Resolv USR (USR), a stablecoin tied to Resolv Labs, broke from its dollar peg after a contract exploit let an attacker mint a huge amount of unbacked supply. Resolv Labs said on Sunday that the attacker used $100,000 in USDC to mint 50 million USR. Blockchain security firm PeckShield later said the attacker also minted another 30 million USR.
The newly created tokens were then moved across multiple crypto protocols and swapped into stablecoins including USDC and USDt before being converted into ETH. That rapid exit hit liquidity hard. USR dropped to $0.50, and on Curve Finance the token briefly collapsed to $0.025.
Mint function failure opened the door to excess issuance
Resolv Labs said the exploit stemmed from a vulnerability in the USR contract that allowed the creation of tokens with no backing. D2 Finance said the issue involved the contract’s minting function. Its early assessment pointed to three possible causes: oracle manipulation, a compromised off-chain signer, or flawed amount validation that failed to block excessive minting.
For a stablecoin, the damage is immediate once the market sees supply that is not matched by collateral. Prices can detach first in liquidity pools, then across broader trading venues. In this case, weak liquidity and rising slippage made the sell-off worse.
Curve rebound trimmed losses, but the peg remains broken
At the time of reporting, USR was trading near $0.87, still about 13% below its intended $1 peg. On Curve Finance, the token hit its low at 2:38 am UTC and then rebounded quickly to around $0.845, though it did not recover the peg.
Resolv Labs has paused all protocol functions to stop any additional malicious activity. The team said it is investigating the exploit and working on a recovery plan. The source material did not include detailed remediation steps.
Hack totals fell in February, but DeFi contract risk remains
The exploit landed during a period when crypto hack losses had declined. The source cited $49 million in losses in February, compared with $385 million in January. Even so, the USR incident shows how exposed DeFi protocols remain when mint logic, oracle inputs, or signing procedures fail. Once issuance breaks, price stability, redemption confidence, and on-chain liquidity can all come under pressure at the same time.

