The post DeFi Has Seen Resolv’s $25M USR Exploit Many Times Before appeared on BitcoinEthereumNews.com. The Resolv hack wasn’t a surprise. The same structural flawThe post DeFi Has Seen Resolv’s $25M USR Exploit Many Times Before appeared on BitcoinEthereumNews.com. The Resolv hack wasn’t a surprise. The same structural flaw

DeFi Has Seen Resolv’s $25M USR Exploit Many Times Before

For feedback or concerns regarding this content, please contact us at [email protected]

The Resolv hack wasn’t a surprise. The same structural flaw has drained hundreds of millions from Morpho, Euler, and Fluid over the past year and the industry kept building on top of it anyway.

On a quiet Sunday morning, someone turned $100,000 into $25 million in about seventeen minutes.

The target was Resolv, a yield-bearing stablecoin protocol. By the time Resolv paused its contracts, its dollar-pegged stablecoin USR had crashed to pennies. It remains deeply depegged, trading around $0.25 as of this writing, down more than 70% on the week.

The blast radius extended well beyond Resolv. Fluid/Instadapp absorbed more than $10 million in bad debt and had outflows of over $300 million in a single day, the worst outflow in its history. Fifteen Morpho vaults were hit. Euler, Venus, Lista DAO, and Inverse Finance all moved to pause USR-related markets.

The mechanism that caused the initial hack to spread its damage – pricing a depegged stablecoin at $1 in a lending market– is not new. It happened at least four times in the past fourteen months.

How the Hack Worked

USR’s minting followed a two-step off-chain process: a user deposited USDC via the `requestSwap’ function, and a privileged off-chain signing key, the `SERVICE_ROLE’, finalized the amount of USR to issue via `completeSwap’. The contract enforced a minimum output but had no maximum. Whatever the key holder signed, the contract honored.

The attacker gained access to that key through Resolv’s AWS Key Management Service. They submitted two USDC deposits, totaling roughly $100,000–$200,000, and used the compromised key to authorize 80 million USR in return. Etherscan shows two transactions worth 50 million USR and 30 million USR, minted in minutes.

“The Resolv USR exploit wasn’t a bug — it was a feature working exactly as designed. And that’s the problem,” said on-chain analyst Vadim (@zacodil).

The SERVICE_ROLE was a regular externally owned address, not a multisig. The admin key had multisig protection, but the mint key didn’t.

“Resolv was audited 18 times,” Vadim said. “One finding was literally called ‘Missing upper [limit]'”

The attacker exited methodically, converting minted USR into wstUSR (the staked wrapped version) to slow the market impact, then rotating through Curve, Uniswap, and KyberSwap into ETH. The attacker’s wallet holds approximately 11,400 ETH (~$24M). Resolv’s collateral pool, the ETH and BTC backing the system, survived intact even as the stablecoin crashed.

How the Contagion Spread

The Resolv hack is two incidents stacked on top of each other. The first is the mint exploit. The second is a cascading lending market failure.

When USR and wstUSR collapsed, every lending market that had accepted them as collateral faced the same problem: their oracle was still pricing wstUSR near $1.

Omer Goldberg, founder of risk analytics firm Chaos Labs, documented the mechanism. His key finding was that “The oracle is hardcoded and thus never repriced. wstUSR was marked at $1.13 while trading at ~$0.63 on secondary markets.”

Traders bought cheap wstUSR on the open market and posted it as collateral at the oracle’s $1.13 valuation on Morpho or Fluid, then borrowed USDC against it and walked away.

At Fluid, the team secured short-term loans to cover 100% of the bad debt and committed to making every user whole. At Morpho, co-founder Paul Frambot said ~15 vaults had significant exposure, all in high-risk, long-tail collateral strategies.

Prominent curator Gauntlet said that “A few high-yield vaults had limited exposure.”

But D2 Finance challenged that framing directly, posting onchain data showing Gauntlet’s flagship “USDC Core vault” had $4.95M allocated to the wstUSR/USDC market. Goldberg later said Gauntlet vaults accounted for 98% of lender liquidity in that market.

“I think the curator industry is poorly designed because there’s not actual curation happening,” said Marc Zeller on X.

Resolv, Gauntlet, Morpho and Fluid did not respond to The Defiant’s requests for comments by press time.

A Recurring Failure

This is not a novel attack. In January 2025, Usual Protocol’s USD0++ was hardcoded at $1 on Morpho vaults by curator MEV Capital. Usual abruptly changed its redemption floor to $0.87 without warning, leaving lenders stuck in the MEV Caital vault as utilization spiked to 100%.

In November 2025, Stream Finance’s xUSD collapsed after curators had routed USDC deposits into leverage loops backed by the synthetic stablecoin, leaving an estimated $285M–$700M at risk across Morpho, Euler, and Silo when its oracle refused to update. Moonwell suffered back-to-back oracle failures in October and November 2025, generating more than $5 million in combined bad debt.

What It Means for the Curator Model

Morpho’s architecture outsources all risk decisions to third-party “curators” who build vaults, choose collateral, set loan-to-value ratios, and select oracles. The theory is that specialist firms have deeper expertise, competition drives better risk management, and the protocol enforces rules.

