{"investigation":{"slug":"resolv","entity_name":"Resolv","trust_score":22,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"Resolv is a DeFi protocol issuing USR, a delta-neutral stablecoin backed by ETH with perpetual futures hedging, developed by Resolv Labs. On March 22, 2026, the protocol suffered a critical exploit in which an attacker compromised Resolv's AWS key management infrastructure to mint 80 million unbacked USR tokens, extracting approximately $23–25 million in ETH and triggering a severe stablecoin depeg. The protocol remains paused as of May 2026 while recovery and infrastructure remediation are underway.","sections":[{"content":"Resolv Labs is the company behind the Resolv protocol, a decentralized finance platform whose core product is USR, a yield-bearing stablecoin pegged to the US dollar. The protocol launched with the stated goal of providing capital-efficient, delta-neutral stablecoin infrastructure backed by Ethereum. Resolv Labs raised a $10 million seed round in April 2025, led by Cyber.Fund and Maven 11, with participation from Coinbase Ventures, Animoca Ventures, Arrington Capital, Gumi Cryptos, SCB Limited, Robot Ventures, and NoLimit Holdings.\n\nThe protocol reached a peak TVL of approximately $448 million on January 6, 2025, per DeFiLlama, before the March 2026 exploit collapsed the protocol. The RESOLV governance token has a fixed supply of 1 billion tokens, distributed as follows: 36.9% to Ecosystem & Community, 26.7% to Team & Contributors (1-year cliff, then 30-month monthly vesting), 22.4% to Investors (1-year cliff, then 24-month linear vesting), and the remainder to two airdrop tranches totaling 14%.","heading":"Background","sources":[{"url":"https://www.coindesk.com/business/2025/04/15/resolv-labs-raises-usd10m-as-crypto-investor-appetite-for-yield-bearing-stablecoins-soars","name":"","type":"other","credibility":3},{"url":"https://thedefiant.io/news/defi/stablecoin-protocol-resolv-s-tvl-soars-above-usd400-million","name":"","type":"other","credibility":3},{"url":"https://cryptorank.io/ico/resolv","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"USR is a delta-neutral stablecoin designed to maintain a $1 peg through a two-layer architecture. For every dollar of ETH deposited by users, the protocol opens an equivalent short position on perpetual futures markets to neutralize directional price exposure. This approach achieves 1:1 capital efficiency, unlike traditional overcollateralized stablecoins that require excess collateral.\n\nThe multi-token ecosystem consists of three assets: USR (the dollar-pegged stablecoin), RLP (Resolv Liquidity Pool, an insurance pool token whose holders accept first-loss risk in exchange for elevated yield), and RESOLV (the governance token). Yield is sourced from ETH staking rewards and futures funding rate income. Holders of staked USR (stUSR) and RLP both receive a portion of protocol revenue.\n\nA critical design characteristic that contributed to the March 2026 exploit was the protocol's reliance on an off-chain service to validate and authorize minting requests. The smart contracts themselves contained no on-chain check validating the ratio of collateral deposited to USR minted, no price oracle validation at the minting layer, and no maximum mint cap per transaction. This placed full trust in a single privileged off-chain signing key.","heading":"Protocol Mechanics","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-resolv-hack-march-2026","name":"","type":"other","credibility":3},{"url":"https://coinbureau.com/review/resolv-protocol-review/","name":"","type":"other","credibility":3},{"url":"https://www.chainalysis.com/blog/lessons-from-the-resolv-hack/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Prior to the March 2026 incident, Resolv Labs engaged MixBytes to conduct multiple smart contract audits, with public reports covering the stUSR module, the Treasury, the Treasury Extension, and Proof-of-Reserve (PoR) Oracles. MixBytes reported no critical, high, or medium findings in the Treasury EtherFi Extension audit, with only two low-severity issues identified. These audit reports are publicly available on MixBytes' GitHub repository.\n\nDespite these smart contract audits, the March 22, 2026 exploit exposed a critical architectural gap: the audits did not cover the off-chain infrastructure that served as the trust anchor for the minting process. The attack unfolded as follows:\n\n1. Attackers obtained GitHub credentials from a compromised third-party contractor project.