{"investigation":{"slug":"resolv-usr-stablecoin-minting-exploit-march-2026","entity_name":"Resolv USR Stablecoin Minting Exploit (March 2026)","trust_score":2,"severity_base":null,"score_modifier":-10,"confidence":0.88,"status":"published","content_type":"investigation","summary":"On March 22, 2026, an attacker compromised Resolv Labs' AWS Key Management Service (KMS) infrastructure to steal the SERVICE_ROLE private key controlling the USR minting contract. Using this key, the attacker deposited approximately $100,000-$200,000 in USDC across two transactions and minted approximately 80 million unbacked USR tokens at a 400-500x over-mint ratio, ultimately extracting roughly $23-$25 million in ETH. The exploit crashed USR's dollar peg by approximately 70-80% within 17 minutes, created functional insolvency for the Resolv protocol ($95M assets vs $173M liabilities), and spread cascading losses across at least 15 Morpho vaults and Fluid/Instadapp lending markets. The Resolv Foundation subsequently launched a tiered compensation plan in late May 2026 and reported completing over $77 million in phase-one redemptions by late May 2026.","sections":[{"content":"At approximately 2:21 AM UTC on Sunday, March 22, 2026, an attacker exploited the Resolv USR minting contract in two sequential transactions. In the first transaction, the attacker deposited approximately 100,000 USDC into Resolv's USR Counter contract (0xa27a69Ae180e202fDe5D38189a3F24Fe24E55861) and received 50 million USR in return — approximately 500 times the expected amount. A second minting transaction approximately two hours later produced an additional 30 million USR. The two transactions together created roughly 80 million unbacked USR tokens. Headline figures in reporting require disambiguation: '$80M exploit' refers to the notional face value of unbacked USR minted at the $1.00 peg price. '$25M extracted' (reported variously as $23M-$26.8M across sources) refers to the actual realized value the attacker obtained after converting USR through DEX swaps, constrained by on-chain liquidity and slippage. The minted USR was converted through decentralized exchanges to wstUSR, then to stablecoins, and finally to ETH. As of March 24, 2026, the primary attacker-linked wallet (0x8ED8cF0C1c531C1b20848E78f1CB32fa5b99b81C) held approximately 11,408.85 ETH (roughly $24.78 million) plus approximately $1.1 million in wrapped staked USR (wstUSR).","heading":"Incident Overview and Figure Disambiguation","sources":[{"url":"https://www.coindesk.com/markets/2026/03/23/resolv-stablecoin-drops-70-after-usd80-million-exploit-after-attacker-mints-usr","name":"Resolv stablecoin crashes 70% as attacker extracts $25 million in ETH — CoinDesk","type":"news_article","credibility":1},{"url":"https://www.theblock.co/post/394582/resolvs-usr-stablecoin-depegs-after-attacker-mints-80-million-unbacked-tokens-extracts-roughly-25-million","name":"Resolv's USR stablecoin depegs after attacker mints 80 million unbacked tokens — The Block","type":"news_article","credibility":1},{"url":"https://decrypt.co/361984/resolv-labs-stablecoin-depegs-plunges-74-after-25m-exploit","name":"Resolv Labs Stablecoin Depegs, Plunges 74% After $25M Exploit — Decrypt","type":"news_article","credibility":1},{"url":"https://www.certik.com/blog/resolv-protocol-incident-analysis","name":"Resolv Protocol Incident Analysis — CertiK","type":"research","credibility":2}],"severity":"critical"},{"content":"Security researchers identified two compounding vulnerabilities that together created the exploit. First, the minting contract's completeSwap() function enforced a minimum USR output but imposed no maximum output limit, no price oracle check, and no ratio validation between collateral deposited and USR to be minted. Any address holding the SERVICE_ROLE key could specify an arbitrarily large mint amount. Second, the SERVICE_ROLE — the off-chain signing key authorizing mint requests — was assigned to a single externally owned account (EOA) wallet (0x15CAd41e6BdCaDc7121ce65080489C92CF6de398) rather than a multisignature wallet. The protocol's admin functions did use a multisig, but the privileged minting role did not. This created a single point of failure: compromise of one private key was sufficient to authorize unlimited minting with no on-chain defense. The completeSwap() function was called via transaction 0xfe37f25e (50 million USR, March 22 at 02:21 UTC) and transaction 0x41b6b937 (30 million USR, approximately 04:21 UTC). An initial swap request was logged via transaction 0x590b5c66 at 01:50 UTC. Resolv did have an Immunefi bug