Resolv Labs has burned 36.73 million USR stablecoins previously controlled by an attacker, using a contract upgrade to claw back part of the haul from a March exploit. The incident saw a single attacker mint 80 million unbacked USR with less than $200,000 in initial collateral, then dump 34 million USR for about 11,409 ETH (~$24.48 million), leaving the protocol nursing an estimated $34 million net loss.
Key Compromise Unleashed 80M Unbacked Mint
On-chain analyst Yu Jin noted that the Resolv team destroyed 36.73 million USR from the hacker's address approximately one hour ago. The exploit originated from a compromised service key in a two-step off-chain minting process, allowing the attacker to generate 80 million uncollateralized USR with minimal upfront capital. About 34 million of those tokens were rapidly swapped into ETH via DeFi liquidity pools, now sitting at address 0x8ED…81C. Chainalysis described it as a case where key management failure cascaded into systemic losses.
USR Depegged to $0.14, Partial Recovery Insufficient
Immediately after the attack, USR lost its peg on Curve and other platforms, crashing as low as $0.14 before partially recovering to the $0.23–$0.27 range. Resolv Labs claimed its collateral pool "remains intact," but liquidity providers and leveraged users across integrated protocols still absorbed slippage and forced unwinds. Although the team has removed roughly 46 million USR from the attacker's address, the ETH already extracted far exceeds the face value of the remaining tokens, resulting in a $34 million economic hit to the protocol.
Contract Upgrade Highlights Double-Edged Control
The partial burn via contract upgrade underscores how privileged admin controls can both enable and mitigate catastrophic failures in nominally decentralized systems. For traders watching Resolv's governance token RESOLV, the episode revives longstanding concerns over whether yield-bearing stablecoins can scale without introducing single points of failure. Industry voices are urging DeFi protocols to harden minting logic, rotate keys regularly, and treat backend infrastructure with the same rigor as audited smart contracts.

