Resolv Labs' USR stablecoin exploited via compromised key; attacker minted 80M tokens, causing 74% depeg.
Security & Exploits ·
A compromised private key allowed an attacker to exploit Resolv Labs' USR stablecoin contract and illegally mint 80 million tokens. The attacker then converted the unbacked USR into a staked version before swapping it across multiple DeFi protocols, ultimately extracting approximately $25 million in value. USR lost its peg to the U.S. dollar, falling more than 74% as the attacker moved to liquidate the minted tokens.
The exploit exposed a structural vulnerability in the protocol's minting mechanism. Minting approvals relied on an off-chain service using a privileged private key to authorize USR creation, and the smart contract imposed no maximum limit on how much could be minted. This allowed the attacker to generate uncollateralized tokens worth $80 million without triggering safeguards.
Resolv Labs paused all protocol functions and burned approximately $9 million in USR tokens to reduce impact. The platform stated it is working with law enforcement and onchain analytics firms to identify the attackers and contain the illicitly minted supply. It is preparing to enable redemptions for pre-incident USR starting with allowlisted users, though the precise timeline and scope of recovery remain unspecified.