bounty program and a Hypernative threat monitoring partnership; neither flagged the minting function's absence of on-chain validation prior to the exploit.","heading":"Technical Root Cause: Unchecked Mint and Single-Key Architecture","sources":[{"url":"https://www.certik.com/blog/resolv-protocol-incident-analysis","name":"Resolv Protocol Incident Analysis — CertiK","type":"research","credibility":2},{"url":"https://www.halborn.com/blog/post/explained-the-resolv-hack-march-2026","name":"Explained: The Resolv Hack (March 2026) — Halborn","type":"research","credibility":2},{"url":"https://www.chainalysis.com/blog/lessons-from-the-resolv-hack/","name":"The Resolv Hack: How One Compromised Key Printed $23 Million — Chainalysis","type":"research","credibility":2},{"url":"https://dev.to/ohmygod/the-resolv-usr-exploit-how-a-missing-max-mint-check-let-an-attacker-print-25m-from-100k-522j","name":"The Resolv USR Exploit: How a Missing Max-Mint Check Let an Attacker Print $25M From $100K — DEV Community","type":"research","credibility":2},{"url":"https://www.quillaudits.com/blog/hack-analysis/resolv-labs-exploit-explained","name":"Resolv Labs $25M Exploit: Unchecked Mint (Explained) — QuillAudits","type":"research","credibility":2}],"severity":"critical"},{"content":"The compromise of Resolv's SERVICE_ROLE signing key is attributed to a breach of Resolv Labs' AWS Key Management Service (KMS) environment. Multiple security analyses identify the alleged entry point as CVE-2026-20131, a critical (CVSS 10.0) zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) software involving insecure deserialization of user-supplied Java byte streams, enabling unauthenticated remote code execution as root. Threat intelligence firms including Recorded Future and eSentire reported that the Interlock ransomware group had been exploiting this zero-day since approximately January 26, 2026 — 36 days before Cisco issued a patch on March 18, 2026. The direct link between the Interlock group and the Resolv Labs breach has not been officially confirmed by Resolv or law enforcement as of the time of publication; this attribution is assessed as alleged and sourced from infrastructure security analysts. Resolv Labs stated it was working with law enforcement and on-chain analytics firms but made no public statement confirming the Interlock attribution or any attacker identity.","heading":"Infrastructure Compromise Vector","sources":[{"url":"https://cointegrity.io/blog/a-deepdive-into-the-resolv-labs-hack/","name":"The Resolv Labs Hack: How One AWS Credential Burned $80 Million — Cointegrity","type":"research","credibility":2},{"url":"https://hivepro.com/threat-advisory/cve-2026-20131-interlock-ransomware-exploits-critical-cisco-secure-fmc-flaw/","name":"CVE-2026-20131: Interlock Ransomware Exploits Critical Cisco Secure FMC Flaw — Hive Pro","type":"research","credibility":2},{"url":"https://www.helpnetsecurity.com/2026/03/20/cisco-fmc-interlock-ransomware-cve-2026-20131/","name":"Cisco FMC flaw was exploited by Interlock weeks before patch (CVE-2026-20131) — Help Net Security","type":"news_article","credibility":1},{"url":"https://www.recordedfuture.com/blog/march-2026-cve-landscape","name":"March 2026 CVE Landscape: Interlock Ransomware Group Exploits Cisco FMC Zero-Day — Recorded Future","type":"research","credibility":2}],"severity":"critical"},{"content":"CertiK's incident analysis identified five attacker-linked wallet addresses: 0x04A288a7789DD6Ade935361a4fB1Ec5db513caEd, 0x8ED8cF0C1c531C1b20848E78f1CB32fa5b99b81C, 0x6Db6006c38468CDc0fD7d1c251018b1B696232Ed, 0xb945eC1be1f42777F3AA7D683562800B4CDD3890, and 0x9FeeEAEc113E6d2DCD5ac997d5358eee41836e5f. The compromised SERVICE_ROLE EOA was 0x15CAd41e6BdCaDc7121ce65080489C92CF6de398. The USR Counter contract (victim) was 0xa27a69Ae180e202fDe5D38189a3F24Fe24E55861. The laundering path proceeded as follows: minted USR was wrapped to wstUSR, swapped through decentralized exchanges to stablecoins, then converted to ETH and rotated through multiple DEX pools and bridges. As of March 24, 2026, wallet 0x8ED8cF0C1c531C1b20848E78f1CB32fa5b99b81C held approximately 11,408.85 ETH (~$24.78 million) plus approximately $1.1 million in wstUSR. On approximately March 24, 2026, Resolv issued a 72-hour ultimatum to the attacker requesting return of 90% of funds in exchange for keeping 10% as a white-hat bounty. No movement of attacker funds in response to this ultimatum was publicly reported.","heading":"Attacker Wallets and Fund Flows","sources":[{"url":"https://www.certik.com/blog/resolv-protocol-incident-analysis","name":"Resolv