
Pyth Network, 19 May'da 2.130.000.000 PYTH tokenini serbest bırakacak ve bu, mevcut dolaşım arzının yaklaşık %36,96'sını oluşturacak.
PYTH
2.25%
2026-05-18
Tokenların Kilidini Aç
Pump.fun, 12 Temmuz'da 82,500,000,000 PUMP token'ı kilidini açacak ve bu, mevcut dolaşımdaki arzın yaklaşık %23,31'ini oluşturacak.
PUMP
-3.37%
2026-07-11
Token Kilidi Açma
Succinct, 5 Ağustos'ta mevcut dolaşımdaki arzın yaklaşık %104,17'sini oluşturan 208,330,000 PROVE token'ını serbest bırakacak.
PROVE
2026-08-04
sign up guide logosign up guide logo
sign up guide content imgsign up guide content img
Sign Up

Related Articles

In-depth Explanation of Yala: Building a Modular DeFi Yield Aggregator with $YU Stablecoin as a Medium
Beginner

In-depth Explanation of Yala: Building a Modular DeFi Yield Aggregator with $YU Stablecoin as a Medium

Yala inherits the security and decentralization of Bitcoin while using a modular protocol framework with the $YU stablecoin as a medium of exchange and store of value. It seamlessly connects Bitcoin with major ecosystems, allowing Bitcoin holders to earn yield from various DeFi protocols.
2024-11-29 10:10:11
The Future of Cross-Chain Bridges: Full-Chain Interoperability Becomes Inevitable, Liquidity Bridges Will Decline
Beginner

The Future of Cross-Chain Bridges: Full-Chain Interoperability Becomes Inevitable, Liquidity Bridges Will Decline

This article explores the development trends, applications, and prospects of cross-chain bridges.
2023-12-27 07:44:05
Solana Need L2s And Appchains?
Advanced

Solana Need L2s And Appchains?

Solana faces both opportunities and challenges in its development. Recently, severe network congestion has led to a high transaction failure rate and increased fees. Consequently, some have suggested using Layer 2 and appchain technologies to address this issue. This article explores the feasibility of this strategy.
2024-06-24 01:39:17
Sui: How are users leveraging its speed, security, & scalability?
Intermediate

Sui: How are users leveraging its speed, security, & scalability?

Sui is a PoS L1 blockchain with a novel architecture whose object-centric model enables parallelization of transactions through verifier level scaling. In this research paper the unique features of the Sui blockchain will be introduced, the economic prospects of SUI tokens will be presented, and it will be explained how investors can learn about which dApps are driving the use of the chain through the Sui application campaign.
2025-08-13 07:33:39
Navigating the Zero Knowledge Landscape
Advanced

Navigating the Zero Knowledge Landscape

This article introduces the technical principles, framework, and applications of Zero-Knowledge (ZK) technology, covering aspects from privacy, identity (ID), decentralized exchanges (DEX), to oracles.
2024-01-04 16:01:13
What is Tronscan and How Can You Use it in 2025?
Beginner

What is Tronscan and How Can You Use it in 2025?

Tronscan is a blockchain explorer that goes beyond the basics, offering wallet management, token tracking, smart contract insights, and governance participation. By 2025, it has evolved with enhanced security features, expanded analytics, cross-chain integration, and improved mobile experience. The platform now includes advanced biometric authentication, real-time transaction monitoring, and a comprehensive DeFi dashboard. Developers benefit from AI-powered smart contract analysis and improved testing environments, while users enjoy a unified multi-chain portfolio view and gesture-based navigation on mobile devices.
2025-05-22 03:13:17