Resupply Hack

TOTAL LOST $10.0M
High Oracle Manipulation & Price Manipulation ethereum

What happened

Resupply's newly deployed Ethereum crvUSD-wstUSR lending pair was exploited about 95 minutes after deployment. The protocol's official postmortem timestamps the exploit at 01:53 UTC on June 26, 2025; the source record's June 25 date reflects a different reporting time zone. The attack created $10 million in reUSD bad debt by making a borrower's loan-to-value calculation resolve to zero.

Technical Root Cause

A collateral-share manipulation could make the oracle price exceed the numerator of an inverse exchange-rate calculation, causing integer division to round the rate to zero. That zero value then disabled the solvency invariant. Protocols must reject zero or otherwise invalid exchange rates before risk calculations, and must harden empty-vault share-accounting paths against donation manipulation.

Case & protocol details

Classification ERC-4626 Share Inflation / Zero-Rate Solvency Bypass
Protocol Type Lending
Smart Contract Language Solidity
Official Website resupply.fi/
Protocol Twitter/X @ResupplyFi

Market Context at Time of Hack

Token Price at Hack $1.58
Market Cap at Hack $8.0M
% of Market Cap Stolen 100.00%

Attack Timeline

The underlying CurveLend vault had no deposits. The attacker donated 2,000 crvUSD to its controller, then deposited about 2 crvUSD to mint one unit of vault-share collateral. That made convertToAssets(1e18) return 2e36.

Resupply's inverse exchange-rate calculation, exchangeRate = 1e36 / price, then rounded down to zero. Its borrow check multiplied the debt by that zero rate, producing a zero LTV and treating the borrower as solvent regardless of the actual debt. The attacker borrowed the pair's full 10 million reUSD limit and swapped the reUSD externally.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.