Protocol Incident Analysis — CertiK","type":"on_chain","credibility":2},{"url":"https://www.chainalysis.com/blog/lessons-from-the-resolv-hack/","name":"The Resolv Hack: How One Compromised Key Printed $23 Million — Chainalysis","type":"on_chain","credibility":2},{"url":"https://www.theblock.co/post/394838/resolv-issues-72-hour-ultimatum-to-exploiter-for-90-return-of-25-million-in-funds","name":"Resolv issues 72-hour ultimatum to exploiter for 90% return of $25 million in funds — The Block","type":"news_article","credibility":1},{"url":"https://www.bankinfosecurity.com/cryptohack-roundup-hacker-mints-24m-from-resolv-a-31196","name":"Cryptohack Roundup: Hacker Mints $24M From Resolv — BankInfoSecurity","type":"news_article","credibility":2}],"severity":"critical"},{"content":"Within 17 minutes of the first minting transaction, USR's price on its most liquid Curve Finance pool crashed from $1.00 to approximately $0.025. The token was reported as low as $0.0025 in some on-chain measurements at peak impact. USR partially recovered to approximately $0.85 before stabilizing around $0.27 by the following Monday — a decline of approximately 72% on the week. Resolv Labs immediately paused all protocol functions and urged users not to trade USR, warning that actions during the post-exploit period could affect recovery calculations. Following the exploit, Resolv's protocol held an estimated $95 million in assets against approximately $173 million in outstanding liabilities, rendering it functionally insolvent at approximately 55% asset coverage. Prior to the exploit, Resolv's total value locked had already contracted approximately 75% over the preceding six weeks, falling from a peak of roughly $400-$684 million (figures vary by source and measurement period) to approximately $100 million.","heading":"Market and Price Impact","sources":[{"url":"https://www.coindesk.com/markets/2026/03/23/resolv-stablecoin-drops-70-after-usd80-million-exploit-after-attacker-mints-usr","name":"Resolv stablecoin crashes 70% as attacker extracts $25 million in ETH — CoinDesk","type":"news_article","credibility":1},{"url":"https://decrypt.co/361984/resolv-labs-stablecoin-depegs-plunges-74-after-25m-exploit","name":"Resolv Labs Stablecoin Depegs, Plunges 74% After $25M Exploit — Decrypt","type":"news_article","credibility":1},{"url":"https://www.ainvest.com/news/resolv-25m-flow-95m-asset-drain-23m-extraction-2603/","name":"Resolv's $25M Flow: A $95M Asset Drain Through a $23M Extraction — Ainvest","type":"news_article","credibility":2},{"url":"https://www.dlnews.com/articles/defi/resolve-labs-stablecoin-falls-80-per-cent-as-millions-tokens-minted/","name":"Resolv Labs' USR Stablecoin Depegs After $80M Exploit — DL News","type":"news_article","credibility":2}],"severity":"critical"},{"content":"The USR depeg spread losses across multiple DeFi lending protocols that had accepted USR or wstUSR as collateral or integrated them into yield strategies. Fluid (formerly Instadapp) absorbed more than $10 million in bad debt and experienced outflows exceeding $300 million in a single day, described as the worst single-day outflow in Fluid's history. Fluid subsequently secured short-term loans to cover 100% of the bad debt. Approximately 15 Morpho vaults were affected. Several Morpho vault curators — including Gauntlet — had accepted wstUSR as premium collateral against USDC loans using oracles hardcoded to price wstUSR at $1.00, on the assumption that the delta-neutral stablecoin strategy would maintain the peg. This pricing assumption failed during the depeg, enabling a secondary exploit pattern: actors purchased discounted wstUSR on open markets, posted it as collateral at the hardcoded $1.00 valuation, borrowed USDC against it, and exited with the proceeds. Approximately $6.2 million in USDC was drained from Morpho vaults by this mechanism; approximately $6 million of this total came from Gauntlet-managed vaults. Euler, Venus, Lista DAO, and Inverse Finance moved to pause USR-related markets preemptively. Aave confirmed zero USR exposure. The Resolv incident contributed to total reported 2026 DeFi losses of at least $137 million.","heading":"DeFi Ecosystem Contagion","sources":[{"url":"https://thedefiant.io/news/hacks/defi-has-seen-resolv-s-usd25m-usr-exploit-many-times-before","name":"DeFi Has Seen Resolv's $25M USR Exploit Many Times Before — The Defiant","type":"news_article","credibility":2},{"url":"https://oakresearch.io/en/analyses/investigations/the-resolv-usr-hack-curators-face-their-responsibilities","name":"The Resolv (USR) Hack: Curators Face Their