Another major security incident has shaken the decentralized finance (DeFi) space. On March 22, 2025, Resolv Labs' stablecoin USR was exploited through a vulnerability in its minting contract. The attacker minted 80 million unbacked USR tokens and subsequently drained approximately $25 million worth of ETH from the protocol.
Attack Details: Privileged Minting Function Abused
According to Resolv Labs, the hacker exploited a privileged minting function that lacked proper access controls. By bypassing the intended safeguards, the attacker generated a huge amount of USR tokens out of thin air. These tokens were then swapped for USDC and USDT on decentralized exchanges, and ultimately converted to ETH and withdrawn. The entire operation unfolded rapidly, catching the protocol off guard.
Market Impact: Price Plunge and Market Cap Collapse
Immediately after the attack, the USR/ETH pair on Curve crashed to $0.025, a drop of over 97%. Although the price later recovered to around $0.85, it remains well below its $1 peg. Resolv Labs paused the protocol and stated that the underlying collateral pool remained intact, but market confidence evaporated. USR's market capitalization plummeted from $400 million to $100 million, causing massive losses for holders. Several DeFi lending platforms that accepted USR as collateral have initiated liquidations to mitigate risk.
Protocol Response: Paused Operations and Compensation Promises
Resolv Labs quickly issued a security advisory, confirming all contract interactions were halted. The team is working with security firms and law enforcement to trace the funds. They emphasized that the core collateral pool (composed mainly of ETH and stablecoins) was not breached, meaning user deposits remain safe. However, the minted USR tokens have already been exchanged for real assets, putting pressure on the pool's solvency. Resolv Labs has pledged to develop a compensation plan, though details are pending. Analysts warn that this incident highlights the fundamental risk of high-yield stablecoin designs—if minting permissions are not rigorously controlled, even a partially collateralized system can collapse.
Industry Reflection: Urgent Need for Better Security and Regulation
The USR depeg is not an isolated case. Similar exploits have hit other stablecoin protocols, such as StablR losing $2.8 million. Industry experts call for stricter access controls, multi-signature wallets, and real-time monitoring systems. Regulators may accelerate efforts to oversee decentralized stablecoins. With USR's market cap shrinking from $400M to $100M, investor trust in vulnerable stablecoins has been severely damaged. For the entire crypto ecosystem, security remains the bedrock of long-term sustainable growth—any project that neglects code audits and permission management risks catastrophic consequences.

