Resolv Hack
What happened
On 22 March 2026, an attacker minted 80M unbacked USR, Resolv Labs' stablecoin, and turned about $25M of it into ETH. The attacker first reached Resolv's cloud infrastructure through a supply-chain compromise. They then used Resolv's own minting service key to approve two mints worth vastly more than the deposits behind them.
USR fell about 97% on Curve within minutes as the attacker sold through DEXes. Resolv paused its contracts at 05:16 UTC, about three hours after the first mint. It burned or blacklisted about 46M of the illicit USR and compensated pre-exploit USR holders 1:1.
How it happened
- A Resolv contractor had contributed to a third-party project whose GitHub account was compromised. The attacker used that access to run malicious CI/CD workflows that leaked infrastructure secrets.
- With those cloud credentials, the attacker changed a key policy and gained signing authority for the
SERVICE_ROLEkey. That key finalizes USR mint requests. - USR minting is a two-step flow. A user deposits collateral on-chain, then the backend key submits how much USR to mint. The contract checked for a valid signature but put no cap on the amount relative to the collateral.
- At 02:21 UTC and 03:41 UTC, the attacker deposited about $100k USDC in each of two transactions and had 50M and then 30M USR minted.
- The attacker wrapped USR into
wstUSRto reach deeper liquidity, swapped through Curve, Uniswap and aggregators into stablecoins and then ETH, and consolidated about 11,400 ETH. No mixer was used.
Protocol details
Evidence
- report @ResolvLabs incident report x.com
- report Resolv Labs - Rekt rekt.news
- report @ResolvLabs incident report x.com
- report @CertiKAlert incident report x.com
- report @PeckShieldAlert incident report x.com
- report @AMLBotHQ incident report x.com
- report Resolv Postmortem: March 22, 2026 Incident resolv.xyz
- analysis DeFiLlama defillama.com
- analysis Resolv Protocol Incident Analysis certik.com
- analysis resolv.xyz page resolv.xyz resolv.xyz
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.