Resolv Labs Hacked: $23M Exploit Causes USR Stablecoin to Depeg to $0.025

Resolv Labs Hacked: $23M Exploit Causes USR Stablecoin to Depeg to $0.025

N
News Editor 01
2026-07-08 19:00:23
DeFi protocol Resolv Labs suffered a $23M exploit after an attacker minted 80 million unbacked USR tokens through a minting flaw, causing USR to depeg to $0.025. The protocol has been paused; collateral remains intact.
DeFi securitystablecoin depeghackResolv LabsUSR

Resolv Labs, a decentralized finance protocol offering yield strategies tied to delta-neutral positions on Bitcoin and Ethereum, halted all operations early Sunday after an attacker exploited a minting vulnerability to generate approximately 80 million unbacked USR stablecoins. The incident sent USR crashing from its $1 peg to as low as $0.025 in certain liquidity pools, marking one of the most severe stablecoin depegs in recent months.

What Happened?

According to on-chain data and official disclosures, the attacker deposited roughly $100,000 to $200,000 in USDC into a contract tied to USR issuance. By manipulating parameters within the two-step minting process—specifically the request and completion flow—the attacker was able to mint approximately 80 million USR, far exceeding the initial deposit and creating a massive pool of unbacked tokens.

Security analysts point to weaknesses in a permissioned service role and insufficient validation checks between minting steps. Early assessments suggest the root cause may involve an off-chain component, such as a compromised signer or flawed backend validation, rather than a traditional smart contract bug. This highlights the growing complexity of DeFi attack vectors that blend on-chain and off-chain infrastructure.

Market Impact and Fund Movements

After minting the tokens, the attacker rapidly converted USR into wrapped variants and dumped them across multiple decentralized exchanges, including Curve and Uniswap. The selling pressure caused USR prices to collapse; in some pools the token traded at just a few cents. The attacker extracted an estimated $23 million to $25 million, largely converted into Ethereum, and continued moving funds across wallets to evade tracking.

The depeg triggered immediate responses from integrated protocols, which paused markets or disabled collateral tied to Resolv assets to limit exposure. USR partially recovered later in the day but still traded significantly below its peg at around $0.05 at the time of writing.

Resolv Labs’ Response

Resolv Labs said it paused all protocol functions immediately and is investigating recovery options. The team emphasized that the underlying collateral pool remains intact and that no backing assets were drained, framing the loss as a result of unbacked issuance rather than collateral failure. “Our focus is on securing remaining funds and determining the best path forward for users,” the team stated. Users were advised to avoid interacting with affected assets while the review continues.

Background

Before the breach, Resolv Labs had a total value locked (TVL) exceeding $500 million, supported by audits, a bug bounty program, and custody integrations. The protocol’s USR stablecoin was marketed as a dollar-pegged asset backed by liquid collateral, but the incident lays bare the risks of complex minting mechanisms even in audited systems. The exploit also raises questions about the security of off-chain signing and validation processes, which are increasingly targeted by attackers.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
800

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.