Resolv’s USR stablecoin suffered a minting exploit that let an attacker turn an initial 100,000 USDC deposit into roughly 50 million USR, then push the amount of improperly issued tokens to 80 million in a follow-up transaction. The counterfeit supply was swapped for major stablecoins including USDC and USDT across decentralized exchanges, ending in a haul of 11,409 ETH, valued in the report at nearly $24 million.
The peg failed fast. Just 17 minutes after the exploit, USR, which was designed to hold at $1, fell to $0.025 on Curve Finance. The token later recovered to around $0.85, but that still left it well below target. The sudden jump in circulating supply weakened confidence and put immediate pressure on pool liquidity and market pricing.
Protocol activity halted after the attack
Resolv Labs, the team behind USR and the junior insurance tranche RLP, said it suspended all protocol operations after the incident in an effort to stop any additional abuse and assess the damage. The team stated that the collateral pool “remains fully intact” and said that “no underlying assets have been lost,” describing the breach as limited to USR issuance mechanics.
That did not shield token holders from losses. The inflated supply diluted existing positions, and the heavy selling that followed drained liquidity pools as the event unfolded. For users holding exposure during the attack window, the impact showed up almost immediately in portfolio value.
Analyst points to privileged account design
Blockchain analyst Andrew Hong traced the exploit to privilege escalation tied to a sensitive SERVICE_ROLE account. According to the report, the role was controlled by a single externally managed wallet rather than a multisignature setup, which allowed unlimited minting. The contract also lacked key safeguards such as price-feed checks, transaction amount validation, and hard caps on token creation.
Resolv had previously said other parts of the protocol underwent 14 audits, supported a $500,000 Immunefi bounty, and were under ongoing monitoring. Security firm Pashov, which had prior audit involvement, said the source of the exploit may have been a compromised private key instead of a flaw in the core code architecture. Cyvers CEO Deddy Lavid added that audits alone are not enough and said minting and supply changes need real-time monitoring.
Pressure spread to lending markets and insurance exposure
The fallout reached beyond the stablecoin itself. Because USR and wstUSR had been approved as collateral on several platforms, discounted tokens could be used by opportunistic traders to pull stablecoins from connected lending systems, adding liquidity strain elsewhere. Resolv’s insurance token RLP also faced possible impairment, while large positions held by Stream Finance raised the prospect of longer-lasting investor losses.
Several DeFi protocols moved to clarify their own exposure. Lido said funds in its Earn product were secure. Aave founder Stani Kulechov said the platform had no direct USR risk and that Resolv had started repaying outstanding obligations. Morpho co-founder Merlin Egalite said only selected vaults were affected by USR exposure. Over the following 24 hours, Resolv’s governance token dropped 8.5%.

