Resolv Labs has provided a fresh update on the exploit that allowed an attacker to mint 80 million USR tokens using a compromised private key. CEO Ivan Kozlov confirmed this week that the first phase of redemptions for whitelisted holders is nearly complete, while other affected groups remain in limbo.
Whitelisted wallets processed manual redemptions within 24 hours. Kozlov stated that about 98% of those requests have been fulfilled, helping to prevent broader market disruption. The same 1:1 redemption commitment applies to non-whitelisted pre-exploit holders, but the technical solution for them is still under development.
Post-exploit users and RLP holders face legal and technical hurdles
Post-exploit holders, liquidity providers, and RLP participants face a more complex process. Kozlov said these cases require coordination across legal, technical, and ecosystem layers, with no single solution finalized. RLP token holders, who initially absorbed losses by design, have redemptions paused. Kozlov acknowledged a recovery plan is being worked on but provided no timeline.
Private key exploit: no multisig, no on-chain mint cap
The attack exploited a private key tied to a privileged minting role. The account lacked multisignature protection and had no on-chain mint cap, allowing unrestricted token creation. Despite prior audits, monitoring, and bug bounty programs, Kozlov admitted these measures proved insufficient.
Investigations by cybersecurity firm Mandiant and blockchain intelligence group zeroShadow have found no evidence of insider wrongdoing so far. The probe continues. Resolv has engaged legal advisors Paul Hastings and Carey Olsen; Kozlov noted that legal considerations now limit what the team can disclose.
For now, the recovery process continues without a defined timeline, leaving affected users waiting for further updates.