\n2. Using those credentials, they deployed a malicious GitHub Actions workflow to exfiltrate sensitive credentials from Resolv's internal repositories.\n3. The exfiltrated credentials provided access to Resolv's AWS Key Management Service (KMS), where the protocol's privileged minting signing key was stored.\n4. Using the signing key, the attacker authorized two minting transactions at 02:21:35 UTC (50M USR) and approximately 03:41 UTC (30M USR), depositing only approximately $100,000–$200,000 USDC to receive 80M USR, roughly a 500x overcreation.\n5. The attacker converted the USR to approximately $23–25 million in ETH within 80 minutes.\n\nAt its lowest point, USR traded at approximately $0.0025 on Curve (a 99.75% depeg) before partially recovering to around $0.85 in subsequent hours. The exploit caused cascading damage: Fluid/Instadapp absorbed over $10 million in bad debt and saw $300 million in outflows in a single day, and 15 Morpho vaults were impacted.\n\nProtocol smart contracts were paused at 05:16 UTC on March 22. Compromised credentials were revoked at 05:30 UTC. Resolv subsequently burned approximately 46 million of the 80 million illicitly minted USR and blacklisted attacker-controlled addresses. External firms engaged for post-incident forensics include Hypernative, Hexens, MixBytes, SEAL 911, Mandiant, and ZeroShadow.\n\nThe Chainalysis post-mortem identified the root architectural failure as the absence of any on-chain sanity check on the minting ratio, meaning the smart contracts unconditionally trusted the off-chain signer's authorization regardless of the collateral-to-mint ratio.","heading":"Security & Audits","sources":[{"url":"https://resolv.xyz/blog/resolv-postmortem-march-22-2026-incident","name":"","type":"other","credibility":3},{"url":"https://www.chainalysis.com/blog/lessons-from-the-resolv-hack/","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-resolv-hack-march-2026","name":"","type":"other","credibility":3},{"url":"https://github.com/mixbytes/audits_public/blob/master/Resolv/Treasury%20Extension/README.md","name":"","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2026/03/23/resolv-stablecoin-drops-70-after-usd80-million-exploit-after-attacker-mints-usr","name":"","type":"other","credibility":3},{"url":"https://www.govinfosecurity.com/cryptohack-roundup-hacker-mints-24m-from-resolv-a-31196","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Resolv Labs was co-founded by Ivan Kozlov, who serves as CEO. Kozlov holds a Bachelor's and Master's degree in Applied Mathematics and Physics from the Moscow Institute of Physics and Technology (MIPT), where he studied from 2004 to 2010. He completed CFA Institute examinations at Levels I and II. His prior experience includes an engineering role at the Nuclear Safety Institute of the Russian Academy of Sciences and a founding role at Shadow Startup. His background in traditional finance structured products is cited as an influence on Resolv's two-tranche risk architecture.\n\nThe Wellfound and Crunchbase profiles for Resolv Labs list additional team members, though comprehensive public documentation of the full technical team and their security credentials is limited. Resolv Labs is incorporated as Resolv Digital Assets Ltd. The company is based in Dubai, United Arab Emirates.\n\nThe team's credibility has been materially impacted by the March 2026 exploit, which revealed significant weaknesses in operational security practices including the use of a single privileged signing key with no multisig redundancy, and a contractor access management failure that allowed attackers to pivot from a third-party project into Resolv's core infrastructure.","heading":"Team & Ownership","sources":[{"url":"https://www.crunchbase.com/person/ivan-kozlov-4bb9","name":"","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2025/04/15/resolv-labs-raises-usd10m-as-crypto-investor-appetite-for-yield-bearing-stablecoins-soars","name":"","type":"other","credibility":3},{"url":"https://wellfound.com/company/resolv-labs-1/people","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"**Critical — March 2026 Exploit ($23–25M loss, stablecoin depeg).** The March 22, 2026 incident is the primary risk signal for Resolv. An attacker extracted approximately $23–25 million in ETH by minting 80 million unbacked USR tokens, causing USR to depeg to as low as $0.0025. The exploit resulted from compounded operational security failures: inadequate contractor access controls, a single-key authorization model for minting with no multisig, and the complete absence of on-chain collateral-to-mint ratio validation in the smart contracts. Protocol operations remain paused as of May 2026.