Resolv Labs attacker continues laundering stolen funds, moving $184K ETH to mixers while still holding $19.2M.
Security & Exploits ·
The attacker behind the Resolv Labs exploit continues to move stolen funds toward mixers, sending approximately $184K in ETH in a recent transaction while retaining control of roughly $19.2M in remaining stolen assets. The original exploit, which occurred in March 2026, leveraged a compromised AWS key to mint approximately 80 million unbacked USR tokens and extract $23–25 million in value from the protocol.
The ongoing fund movements indicate an attempt to obscure the origin and ownership of the stolen assets through mixing services—a common technique for laundering proceeds from major exploits. The attacker's gradual disbursement to mixers, rather than a single bulk transfer, may reflect both operational caution and the practical constraints of moving large amounts through privacy services without triggering detection or liquidity bottlenecks.
What remains unclear is the timeline and final destination of the remaining $19.2M held by the attacker, whether additional transfers to mixers are planned, and what recovery mechanisms Resolv has implemented or can implement to address the outstanding losses. The protocol has launched a three-month recovery program for affected USR, RLP, and LP users, though the extent to which stolen funds can be recovered through on-chain tracing or law enforcement channels is not yet determined.