Responsibilities — OAK Research","type":"research","credibility":2},{"url":"https://defiprime.com/resolv-usr-exploit","name":"The Resolv USR Exploit: $80M Minted From Thin Air, and What It Tells Us About DeFi's Trust Problem — DeFi Prime","type":"research","credibility":2},{"url":"https://cointegrity.substack.com/p/a-deepdive-into-the-resolv-labs-hack","name":"A Deepdive into the Resolv Labs Hack, and the fall of the USR Stablecoin — Cointegrity Substack","type":"research","credibility":2},{"url":"https://www.cryptopolitan.com/iotex-resolv-move-on-exploits-2026-defi-loss/","name":"IoTeX, Resolv Labs move on from exploits as 2026 DeFi losses hit $137M — Cryptopolitan","type":"news_article","credibility":2}],"severity":"high"},{"content":"Resolv Labs paused all protocol functions immediately following detection of the exploit. Approximately 9 million USR remaining in the attacker's account was burned on March 23, 2026 to partially reduce the outstanding unbacked supply. Resolv issued a 72-hour ultimatum to the attacker on approximately March 24, 2026, requesting return of 90% of funds in exchange for 10% as a bounty; no response or fund movement was publicly reported. On May 27, 2026, the Resolv Foundation announced a tiered compensation plan. Pre-incident USR and wstUSR holders — verified against a pre-exploit blockchain snapshot — are eligible for exchange at a 1:1 ratio for USDC. Post-incident holders receive a 1:0.5 ratio, intended to deter speculative profiteering from post-collapse purchases. RLP (Resolv Liquidity Provider) token holders receive 0.71 USDC per token plus additional RESOLV governance tokens valued at approximately $0.03 each. By late May 2026, over $77 million had been redeemed for allowlisted pre-exploit USR holders, representing more than 90% of that user group, completing phase one of recovery. Resolv Labs simultaneously announced Vault Street, a new institutional real-world asset (RWA) product line.","heading":"Protocol Response and Recovery","sources":[{"url":"https://news.bitcoin.com/resolv-labs-pauses-protocol-after-23m-exploit-triggers-usr-stablecoin-depeg/","name":"Resolv Labs Pauses Protocol After $23M Exploit — Bitcoin.com News","type":"news_article","credibility":2},{"url":"https://cryptonews.net/news/security/32923832/","name":"Resolv Foundation Outlines Recovery Plan Following $25M Protocol Exploit — CryptoNews.net","type":"news_article","credibility":2},{"url":"https://phemex.com/news/article/resolv-labs-completes-77-million-redemption-for-usr-holders-68936","name":"Resolv Labs Completes $77M USR Redemption — Phemex News","type":"news_article","credibility":2},{"url":"https://www.mexc.com/news/981363","name":"Resolv redeems over 90% of affected users as DeFi platforms recover from USR exploit — MEXC News","type":"news_article","credibility":2}],"severity":"high"},{"content":"Resolv Labs was founded in January 2023 by Ivan Kozlov (Co-Founder and CEO), Fedor Chmile, and Tim Shekikhachev. Kozlov holds degrees in Applied Mathematics and Physics from the Moscow Institute of Physics and Technology (MIPT) and a background in derivatives structuring at VTB Capital and FG BCS, which he has cited as the basis for the protocol's structured-product architecture. The company is based in Dubai, United Arab Emirates. In April 2025, Resolv Labs raised a $10 million seed round led by Cyber.Fund and Maven11, with participation from Coinbase Ventures, SCB Limited, Arrington Capital, Animoca Ventures, Gumi Cryptos, NoLimit Holdings, and Robot Ventures. The USR stablecoin employed a delta-neutral hedging strategy backed by ETH and BTC perpetual positions to generate yield for holders. Prior to the exploit, USR had achieved meaningful DeFi integration with approximately $500 million in TVL across Morpho, Aave, Euler, and Curve at peak.","heading":"Resolv Labs Entity Background","sources":[{"url":"https://www.coindesk.com/business/2025/04/15/resolv-labs-raises-usd10m-as-crypto-investor-appetite-for-yield-bearing-stablecoins-soars","name":"Resolv Labs Raises $10M as Crypto Investor Appetite for Yield-Bearing Stablecoins Soars — CoinDesk","type":"news_article","credibility":1},{"url":"https://www.crunchbase.com/person/ivan-kozlov-4bb9","name":"Ivan Kozlov — Co-Founder & CEO at Resolv Labs — Crunchbase","type":"other","credibility":2},{"url":"https://www.finsmes.com/2025/04/resolv-labs-closes-10m-seed-funding-round.html","name":"Resolv Labs Closes $10M Seed Funding Round — Finsmes","type":"news_article","credibility":2}],"severity":"medium"},{"content":"Security analysts noted that the Resolv exploit pattern — over-reliance