Decentralized finance protocol Resolv Labs was exploited early Sunday morning, allowing an attacker to mint tens of millions of unbacked USR stablecoins and drain approximately $23–25 million in value. The USR token, which was pegged to the dollar, collapsed to as low as $0.025 in some liquidity pools before partially recovering.
How the Attack Worked
According to on-chain data and project disclosures, the attacker deposited roughly $100,000 to $200,000 in USDC into a contract associated with USR issuance. They then exploited a two-step minting process by manipulating parameters in the request and completion flow, minting about 80 million USR — far exceeding the initial deposit and creating a massive pool of unbacked tokens. Analysts pointed to weaknesses tied to a permissioned service role and insufficient validation checks between minting steps. Early assessments suggest the issue may involve an off-chain component, such as a compromised signer or flawed backend validation, rather than a traditional smart contract bug.
Market Impact and Depeg
After minting the tokens, the attacker quickly converted USR into wrapped variants and sold across multiple decentralized exchanges, including Curve and Uniswap. Prices collapsed during the sell-off, with USR trading as low as $0.025 in certain pools. The attacker extracted an estimated $23 million to $25 million, largely converted into Ethereum, while continuing to move funds across wallets. The exploit triggered a swift depeg, with USR falling from $1 to as low as $0.025 before partially recovering later in the day. Several integrated protocols moved quickly to limit exposure, pausing markets or disabling collateral tied to Resolv assets.
Protocol Response and Status
Resolv Labs said it paused all protocol functions immediately and is investigating recovery options. The team emphasized that the underlying collateral pool remains intact and that no backing assets were drained, framing the loss as a result of unbacked issuance rather than collateral failure. Users were advised to avoid interacting with affected assets while the review continues. Prior to the breach, the protocol’s total value locked exceeded $500 million, supported by audits, a bug bounty program, and custody integrations. The incident underscores the risks of multi-step processes with off-chain components, even for audited protocols.

