Resolv Labs’ stablecoin USR suffered a major depeg after an attacker exploited a flaw in the protocol’s minting contract. According to the reported details, the exploit took place on March 22, 2025, allowing the attacker to mint 80 million unbacked USR tokens and extract roughly $25 million in ETH. The incident pushed USR down to as low as $0.025 on Curve before it partially recovered to around $0.85, still well below its intended $1 peg.
Minting Role Abuse Triggered the Attack
The exploit was tied to a privileged minting role that lacked adequate access controls. This allowed the attacker to create an excessive amount of tokens, swap them into USDC and USDT, and then convert the proceeds into ETH. The event highlights how weaknesses in permission management can become critical points of failure for DeFi protocols, especially those built around stablecoin issuance and redemption mechanisms.
Protocol Paused as Confidence Takes a Hit
Following the attack, Resolv Labs said it had paused protocol functions and stated that the collateral pool remains intact. Even so, the exploit severely damaged market confidence in USR. A stablecoin can face heavy selling pressure and deep dislocations once traders begin to question whether the system can maintain redemption stability, regardless of whether the collateral itself has been directly drained.
Market Cap Collapse Underscores DeFi Stablecoin Risk
The fallout has been significant. USR’s market capitalization reportedly dropped from about $400 million to $100 million, hurting holders and spilling over into DeFi lending markets. The episode serves as another warning that higher-yield stablecoin models may carry elevated smart contract and governance risks. It also adds to broader calls for stronger security practices, tighter control over privileged functions, and more regulatory scrutiny across the DeFi sector.
Beyond the immediate losses, the USR incident shows how quickly trust can evaporate in on-chain financial systems. For users and investors, yield is only one side of the equation; contract design, access control, and emergency response mechanisms are becoming just as important in assessing protocol risk.