on a single off-chain privileged key with no on-chain validation or mint cap — is not novel in DeFi. Reporting from The Defiant and BlockBeats identified at least four prior incidents following the same structural pattern. The hardcoded oracle problem that amplified contagion through Morpho and Fluid has been documented in multiple prior DeFi post-mortems. The incident illustrates what analysts described as a systemic gap between off-chain infrastructure security and on-chain safety assumptions: the smart contract's implicit trust in an external signer, combined with the absence of any circuit-breaker, rate limit, or anomaly detection at the contract level, meant that a single cloud credential compromise translated directly into unlimited money printing. Recommended remediations from multiple security firms include mandatory multisig controls for privileged minting roles, on-chain mint caps enforced at the contract level, independent price oracle validation relative to collateral value, and automated emergency pause mechanisms triggered by anomalous mint-ratio signals.","heading":"Systemic DeFi Security Context","sources":[{"url":"https://en.theblockbeats.news/news/61670","name":"Besides Resolv Hack, This DeFi Vulnerability Type Has Occurred Four Times — BlockBeats","type":"news_article","credibility":2},{"url":"https://defiprime.com/resolv-usr-exploit","name":"The Resolv USR Exploit: $80M Minted From Thin Air, and What It Tells Us About DeFi's Trust Problem — DeFi Prime","type":"research","credibility":2},{"url":"https://thedefiant.io/news/hacks/defi-has-seen-resolv-s-usd25m-usr-exploit-many-times-before","name":"DeFi Has Seen Resolv's $25M USR Exploit Many Times Before — The Defiant","type":"news_article","credibility":2},{"url":"https://theethereum.wiki/news/resolv-hack-25-million-usr-stablecoin-defi-exploit/","name":"Resolv Hack: How a $100K Deposit Stole $25M in ETH — The Ethereum Wiki","type":"research","credibility":2}],"severity":"medium"}],"timeline":[{"date":"2023","event":"Resolv Labs founded by Ivan Kozlov, Fedor Chmile, and Tim Shekikhachev in Dubai, UAE.","source":"Crunchbase","source_url":"https://www.crunchbase.com/person/ivan-kozlov-4bb9","date_original":"2023-01-01"},{"date":"2024-12-26","event":"SERVICE_ROLE assigned to externally owned account wallet 0x15CAd41e6BdCaDc7121ce65080489C92CF6de398 — the key later compromised in the attack.","source":"CertiK Incident Analysis","source_url":"https://www.certik.com/blog/resolv-protocol-incident-analysis"},{"date":"2025-04-15","event":"Resolv Labs raises $10M seed round led by Cyber.Fund and Maven11, with Coinbase Ventures and others participating.","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2025/04/15/resolv-labs-raises-usd10m-as-crypto-investor-appetite-for-yield-bearing-stablecoins-soars"},{"date":"2026-01-26","event":"Alleged entry point: Interlock ransomware group begins exploiting CVE-2026-20131, a zero-day in Cisco Secure Firewall Management Center, 36 days before a patch is issued. Connection to Resolv breach is alleged, not officially confirmed.","source":"Help Net Security","source_url":"https://www.helpnetsecurity.com/2026/03/20/cisco-fmc-interlock-ransomware-cve-2026-20131/"},{"date":"2026-03-18","event":"Cisco issues patch for CVE-2026-20131.","source":"Help Net Security","source_url":"https://www.helpnetsecurity.com/2026/03/20/cisco-fmc-interlock-ransomware-cve-2026-20131/"},{"date":"2026-03-22","event":"At 01:50 UTC, attacker submits swap request transaction (0x590b5c66) depositing approximately 100,000 USDC into the USR Counter contract.","source":"CertiK Incident Analysis","source_url":"https://www.certik.com/blog/resolv-protocol-incident-analysis"},{"date":"2026-03-22","event":"At 02:21 UTC, attacker calls completeSwap() (tx: 0xfe37f25e) via compromised SERVICE_ROLE key, minting 50 million USR — a ~500x over-mint ratio on the USDC deposit.","source":"CertiK / Halborn / CoinDesk","source_url":"https://www.certik.com/blog/resolv-protocol-incident-analysis"},{"date":"2026-03-22","event":"Within 17 minutes of the first mint, USR price on Curve Finance collapses from $1.00 to approximately $0.025.","source":"CoinDesk","source_url":"https://www.coindesk.com/markets/2026/03/23/resolv-stablecoin-drops-70-after-usd80-million-exploit-after-attacker-mints-usr"},{"date":"2026-03-22","event":"At approximately 04:21 UTC, second minting transaction (tx: 0x41b6b937) mints an additional 30 million USR. Total unbacked supply reaches approximately 80 million USR.","source":"CertiK Incident Analysis","source_url":"https://www.certik.com/blog/resolv-protocol-incident-analysis"},{"date":"2026-03-22","event":"Attacker converts minted USR to wstUSR, then to stablecoins, then to approximately 11,409 ETH (~$23-25 million) across decentralized exchanges and bridges.","source":"Chainalysis","source_url":"https://www.chainalysis.com/blog/lessons-from-the-resolv-hack/"},{"date":"2026-03-22","event":"Resolv Labs pauses all protocol functions. Fluid/Instadapp records $300M+ in outflows and $10M+ in bad debt. Euler, Venus, Lista DAO, and Inverse Finance pause USR markets. 