But curators earn fees on yield generated, which creates an incentive to accept riskier, higher-yield collateral, like yield-bearing stablecoins. The downside is that when those stablecoins depeg, the losses fall on depositors, not on the curator. In the Resolv case, some curators had automated bots still refilling affected vaults hours after the exploit started, deepening losses.

The reason to hardcode oracles for yield-bearing stablecoins is to prevent short-term volatility from triggering unnecessary liquidations. But that protection only works as long as the stablecoin remains stable.

Chainalysis said in a post-mortem that real-time chain detection is needed.

“The on-chain smart contract worked perfectly. The broader system design and off-chain infrastructure apparently did not,” the analytics firm said.

Source: https://thedefiant.io/news/hacks/defi-has-seen-resolv-s-usd25m-usr-exploit-many-times-before

Market Opportunity
Resolv Logo
Resolv Price(RESOLV)
$0,0523
$0,0523$0,0523
-2,05%
USD
Resolv (RESOLV) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release

A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release

The post A Netflix ‘KPop Demon Hunters’ Short Film Has Been Rated For Release appeared on BitcoinEthereumNews.com. KPop Demon Hunters Netflix Everyone has wondered what may be the next step for KPop Demon Hunters as an IP, given its record-breaking success on Netflix. Now, the answer may be something exactly no one predicted. According to a new filing with the MPA, something called Debut: A KPop Demon Hunters Story has been rated PG by the ratings body. It’s listed alongside some other films, and this is obviously something that has not been publicly announced. A short film could be well, very short, a few minutes, and likely no more than ten. Even that might be pushing it. Using say, Pixar shorts as a reference, most are between 4 and 8 minutes. The original movie is an hour and 36 minutes. The “Debut” in the title indicates some sort of flashback, perhaps to when HUNTR/X first arrived on the scene before they blew up. Previously, director Maggie Kang has commented about how there were more backstory components that were supposed to be in the film that were cut, but hinted those could be explored in a sequel. But perhaps some may be put into a short here. I very much doubt those scenes were fully produced and simply cut, but perhaps they were finished up for this short film here. When would Debut: KPop Demon Hunters theoretically arrive? I’m not sure the other films on the list are much help. Dead of Winter is out in less than two weeks. Mother Mary does not have a release date. Ne Zha 2 came out earlier this year. I’ve only seen news stories saying The Perfect Gamble was supposed to come out in Q1 2025, but I’ve seen no evidence that it actually has. KPop Demon Hunters Netflix It could be sooner rather than later as Netflix looks to capitalize…
Share
BitcoinEthereumNews2025/09/18 02:23
XRP News: Regulatory Clarity Lifts Markets as Pepeto Nears Exchange Listings

XRP News: Regulatory Clarity Lifts Markets as Pepeto Nears Exchange Listings

According to market analysts, the SEC classifying 18 tokens as digital commodities could improve liquidity conditions across the entire market in the xrp news this
Share
Techbullion2026/03/24 03:09
Cryptos Signal Divergence Ahead of Fed Rate Decision

Cryptos Signal Divergence Ahead of Fed Rate Decision

The post Cryptos Signal Divergence Ahead of Fed Rate Decision appeared on BitcoinEthereumNews.com. Crypto assets send conflicting signals ahead of the Federal Reserve’s September rate decision. On-chain data reveals a clear decrease in Bitcoin and Ethereum flowing into centralized exchanges, but a sharp increase in altcoin inflows. The findings come from a Tuesday report by CryptoQuant, an on-chain data platform. The firm’s data shows a stark divergence in coin volume, which has been observed in movements onto centralized exchanges over the past few weeks. Bitcoin and Ethereum Inflows Drop to Multi-Month Lows Sponsored Sponsored Bitcoin has seen a dramatic drop in exchange inflows, with the 7-day moving average plummeting to 25,000 BTC, its lowest level in over a year. The average deposit per transaction has fallen to 0.57 BTC as of September. This suggests that smaller retail investors, rather than large-scale whales, are responsible for the recent cash-outs. Ethereum is showing a similar trend, with its daily exchange inflows decreasing to a two-month low. CryptoQuant reported that the 7-day moving average for ETH deposits on exchanges is around 783,000 ETH, the lowest in two months. Other Altcoins See Renewed Selling Pressure In contrast, other altcoin deposit activity on exchanges has surged. The number of altcoin deposit transactions on centralized exchanges was quite steady in May and June of this year, maintaining a 7-day moving average of about 20,000 to 30,000. Recently, however, that figure has jumped to 55,000 transactions. Altcoins: Exchange Inflow Transaction Count. Source: CryptoQuant CryptoQuant projects that altcoins, given their increased inflow activity, could face relatively higher selling pressure compared to BTC and ETH. Meanwhile, the balance of stablecoins on exchanges—a key indicator of potential buying pressure—has increased significantly. The report notes that the exchange USDT balance, around $273 million in April, grew to $379 million by August 31, marking a new yearly high. CryptoQuant interprets this surge as a reflection of…
Share
BitcoinEthereumNews2025/09/18 01:01