\n\n**High — Protocol remains non-operational.** As of May 2026, Resolv has not relaunched. Users who held USR prior to the hack are being compensated at a 1:1 rate, with the majority of pre-incident redemptions processed. Post-incident USR holders face uncertain recovery terms. The ongoing pause creates significant counterparty risk for any assets still within the protocol.\n\n**High — Architectural single points of failure.** The protocol's design placed unconditional trust in an off-chain signing service with no redundancy, no on-chain validation, and no anomaly detection triggers. Even with MixBytes' smart contract audits finding no critical issues, the attack surface extended well beyond the audited code into cloud and CI/CD infrastructure.\n\n**High — Cascading third-party damage.** The exploit caused spillover harm to at least two external protocols: Fluid/Instadapp absorbed over $10 million in bad debt and experienced $300 million in outflows, and 15 Morpho vaults were impacted. This demonstrates systemic risk when integrated DeFi protocols over-rely on Resolv's stablecoin.\n\n**Medium — Token vesting concentration.** RESOLV token allocations vest over extended timelines, but Team & Contributors (26.7%) and Investors (22.4%) — representing nearly 50% of supply — become eligible for sale after year one cliff periods. If the protocol relaunches, unlock-driven sell pressure could suppress recovery.\n\n**Medium — Regulatory and reputational uncertainty.** Resolv Labs is incorporated in the UAE and has engaged external forensics firms including Mandiant. Whether any regulatory action follows the incident is currently unknown. The project's public reputation has been severely damaged by the exploit and the ensuing stablecoin crash.\n\n**Low — Prior audits did not cover off-chain systems.** MixBytes conducted multiple smart contract audits with clean or near-clean results, but no public evidence exists of a comprehensive operational security or infrastructure audit prior to the incident. This gap is a systemic issue across many DeFi protocols.","heading":"Risk Assessment","sources":[{"url":"https://resolv.xyz/blog/resolv-postmortem-march-22-2026-incident","name":"","type":"other","credibility":3},{"url":"https://www.chainalysis.com/blog/lessons-from-the-resolv-hack/","name":"","type":"other","credibility":3},{"url":"https://blockaid.io/blog/how-a-compromised-key-minted-80m-in-resolvs-usr-stablecoin-and-triggered-a-depeg","name":"","type":"other","credibility":3},{"url":"https://finance.yahoo.com/markets/crypto/articles/resolv-23m-hack-highlights-defi-174413345.html","name":"","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/resolv-labs-exploit-explained","name":"","type":"other","credibility":3},{"url":"https://news.bitcoin.com/resolv-labs-pauses-protocol-after-23m-exploit-triggers-usr-stablecoin-depeg/","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2024-11","event":"Resolv protocol launches; TVL begins growing rapidly, rising over 380% through November–December 2024.","source":"","date_original":"2024-11-01"},{"date":"2024-12","event":"Resolv TVL hits $77 million all-time high at the time, per DeFiLlama.","source":"","date_original":"2024-12-01"},{"date":"2025-01-06","event":"Resolv TVL peaks at approximately $448 million, per DeFiLlama.","source":""},{"date":"2025-04-15","event":"Resolv Labs announces $10 million seed funding led by Cyber.Fund and Maven 11, with participation from Coinbase Ventures, Animoca Ventures, Arrington Capital, and others.","source":""},{"date":"2026-03-22","event":"Critical exploit: attacker compromises AWS KMS signing key via GitHub Actions credential exfiltration from a contractor's account. Mints 80 million USR in two transactions using ~$100K–$200K USDC, extracting $23–25M in ETH. USR depegs to $0.0025 on Curve. Protocol paused at 05:16 UTC.","source":""},{"date":"2026-03-23","event":"CoinDesk and major outlets report on the exploit. Fluid/Instadapp confirms over $10 million in bad debt and $300 million in outflows attributed to the Resolv depeg.","source":""},{"date":"2026-03-26","event":"Resolv Labs publishes official postmortem. 