On March 22, 2026, the Resolv protocol suffered a devastating hack that sent its stablecoin USR into a freefall. The price dropped from its $1 peg to as low as $0.025 before partially recovering to the $0.20-$0.30 range. The root cause: a compromised private key that allowed the attacker to mint approximately 80 million unbacked tokens.
Attack Execution: How the Exploit Unfolded
The attacker used the stolen private key to mint USR en masse, then rapidly swapped the tokens for ETH and USDT via decentralized exchanges, draining roughly $23 million to $25 million. Resolv's team later confirmed that the protocol's $141 million collateral pool remained untouched, with only about $500K in direct losses recorded before the system was halted.
Emergency Response: Pause, Burn, and Redemption Plan
Immediately after detecting the breach, Resolv paused the protocol to prevent further damage. The team also burned approximately 9 million USR held by the attacker. A redemption plan went live on March 23, prioritizing verified users who held USR before the exploit. Law enforcement and blockchain analytics firms are now assisting in fund recovery. In the meantime, the team warned users not to trade affected tokens until stability returns.
Ripple Effects Across DeFi Protocols
The sudden depeg of USR triggered a cascade of problems across DeFi platforms that used the token as collateral. Many users faced forced liquidations, and some protocols had to temporarily pause operations. While a few DeFi projects stepped in to offer assistance, the incident highlights how a single stablecoin exploit can propagate risk through the entire ecosystem via cross-platform collateral dependencies.
Stablecoin Hacks in Context
This is not the first time a stablecoin has been exploited. In May 2022, TerraUSD collapsed due to a design flaw, wiping out $40 billion to $60 billion. Other major incidents include Cashio, Beanstalk (2022), Euler Finance, Curve Finance (2023), and the YU stablecoin drain in 2025-2026, each costing hundreds of millions. Cumulative DeFi hack losses now exceed $7 billion, with stablecoin exploits often causing the most widespread damage due to their role as lynchpins in lending and trading.
Attackers will continue to exploit the open, permissionless nature of DeFi to move stolen assets quickly and evade recovery. The Resolv case underscores the urgent need for robust security infrastructure and diligent maintenance — without them, innovation becomes a liability.