15 Morpho vaults affected. Gauntlet vaults lose approximately $6 million in USDC to secondary hardcoded-oracle exploit.","source":"The Defiant / OAK Research","source_url":"https://thedefiant.io/news/hacks/defi-has-seen-resolv-s-usd25m-usr-exploit-many-times-before"},{"date":"2026-03-23","event":"Resolv Labs publicly confirms the exploit. Protocol burns approximately 9 million USR from the attacker's account. Protocol reports functional insolvency: $95M assets vs $173M liabilities.","source":"CoinDesk / Decrypt","source_url":"https://www.coindesk.com/markets/2026/03/23/resolv-stablecoin-drops-70-after-usd80-million-exploit-after-attacker-mints-usr"},{"date":"2026-03-24","event":"Resolv issues 72-hour ultimatum to the attacker requesting return of 90% of funds in exchange for 10% white-hat bounty. No attacker response or fund movement publicly reported.","source":"The Block","source_url":"https://www.theblock.co/post/394838/resolv-issues-72-hour-ultimatum-to-exploiter-for-90-return-of-25-million-in-funds"},{"date":"2026-05-27","event":"Resolv Foundation announces tiered compensation plan: 1:1 USDC for pre-incident USR/wstUSR holders; 1:0.5 USDC for post-incident holders; 0.71 USDC plus RESOLV tokens for RLP holders. Claims window runs May 26 to August 26, 2026.","source":"CryptoNews.net","source_url":"https://cryptonews.net/news/security/32923832/"},{"date":"2026-05-27","event":"Resolv Labs reports over $77 million redeemed for allowlisted pre-exploit USR holders, representing more than 90% of that group, completing phase one of recovery. Vault Street institutional RWA product line announced.","source":"Phemex News / MEXC News","source_url":"https://phemex.com/news/article/resolv-labs-completes-77-million-redemption-for-usr-holders-68936"}],"sources_used":[{"url":"https://www.coindesk.com/markets/2026/03/23/resolv-stablecoin-drops-70-after-usd80-million-exploit-after-attacker-mints-usr","name":"Resolv stablecoin crashes 70% as attacker extracts $25 million in ETH — CoinDesk","type":"news_article","archive_url":"http://web.archive.org/web/20260325001433/https://www.coindesk.com/markets/2026/03/23/resolv-stablecoin-drops-70-after-usd80-million-exploit-after-attacker-mints-usr","credibility":1,"archive_timestamp":"2026-03-25T00:14:33+00:00"},{"url":"https://www.theblock.co/post/394582/resolvs-usr-stablecoin-depegs-after-attacker-mints-80-million-unbacked-tokens-extracts-roughly-25-million","name":"Resolv's USR stablecoin depegs after attacker mints 80 million unbacked tokens — The Block","type":"news_article","archive_url":"http://web.archive.org/web/20260602062527/https://www.theblock.co/post/394582/resolvs-usr-stablecoin-depegs-after-attacker-mints-80-million-unbacked-tokens-extracts-roughly-25-million","credibility":1,"archive_timestamp":"2026-06-02T06:25:27+00:00"},{"url":"https://decrypt.co/361984/resolv-labs-stablecoin-depegs-plunges-74-after-25m-exploit","name":"Resolv Labs Stablecoin Depegs, Plunges 74% After $25M Exploit — Decrypt","type":"news_article","archive_url":"http://web.archive.org/web/20260717050626/https://decrypt.co/361984/resolv-labs-stablecoin-depegs-plunges-74-after-25m-exploit","credibility":1,"archive_timestamp":"2026-07-17T05:06:26+00:00"},{"url":"https://www.theblock.co/post/394838/resolv-issues-72-hour-ultimatum-to-exploiter-for-90-return-of-25-million-in-funds","name":"Resolv issues 72-hour ultimatum to exploiter for 90% return — The Block","type":"news_article","archive_url":"http://web.archive.org/web/20260325111826/https://www.theblock.co/post/394838/resolv-issues-72-hour-ultimatum-to-exploiter-for-90-return-of-25-million-in-funds","credibility":1,"archive_timestamp":"2026-03-25T11:18:26+00:00"},{"url":"https://www.coindesk.com/business/2025/04/15/resolv-labs-raises-usd10m-as-crypto-investor-appetite-for-yield-bearing-stablecoins-soars","name":"Resolv Labs Raises $10M Seed Round — CoinDesk","type":"news_article","archive_url":"http://web.archive.org/web/20260607203908/https://www.coindesk.com/business/2025/04/15/resolv-labs-raises-usd10m-as-crypto-investor-appetite-for-yield-bearing-stablecoins-soars","credibility":1,"archive_timestamp":"2026-06-07T20:39:08+00:00"},{"url":"https://www.helpnetsecurity.com/2026/03/20/cisco-fmc-interlock-ransomware-cve-2026-20131/","name":"Cisco