On March 22, 2026, at approximately 2:21 a.m. UTC, an attacker exploited a compromised AWS Key Management Service credential to mint 80 million unbacked USR stablecoins on the Resolv protocol. The attacker deposited $200,000 in USDC and received tokens worth 500 times that amount, extracting appr...
"If you're not monitoring minting and supply in real time, you're blind when it matters most." — Deddy Lavid, CEO, Cyvers
On March 22, 2026, at approximately 2:21 a.m. UTC, an attacker exploited a compromised AWS Key Management Service credential to mint 80 million unbacked USR stablecoins on the Resolv protocol. The attacker deposited $200,000 in USDC and received tokens worth 500 times that amount, extracting approximately $25 million in ETH within 17 minutes. The USR token, designed to hold a $1.00 peg, crashed to $0.025 on Curve Finance.
The direct theft was only the first-order effect. The exploit triggered cascading failures across at least six DeFi lending protocols. Morpho-based vaults managed by risk curator Gauntlet recorded $7.5 million in direct exposure. Fluid/Instadapp absorbed over $10 million in bad debt and suffered $334 million in single-day outflows — the worst in its history. In total, the incident contributed to approximately $180 million in liquidations across connected protocols. Resolv Labs has since completed $77 million in redemptions covering 90% of affected pre-exploit holders, but the event exposed a structural vulnerability in DeFi's rapidly growing risk-curator lending model.
Resolv's USR stablecoin operated on a two-step minting flow: requestSwap() accepted USDC deposits, and completeSwap() finalized USR issuance. The critical flaw: no on-chain validation enforced a deposit-to-mint ratio between the two functions. The SERVICE_ROLE — the privileged account authorized to complete swaps — was controlled by a single externally owned account (EOA), not a multisig wallet.
According to analysis by security firm Cyvers, the attacker compromised the private key through Resolv's AWS Key Management Service infrastructure. Once in control of the SERVICE_ROLE, the attacker executed two transactions:
The contract had no oracle checks, no maximum mint limits, no per-epoch caps, and no bounds validation between the request and completion steps. According to D2 Finance research, "Either the oracle was gamed, the off-chain signer was compromised, or the amount validation is simply missing." Subsequent analysis confirmed the latter: the validation was absent entirely.
Security expert Ido Sofer noted that the single-key architecture, while common in DeFi, represented "an attractive target for internal and external threats." Resolv had completed 14 audits and maintained a $500,000 Immunefi bug bounty program. None of these safeguards caught the operational key management gap.
The attack unfolded with speed that outpaced human intervention. From the first 50-million-token mint to the full depeg, 17 minutes elapsed.
The attacker swapped USR for staked variants (wstUSR), then converted to USDC on decentralized exchanges, and finally purchased approximately 9,100 ETH (~$4.55 million in the first conversion). By the time Resolv's monitoring systems flagged the anomaly, the attacker held 11,409 ETH (~$23.7 million) plus $1.1 million in residual wrapped USR.
Price trajectory:
Resolv's total value locked had already declined from over $500 million at peak to approximately $100 million before the exploit — a 75% reduction over the preceding weeks. According to multiple on-chain analysts, this pre-exploit TVL decline raised questions about whether insiders may have anticipated the vulnerability.
The exploit's second-order damage was amplified by DeFi's increasingly popular risk-curator lending model. On protocols like Morpho, third-party curators — firms like Gauntlet, Re7 Labs, kpk, and 9summits — create specialized lending vaults with custom parameters, collateral types, and risk profiles. Unlike Aave's standardized lending pools, these curated vaults operate with independent liquidity allocation and interest rate rules.
The problem: several curators had accepted USR and wstUSR as collateral in their vaults. When USR crashed, the oracle infrastructure failed to reprice in real time. According to on-chain data, Morpho's wstUSR collateral was hardcoded at $1.13 while the market price had fallen below $0.63. This created a textbook arbitrage: traders purchased discounted wstUSR on secondary markets and posted it as collateral at the inflated oracle valuation, then borrowed USDC against it.
Morpho vault exposure:
Deposits were paused on certain Morpho Frontier and Core vaults. Automated liquidity systems remained active for hours after the exploit, amplifying damage as bots continued to interact with mispriced collateral.
Multiple protocols responded by isolating exposure. Euler Labs initiated investigation and risk isolation measures. Venus, Inverse Finance, and Lista DAO paused all USR-related markets. Aave reported zero exposure. Steakhouse Financial confirmed no direct exposure in its main vaults. On-chain asset manager kpk declared "zero loss to depositors" after managing its positions through the event.
