On March 22, 2026, at 2:21 AM UTC, an attacker deposited $100,000 in USDC into Resolv Labs' USR stablecoin protocol and received 50 million USR in return — roughly 500 times the expected output. Within 17 minutes, USR crashed 97% on Curve Finance, falling from $1.00 to $0.025. The attacker extrac...
"This single point of failure is an attractive target for internal and external threats." — Ido Sofer, Founder, Sodot (crypto key management firm)
On March 22, 2026, at 2:21 AM UTC, an attacker deposited $100,000 in USDC into Resolv Labs' USR stablecoin protocol and received 50 million USR in return — roughly 500 times the expected output. Within 17 minutes, USR crashed 97% on Curve Finance, falling from $1.00 to $0.025. The attacker extracted approximately $25 million in ETH before the protocol froze operations.
The exploit was not a novel zero-day or a complex reentrancy attack. It was an access-control failure: a single externally owned account (EOA) controlled the protocol's minting authority with no on-chain caps, no oracle checks, and no multisig protection. The attacker compromised Resolv's AWS Key Management Service environment, gained access to the privileged signing key, and printed $80 million worth of unbacked stablecoins.
The incident pushes Q1 2026 DeFi losses to $137 million across 15 separate exploits — a 28% increase over the same period in 2025. It also exposes a systemic problem: yield-bearing stablecoins that scaled to hundreds of millions in TVL during points season without proportionate investment in operational security infrastructure.
USR is a dollar-pegged stablecoin issued by Resolv Labs, backed by ETH, staked ETH, and Bitcoin, with directional price risk hedged through perpetual futures — a so-called delta-neutral design. The protocol raised $10 million in seed funding from Coinbase Ventures, Maven 11, and Animoca Brands. At its peak in February 2025, Resolv held over $500 million in TVL.
By the time of the attack, USR's market capitalization had already declined 75% over six weeks, falling from approximately $400 million in early February 2026 to roughly $100 million.
The attack proceeded in two transactions. In the first, the attacker deposited approximately $100,000 in USDC via the protocol's requestSwap() function and received 50 million USR — an over-mint of roughly 500x. A second transaction produced an additional 30 million USR. Total unbacked tokens created: approximately 80 million.
The attacker then swapped the minted USR for USDC and USDT across Curve, KyberSwap, and Velodrome, converting the proceeds into ETH. According to PeckShield, early conversions alone totaled over $4.55 million worth of ETH (approximately 9,100 ETH). The attacker's identified wallet ultimately held 11,409 ETH (~$23.7 million) and 20 million wstUSR (~$1.3 million at depressed prices).
USR crashed to $0.025 on Curve Finance within 17 minutes of the first mint. It partially recovered to $0.85 before settling at $0.27 as of Monday, March 23 — still 73% below its intended $1.00 peg.
Resolv's minting mechanism used a two-step process: requestSwap() initiated a deposit, and completeSwap() finalized the mint. The second step required authorization from a SERVICE_ROLE — a privileged account that signed off on how much USR to create for a given collateral deposit.
The vulnerability was structural, not algorithmic. According to security analysis by Chainalysis and independent researchers, the following safeguards were absent:
The smart contract's only check was that a valid cryptographic signature existed. It did not verify whether the amount was reasonable.
The SERVICE_ROLE's private key was stored in Resolv's AWS Key Management Service (KMS) environment. According to Chainalysis, the attacker gained access to this environment, allowing them to generate valid signatures for arbitrary mint amounts. D2 Finance summarized the three possible vectors: "Either the oracle was gamed, the off-chain signer was compromised, or the amount validation between request and completion is simply missing."
The protocol's admin role did use multisig protection. The minting authority — the function that could print unbacked money — did not.
The Resolv exploit did not stay contained within a single protocol. USR and its wrapped derivative (wstUSR) were integrated across multiple DeFi lending and yield platforms, creating cascading exposure:
Gauntlet (Morpho vault curator) reported approximately $4.95 million in wstUSR/USDC exposure through its USDC Core vault on Morpho, with total estimated exposure across affected vaults exceeding $7.5 million. Gauntlet paused deposits on affected Morpho Frontier and Core vaults.