46 million of the 80 million illicitly minted USR burned or blacklisted. External forensic investigation begins with Hypernative, Hexens, MixBytes, SEAL 911, Mandiant, and ZeroShadow.","source":""},{"date":"2026-05-11","event":"Resolv Labs posts update on X confirming ongoing recovery coordination with affected counterparties. Protocol has not relaunched as of this date.","source":""}],"sources_used":[{"url":"https://www.coindesk.com/business/2025/04/15/resolv-labs-raises-usd10m-as-crypto-investor-appetite-for-yield-bearing-stablecoins-soars","name":"","type":"other","archive_url":"http://web.archive.org/web/20260607203908/https://www.coindesk.com/business/2025/04/15/resolv-labs-raises-usd10m-as-crypto-investor-appetite-for-yield-bearing-stablecoins-soars","credibility":3,"archive_timestamp":"2026-06-07T20:39:08+00:00"},{"url":"https://thedefiant.io/news/defi/stablecoin-protocol-resolv-s-tvl-soars-above-usd400-million","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptorank.io/ico/resolv","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829074705/https://cryptorank.io/ico/resolv","credibility":3,"archive_timestamp":"2026-08-29T07:47:05+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-resolv-hack-march-2026","name":"","type":"other","archive_url":"http://web.archive.org/web/20260414114336/https://www.halborn.com/blog/post/explained-the-resolv-hack-march-2026","credibility":3,"archive_timestamp":"2026-04-14T11:43:36+00:00"},{"url":"https://coinbureau.com/review/resolv-protocol-review/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260313042122/https://coinbureau.com/review/resolv-protocol-review","credibility":3,"archive_timestamp":"2026-03-13T04:21:22+00:00"},{"url":"https://www.chainalysis.com/blog/lessons-from-the-resolv-hack/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260420024427/https://www.chainalysis.com/blog/lessons-from-the-resolv-hack/","credibility":3,"archive_timestamp":"2026-04-20T02:44:27+00:00"},{"url":"https://resolv.xyz/blog/resolv-postmortem-march-22-2026-incident","name":"","type":"other","archive_url":"http://web.archive.org/web/20260509161218/https://resolv.xyz/blog/resolv-postmortem-march-22-2026-incident","credibility":3,"archive_timestamp":"2026-05-09T16:12:18+00:00"},{"url":"https://github.com/mixbytes/audits_public/blob/master/Resolv/Treasury%20Extension/README.md","name":"","type":"other","archive_url":"http://web.archive.org/web/20251104075925/https://github.com/mixbytes/audits_public/blob/master/Resolv/Treasury%20Extension/README.md","credibility":3,"archive_timestamp":"2025-11-04T07:59:25+00:00"},{"url":"https://www.coindesk.com/markets/2026/03/23/resolv-stablecoin-drops-70-after-usd80-million-exploit-after-attacker-mints-usr","name":"","type":"other","archive_url":"http://web.archive.org/web/20260325001433/https://www.coindesk.com/markets/2026/03/23/resolv-stablecoin-drops-70-after-usd80-million-exploit-after-attacker-mints-usr","credibility":3,"archive_timestamp":"2026-03-25T00:14:33+00:00"},{"url":"https://www.govinfosecurity.com/cryptohack-roundup-hacker-mints-24m-from-resolv-a-31196","name":"","type":"other","archive_url":"http://web.archive.org/web/20260506092608/https://www.govinfosecurity.com/cryptohack-roundup-hacker-mints-24m-from-resolv-a-31196","credibility":3,"archive_timestamp":"2026-05-06T09:26:08+00:00"},{"url":"https://www.crunchbase.com/person/ivan-kozlov-4bb9","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://wellfound.com/company/resolv-labs-1/people","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://blockaid.io/blog/how-a-compromised-key-minted-80m-in-resolvs-usr-stablecoin-and-triggered-a-depeg","name":"","type":"other","archive_url":"http://web.archive.org/web/20260613154802/https://www.blockaid.io/blog/how-a-compromised-key-minted-80m-in-resolvs-usr-stablecoin-and-triggered-a-depeg","credibility":3,"archive_timestamp":"2026-06-13T15:48:02+00:00"},{"url":"https://finance.yahoo.com/markets/crypto/articles/resolv-23m-hack-highlights-defi-174413345.html","name":"","type":"other","archive_url":"http://web.archive.org/web/20260325143921/https://finance.yahoo.com/markets/crypto/articles/resolv-23m-hack-highlights-defi-174413345.html","credibility":3,"archive_timestamp":"2026-03-25T14:39:21+00:00"},{"url":"https://www.quillaudits.com/blog/hack-analysis/resolv-labs-exploit-explained","name":"","type":"other","archive_url":"http://web.archive.org/web/20260417064129/https://www.quillaudits.com/blog/hack-analysis/resolv-labs-exploit-explained","credibility":3,"archive_timestamp":"2026-04-17T06:41:29+00:00"},{"url":"https://news.bitcoin.com/resolv-labs-pauses-protocol-after-23m-exploit-triggers-usr-stablecoin-depeg/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260323060444/https://news.bitcoin.com/resolv-labs-pauses-protocol-after-23m-exploit-triggers-usr-stablecoin-depeg/","credibility":3,"archive_timestamp":"2026-03-23T06:04:44+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:12.347802+00:00","updated_at":"2026-08-29T23:26:10.140238+00:00"}}