FMC flaw exploited by Interlock weeks before patch (CVE-2026-20131) — Help Net Security","type":"news_article","archive_url":"http://web.archive.org/web/20260322083415/https://www.helpnetsecurity.com/2026/03/20/cisco-fmc-interlock-ransomware-cve-2026-20131/","credibility":1,"archive_timestamp":"2026-03-22T08:34:15+00:00"},{"url":"https://www.certik.com/blog/resolv-protocol-incident-analysis","name":"Resolv Protocol Incident Analysis — CertiK","type":"research","archive_url":"http://web.archive.org/web/20260724173119/https://www.certik.com/blog/resolv-protocol-incident-analysis","credibility":2,"archive_timestamp":"2026-07-24T17:31:19+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-resolv-hack-march-2026","name":"Explained: The Resolv Hack (March 2026) — Halborn","type":"research","archive_url":"http://web.archive.org/web/20260414114336/https://www.halborn.com/blog/post/explained-the-resolv-hack-march-2026","credibility":2,"archive_timestamp":"2026-04-14T11:43:36+00:00"},{"url":"https://www.chainalysis.com/blog/lessons-from-the-resolv-hack/","name":"The Resolv Hack: How One Compromised Key Printed $23 Million — Chainalysis","type":"research","archive_url":"http://web.archive.org/web/20260420024427/https://www.chainalysis.com/blog/lessons-from-the-resolv-hack/","credibility":2,"archive_timestamp":"2026-04-20T02:44:27+00:00"},{"url":"https://cointegrity.io/blog/a-deepdive-into-the-resolv-labs-hack/","name":"The Resolv Labs Hack: How One AWS Credential Burned $80 Million — Cointegrity","type":"research","archive_url":"https://web.archive.org/web/20260726190905/https://cointegrity.io/blog/a-deepdive-into-the-resolv-labs-hack/","credibility":2,"archive_timestamp":"2026-07-26T19:09:05+00:00"},{"url":"https://cointegrity.substack.com/p/a-deepdive-into-the-resolv-labs-hack","name":"A Deepdive into the Resolv Labs Hack — Cointegrity Substack","type":"research","archive_url":"https://web.archive.org/web/20260726191003/https://cointegrity.substack.com/p/a-deepdive-into-the-resolv-labs-hack","credibility":2,"archive_timestamp":"2026-07-26T19:10:03+00:00"},{"url":"https://oakresearch.io/en/analyses/investigations/the-resolv-usr-hack-curators-face-their-responsibilities","name":"The Resolv (USR) Hack: Curators Face Their Responsibilities — OAK Research","type":"research","archive_url":"http://web.archive.org/web/20260518222128/https://oakresearch.io/en/analyses/investigations/the-resolv-usr-hack-curators-face-their-responsibilities","credibility":2,"archive_timestamp":"2026-05-18T22:21:28+00:00"},{"url":"https://www.quillaudits.com/blog/hack-analysis/resolv-labs-exploit-explained","name":"Resolv Labs $25M Exploit: Unchecked Mint (Explained) — QuillAudits","type":"research","archive_url":"http://web.archive.org/web/20260417064129/https://www.quillaudits.com/blog/hack-analysis/resolv-labs-exploit-explained","credibility":2,"archive_timestamp":"2026-04-17T06:41:29+00:00"},{"url":"https://defiprime.com/resolv-usr-exploit","name":"The Resolv USR Exploit: $80M Minted From Thin Air — DeFi Prime","type":"research","archive_url":"http://web.archive.org/web/20260718155841/https://defiprime.com/resolv-usr-exploit","credibility":2,"archive_timestamp":"2026-07-18T15:58:41+00:00"},{"url":"https://thedefiant.io/news/hacks/defi-has-seen-resolv-s-usd25m-usr-exploit-many-times-before","name":"DeFi Has Seen Resolv's $25M USR Exploit Many Times Before — The Defiant","type":"news_article","archive_url":"http://web.archive.org/web/20260526151125/https://thedefiant.io/news/hacks/defi-has-seen-resolv-s-usd25m-usr-exploit-many-times-before","credibility":2,"archive_timestamp":"2026-05-26T15:11:25+00:00"},{"url":"https://news.bitcoin.com/resolv-labs-pauses-protocol-after-23m-exploit-triggers-usr-stablecoin-depeg/","name":"Resolv Labs Pauses Protocol After $23M Exploit — Bitcoin.com News","type":"news_article","archive_url":"http://web.archive.org/web/20260323060444/https://news.bitcoin.com/resolv-labs-pauses-protocol-after-23m-exploit-triggers-usr-stablecoin-depeg/","credibility":2,"archive_timestamp":"2026-03-23T06:04:44+00:00"},{"url":"https://beincrypto.com/resolv-usr-stablecoin-depegs-after-security-failure/","name":"Resolv's USR Stablecoin Plunges After $80 Million Unauthorized Mint — BeInCrypto","type":"news_article","archive_url":"https://web.archive.org/web/20260726141423/https://beincrypto.com/resolv-usr-stablecoin-depegs-after-security-failure/","credibility":2,"archive_timestamp":"2026-07-26T14:14:23+00:00"},{"url":"https://cryptobriefing.com/resolvlabs-usr-stablecoin-exploit/","name":"Resolv's