Chainalysis traces Resolv's $25M exploit to a compromised AWS key that minted 80M unbacked USR tokens, revealing critical contract guardrail failures.
Security & Exploits ·
A security breach at Resolv resulted in the minting of 80 million unbacked USR tokens and a loss valued at $25 million, according to Chainalysis investigation. The exploit stemmed from a compromised AWS key that gained access to Resolv's minting contract. Resolv Labs subsequently issued a 72-hour ultimatum to the exploiter, offering a 10% settlement bonus in exchange for returning 90% of the stolen funds.
The core vulnerability centered on the minting contract's lack of on-chain safeguards. The contract contained no maximum mint ratio or other protective guardrails that could have prevented the unauthorized token creation. This design flaw meant that possession of the AWS key alone was sufficient to generate unbacked tokens at scale, bypassing typical blockchain-level restrictions.
The incident's secondary effects rippled through connected protocols; the Yuzu Team flagged heightened volatility and spiking borrowing costs on Morpho following the exploit. Whether the exploiter will comply with the ultimatum and what recovery mechanism Resolv may pursue remain unresolved.