Euler Labs reported it was investigating and had isolated USR-related risk within its vaults.
Aave confirmed zero exposure. Founder Stani Kulechov publicly stated the protocol held no USR positions.
Steakhouse Financial, which served as risk manager for Resolv and had published a risk assessment days before the exploit, reported zero direct exposure to the protocol.
Multiple additional protocols — Fluid/Instadapp, Venus, Inverse Finance, and Lista DAO — paused USR markets as a precaution.
The contagion pattern illustrates what DeFiPrime described as "integration risk compounding": yield curators operating three layers removed from the underlying minting contracts inherit exposure they may not fully understand.
Resolv's trajectory followed a pattern common to DeFi protocols during points season: rapid TVL growth driven by yield incentives, outpacing investment in operational security.
The protocol scaled from under $50 million to over $650 million in TVL in under three months during its incentivized growth phase. It had completed audits and maintained a partnership with Hypernative for real-time threat detection. Neither caught the core vulnerability.
The flaw was not exotic. Input validation and access-control design are foundational software engineering concerns. Security researcher @andrewhong5297 and Cyvers both noted that the vulnerability — an EOA-controlled service role without transaction-level validation — represented a failure in basic security architecture despite the protocol's claim to have passed audits.
This gap between audit completion and actual operational security is not unique to Resolv. It reflects a broader pattern in DeFi where security reviews focus on contract logic while operational key management, deployment architecture, and integration risk receive less scrutiny.
The Resolv exploit contributes to a Q1 2026 total of approximately $137 million in DeFi losses across 15 incidents, according to data aggregated by TechFlow and CryptoRank. This represents a 28% increase over Q1 2025's approximately $106.8 million.
Notable Q1 2026 incidents by size:
| Protocol | Loss | Type | |----------|------|------| | Step Finance | $27.3M | Exploit | | Truebit | $26.2M | Exploit | | Resolv Labs | ~$25M | Key compromise / minting exploit | | SwapNet | $13.4M | Exploit | | Moonwell | $1.78M | Lending exploit | | IoTeX | Undisclosed | Cross-chain bridge exploit |
The data shows that key compromise and access-control attacks — rather than novel smart contract bugs — account for a growing share of DeFi losses. The Resolv incident, like the 2024 Microsoft Azure AD signing key compromise that affected multiple U.S. government agencies, demonstrates that off-chain key management infrastructure remains a persistent weak point.
Resolv Labs paused all protocol functions immediately after detecting the exploit. The team burned approximately $9 million in illicitly minted USR to reduce circulating supply and stated it is "working with law enforcement and onchain analytics firms" to identify the attacker.
The protocol reported $95 million in remaining assets against $173 million in liabilities — making it functionally insolvent at current valuations. Resolv stated it will cover all USR positions that originated before the security incident and enable redemptions for pre-incident holders, starting with an allowlist.
The attacker's wallet has been identified and is being tracked by PeckShield, Cyvers, D2 Finance, and community researchers. No funds have been recovered. No formal postmortem has been published.
USR's recovery to its $1.00 peg depends on the protocol's ability to reconcile its asset-liability gap and restore user confidence — a challenge complicated by the 75% TVL decline that preceded the attack.
The Resolv USR exploit is not a story about a clever hacker finding a novel vulnerability. It is a story about a protocol that gave a single key the power to print unlimited money, stored that key in a cloud environment, and deployed no on-chain safeguards to limit the damage if it was compromised.
The $25 million loss is significant but not unprecedented. The structural lesson is more important: as DeFi protocols compete for TVL through yield incentives and points programs, the gap between growth velocity and security investment continues to widen. Resolv scaled from $50 million to $650 million in under three months. Its minting architecture never caught up.
For the stablecoin sector — already under legislative scrutiny as the U.S. Senate debates yield-bearing stablecoin rules under the CLARITY Act — the incident adds data to a growing case that protocol-level risk management standards need to match the pace of capital inflows. The question is no longer whether DeFi protocols can attract capital. It is whether they can keep it safe once it arrives.