Risk curator protocols collectively hold $7.5 billion in TVL, representing approximately 10% of all lending protocol deposits. In the days following the exploit, this figure dropped from a $10 billion peak as withdrawals accelerated — dozens of vaults reached 100% utilization, temporarily locking lender capital.
Fluid (formerly Instadapp) was among the hardest hit by contagion. The protocol absorbed more than $10 million in bad debt from USR-collateralized positions. On the day of the exploit, Fluid recorded $334 million in outflows — the largest single-day withdrawal in the protocol's history.
According to reports, approximately $70 million in USR-related debt on Fluid has since been repaid. The Fluid team secured short-term loans, backed by personal financial commitments from team members, to cover 100% of the bad debt and prevent socialized losses for depositors.
The asymmetry was stark: borrowers who had posted depreciated USR as collateral remained liquid, while lenders found themselves holding claims against collateral worth a fraction of its stated value. This lender-borrower asymmetry is an inherent structural risk in the curator model, where collateral diversity increases yield potential but also expands the blast radius of any single asset failure.
Resolv Labs moved to contain damage within 24 hours. The protocol paused all functions and announced a phased recovery plan:
Resolv confirmed that the underlying collateral pool remained intact — no backing assets were stolen. The attacker exploited the minting mechanism, not the reserves. This distinction enabled the team to honor redemptions at par for pre-exploit holders using existing reserves.
The Resolv team stated it would cover all USR positions that originated before the security incident. The protocol is working with law enforcement and on-chain analytics firms to track and potentially recover the stolen ETH.
The Resolv incident is part of a worsening pattern. According to aggregated data, DeFi exploits in Q1 2026 have reached approximately $137–$138 million across 15 incidents, already exceeding the $106.8 million recorded in Q1 2025.
Largest Q1 2026 exploits by value: | Protocol | Loss | Attack Vector | |---|---|---| | Step Finance | $27.3M | Executive device phished, private key extracted | | Truebit | $26.2M | Contract vulnerability | | Resolv (USR) | $25.0M | AWS KMS key compromise, minting flaw |
A structural shift is visible in the data: private key compromise and off-chain infrastructure failures have overtaken smart contract logic bugs as the primary attack vector. Step Finance lost $27.3 million when an executive's device was compromised via phishing and the private key was extracted, draining the treasury. Resolv's exploit originated from AWS key management, not a Solidity bug.
This trend aligns with earlier findings from on-chain security researchers that key management failures now account for a larger share of DeFi losses than smart contract vulnerabilities — a pattern first identified in late 2025 and accelerating through Q1 2026.
The Resolv exploit stress-tested three assumptions underlying modern DeFi lending infrastructure:
1. Curator diversification reduces risk. The curator model's premise — that specialized risk managers will make better collateral decisions than monolithic governance — failed in practice. Multiple curators independently accepted USR as collateral, creating correlated exposure across ostensibly independent vaults. When USR failed, the blast radius was wider, not narrower, than it would have been in a single standardized pool.
2. Audits catch critical vulnerabilities. Resolv completed 14 audits and maintained an active Immunefi bounty program. The exploit bypassed all of these through an operational infrastructure gap — a compromised AWS key — that falls outside the scope of traditional smart contract auditing.
3. On-chain oracles reprice quickly enough. The hardcoded $1.13 valuation for wstUSR on Morpho persisted while the market price collapsed, enabling the secondary arbitrage attack. Oracle latency and design choices amplified losses beyond the initial exploit.
Aave founder Stani Kulechov has previously highlighted risks in the curator model, noting that vault lockdowns and depeg events can trap user capital when curators pause operations.
The Resolv USR exploit was a $25 million theft that produced over $500 million in secondary market impact. It demonstrated that DeFi's security perimeter has shifted from smart contract logic to operational infrastructure — key management, cloud provider security, and real-time monitoring. The 14 audits and half-million-dollar bug bounty were irrelevant to the actual attack vector.
More consequentially, the contagion pattern exposed structural fragility in the curator-based lending model that now manages 10% of DeFi lending deposits. The model's core value proposition — that specialized risk managers allocate capital more efficiently than protocol-level governance — requires those managers to accurately price tail risk in novel collateral assets. The evidence from March 22 suggests they do not.
Resolv's $77 million redemption program and Fluid's team-backed debt coverage represent functional crisis responses, but they rely on discretionary human intervention rather than protocol-level safeguards. For a sector predicated on removing trusted intermediaries, the pattern is notable.