Resolv Labs, a decentralized finance (DeFi) protocol offering yield strategies tied to delta-neutral positions on bitcoin and ethereum, suffered a major exploit early Sunday morning that sent its USR stablecoin into a severe depeg. The attacker manipulated a two-step minting process to create approximately 80 million unbacked USR tokens, then rapidly converted and sold them across decentralized exchanges, extracting an estimated $23 million to $25 million in value—mostly converted into ether.
The Attack Vector: Flaw in the Minting Workflow
According to onchain data and project disclosures, the attacker initially deposited roughly $100,000 to $200,000 in USDC into a contract tied to USR issuance. By exploiting the request-and-completion flow of the minting process, the attacker was able to manipulate parameters and bypass collateral checks, minting tens of millions of USR far exceeding the initial deposit. Security analysts identified weaknesses related to a permissioned service role and insufficient validation checks between minting steps. Early assessments suggest the vulnerability may involve an off-chain component—such as a compromised signer or flawed backend validation—rather than a traditional smart contract bug.
After minting, the attacker quickly converted USR into wrapped variants and sold them on Curve, Uniswap, and other platforms. The sell-off caused the price of USR to collapse, trading as low as $0.025 in some liquidity pools before partially recovering later in the day. Several integrated protocols moved swiftly to limit exposure by pausing markets or disabling collateral tied to Resolv assets.
Team Response: Collateral Pool Secure, Investigation Underway
Resolv Labs announced it had paused all protocol functions immediately upon detection. The team emphasized that the underlying collateral pool remains intact and that no backing assets were drained. The loss is attributed entirely to the issuance of unbacked tokens, not to a compromise of the collateral. The team is currently investigating recovery options and advised users to avoid interacting with affected assets while the review continues. The protocol had previously held over $500 million in total value locked (TVL), with audits from multiple firms, a bug bounty program, and custody integrations in place.
Market Impact and Industry Implications
The exploit underscores a critical vulnerability in DeFi protocols that rely on multi-step processes with off-chain components. Despite thorough audits, the attacker was able to exploit parameter manipulation and potentially weak backend validation, resulting in a flood of unbacked stablecoins. The incident highlights the need for atomic lockstep validation between minting and collateral, robust multi-signature approvals for permissioned roles, and real-time anomaly detection systems. For the stablecoin ecosystem, it serves as a stark reminder that trust in audit reports is not enough—operational security of off-chain infrastructure is equally vital.
The attacker continues to move funds across wallets, complicating recovery efforts. The FBI has not yet commented on this specific case, but as crypto exploits grow more sophisticated, regulatory and law enforcement attention is likely to intensify. Resolv Labs has promised a detailed post-mortem once the investigation concludes.

