Resolv protocol exploited for $25M after contractor GitHub credentials were compromised, resulting in 80M USR tokens illicitly minted.
Security & Exploits ·
On March 22, 2026, Resolv's off-chain infrastructure was compromised through a multi-stage attack that exploited unauthorized access to the protocol's signing infrastructure. Attackers executed two illicit transactions via the Counter smart contract, minting 80M USR tokens and extracting approximately $25M in value as ETH, according to Resolv's postmortem. The breach originated from a third-party project where a Resolv contractor had been involved.
The Counter contract normally operates as a two-step permissionless minting mechanism: users deposit collateral on-chain, then an authorized off-chain service confirms parameters and finalizes issuance. The attackers bypassed this authorization layer by compromising the contractor's GitHub credentials, granting them access to the signing infrastructure that completes minting transactions.
Resolv has contained the incident by eliminating the attack vector and revoking compromised credentials. The protocol paused most operations and neutralized approximately 46M of the illicitly minted USR through burns and blacklist functionality. Pre-hack USR holders are being compensated 1:1, with most redemptions already processed. An active investigation continues with external security firms and blockchain forensics teams, though the full scope of impact remains under assessment.