USR stablecoin depegs after $80M exploit hits supply — Crypto Briefing","type":"news_article","archive_url":"http://web.archive.org/web/20260417180945/https://cryptobriefing.com/resolvlabs-usr-stablecoin-exploit/","credibility":2,"archive_timestamp":"2026-04-17T18:09:45+00:00"},{"url":"https://www.cryptopolitan.com/iotex-resolv-move-on-exploits-2026-defi-loss/","name":"IoTeX, Resolv Labs move on from exploits as 2026 DeFi losses hit $137M — Cryptopolitan","type":"news_article","archive_url":"https://web.archive.org/web/20260726101649/https://www.cryptopolitan.com/iotex-resolv-move-on-exploits-2026-defi-loss/","credibility":2,"archive_timestamp":"2026-07-26T10:16:49+00:00"},{"url":"https://hivepro.com/threat-advisory/cve-2026-20131-interlock-ransomware-exploits-critical-cisco-secure-fmc-flaw/","name":"CVE-2026-20131: Interlock Ransomware Exploits Critical Cisco Secure FMC Flaw — Hive Pro","type":"research","archive_url":null,"credibility":2,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.recordedfuture.com/blog/march-2026-cve-landscape","name":"March 2026 CVE Landscape: Interlock Ransomware Exploits Cisco FMC Zero-Day — Recorded Future","type":"research","archive_url":"http://web.archive.org/web/20260606174123/https://www.recordedfuture.com/blog/march-2026-cve-landscape","credibility":2,"archive_timestamp":"2026-06-06T17:41:23+00:00"},{"url":"https://cryptonews.net/news/security/32923832/","name":"Resolv Foundation Outlines Recovery Plan — CryptoNews.net","type":"news_article","archive_url":"https://web.archive.org/web/20260726223426/https://cryptonews.net/news/security/32923832/","credibility":2,"archive_timestamp":"2026-07-26T22:34:26+00:00"},{"url":"https://phemex.com/news/article/resolv-labs-completes-77-million-redemption-for-usr-holders-68936","name":"Resolv Labs Completes $77M USR Redemption — Phemex News","type":"news_article","archive_url":"https://web.archive.org/web/20260726192608/https://phemex.com/news/article/resolv-labs-completes-77-million-redemption-for-usr-holders-68936","credibility":2,"archive_timestamp":"2026-07-26T19:26:08+00:00"},{"url":"https://www.mexc.com/news/981363","name":"Resolv redeems over 90% of affected users — MEXC News","type":"news_article","archive_url":"https://web.archive.org/web/20260726105305/https://www.mexc.com/news/981363","credibility":2,"archive_timestamp":"2026-07-26T10:53:05+00:00"},{"url":"https://phemex.com/news/article/resolv-labs-recovers-57-of-illegally-issued-usr-stablecoins-69176","name":"Resolv Labs Recovers 57% of Illegally Issued USR — Phemex News","type":"news_article","archive_url":"https://web.archive.org/web/20260726093709/https://phemex.com/news/article/resolv-labs-recovers-57-of-illegally-issued-usr-stablecoins-69176","credibility":2,"archive_timestamp":"2026-07-26T09:37:09+00:00"},{"url":"https://www.bankinfosecurity.com/cryptohack-roundup-hacker-mints-24m-from-resolv-a-31196","name":"Cryptohack Roundup: Hacker Mints $24M From Resolv — BankInfoSecurity","type":"news_article","archive_url":"http://web.archive.org/web/20260506092442/https://www.bankinfosecurity.com/cryptohack-roundup-hacker-mints-24m-from-resolv-a-31196","credibility":2,"archive_timestamp":"2026-05-06T09:24:42+00:00"},{"url":"https://en.theblockbeats.news/news/61670","name":"Besides Resolv Hack, This DeFi Vulnerability Type Has Occurred Four Times — BlockBeats","type":"news_article","archive_url":"https://web.archive.org/web/20260726143736/https://en.theblockbeats.news/news/61670","credibility":2,"archive_timestamp":"2026-07-26T14:37:36+00:00"},{"url":"https://www.ainvest.com/news/resolv-25m-flow-95m-asset-drain-23m-extraction-2603/","name":"Resolv's $25M Flow: A $95M Asset Drain — Ainvest","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.crunchbase.com/person/ivan-kozlov-4bb9","name":"Ivan Kozlov — Co-Founder & CEO at Resolv Labs — Crunchbase","type":"other","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.dlnews.com/articles/defi/resolve-labs-stablecoin-falls-80-per-cent-as-millions-tokens-minted/","name":"Resolv Labs — DL News","type":"news_article","archive_url":"http://web.archive.org/web/20260617163122/https://www.dlnews.com/articles/defi/resolve-labs-stablecoin-falls-80-per-cent-as-millions-tokens-minted/","credibility":2,"archive_timestamp":"2026-06-17T16:31:22+00:00"}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-code-investigator","created_at":"2026-06-07T23:29:48.922089+00:00","updated_at":"2026-07-26T23:10:22.479406+00:00"}}