Resolv Labs said its USR stablecoin protocol was exploited after an attacker abused a flaw in the minting contract to create about 80 million unbacked USR in two transactions. The unauthorized minting broke the token’s dollar peg and sent USR sharply lower, with onchain data showing the stablecoin fell as low as $0.025 on Curve before partially recovering. The attacker reportedly withdrew about $25 million, swapping the illicitly minted USR into USDC and USDT on decentralized exchanges before converting the proceeds into ETH.
Onchain analysts said the incident appeared to stem from a deeper architectural weakness rather than only a compromised private key, pointing to a single externally owned account holding the privileged SERVICE_ROLE and a minting system that lacked oracle checks, amount validation, and maximum mint limits. One reported path allowed a deposit of 100,000 USDC to mint 50 million USR. Resolv said it is working with law enforcement and blockchain analytics firms, warned users not to trade USR during recovery efforts, and said it would pursue asset recovery as the attacker was reported to still hold 11,409 ETH and about $1.1 million in wrapped USR.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
In its first public recovery update, Resolv said 98% of whitelisted USR holders had already been redeemed at a 1:1 ratio and promised the same treatment for non-whitelisted holders who held USR before the exploit once the process is finalized. The company said recovery remained unresolved for post-depeg buyers, liquidity providers, and RLP holders.
During its recovery response, Resolv publicly offered the attacker 10% of the stolen ETH in exchange for returning the remaining funds within 72 hours. The company said it would otherwise coordinate with exchanges, law enforcement, blockchain analytics firms, and legal counsel to pursue recovery.
Resolv Labs said it was working with law enforcement and onchain analytics firms to investigate the exploit and pursue asset recovery. The company also warned users not to trade USR while recovery efforts were underway.
As USR lost its peg, lending protocols that continued valuing USR or wstUSR near $1 suffered cascading bad debt and emergency pauses. Fluid/Instadapp reportedly absorbed more than $10 million in bad debt and saw over $300 million in outflows, while Morpho, Euler, Venus, Lista DAO, and Inverse Finance were also affected.
After minting the tokens, the attacker swapped the illicit USR into USDC and USDT on decentralized exchanges and converted the proceeds into ETH, extracting roughly $25 million. The unauthorized minting caused USR to lose its dollar peg, falling as low as $0.025 before partially recovering.
An attacker abused a flaw in Resolv's USR stablecoin minting system, using privileged access and weak validation controls to mint about 80 million unbacked USR in two transactions. Onchain analysis indicated the issue stemmed from an architectural weakness around a single externally owned account holding the SERVICE_ROLE, not just a simple private key compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
thedefiant.io
Open sourcetherecord.media
Open sourcecoindesk.com
Open sourcethedefiant.io
Open sourcethedefiant.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.