Resolv USR Stablecoin Minting Exploit (March 2026)
Summary
On March 22, 2026, an attacker compromised Resolv Labs' AWS Key Management Service (KMS) infrastructure to steal the SERVICE_ROLE private key controlling the USR minting contract. Using this key, the attacker deposited approximately $100,000-$200,000 in USDC across two transactions and minted approximately 80 million unbacked USR tokens at a 400-500x over-mint ratio, ultimately extracting roughly $23-$25 million in ETH. The exploit crashed USR's dollar peg by approximately 70-80% within 17 minutes, created functional insolvency for the Resolv protocol ($95M assets vs $173M liabilities), and spread cascading losses across at least 15 Morpho vaults and Fluid/Instadapp lending markets. The Resolv Foundation subsequently launched a tiered compensation plan in late May 2026 and reported completing over $77 million in phase-one redemptions by late May 2026.
Connected Entities
1 entities · 10 linked investigationsTimeline(15 events)
2023-01-01
Resolv Labs founded by Ivan Kozlov, Fedor Chmile, and Tim Shekikhachev in Dubai, UAE.
Crunchbase2024-12-26
SERVICE_ROLE assigned to externally owned account wallet 0x15CAd41e6BdCaDc7121ce65080489C92CF6de398 — the key later compromised in the attack.
CertiK Incident Analysis2025-04-15
Resolv Labs raises $10M seed round led by Cyber.Fund and Maven11, with Coinbase Ventures and others participating.
CoinDesk2026-01-26
Alleged entry point: Interlock ransomware group begins exploiting CVE-2026-20131, a zero-day in Cisco Secure Firewall Management Center, 36 days before a patch is issued. Connection to Resolv breach is alleged, not officially confirmed.
Help Net Security2026-03-22
At 01:50 UTC, attacker submits swap request transaction (0x590b5c66) depositing approximately 100,000 USDC into the USR Counter contract.
CertiK Incident Analysis2026-03-22
At 02:21 UTC, attacker calls completeSwap() (tx: 0xfe37f25e) via compromised SERVICE_ROLE key, minting 50 million USR — a ~500x over-mint ratio on the USDC deposit.
CertiK / Halborn / CoinDesk2026-03-22
Within 17 minutes of the first mint, USR price on Curve Finance collapses from $1.00 to approximately $0.025.
CoinDesk2026-03-22
At approximately 04:21 UTC, second minting transaction (tx: 0x41b6b937) mints an additional 30 million USR. Total unbacked supply reaches approximately 80 million USR.
CertiK Incident Analysis2026-03-22
Attacker converts minted USR to wstUSR, then to stablecoins, then to approximately 11,409 ETH (~$23-25 million) across decentralized exchanges and bridges.
Chainalysis2026-03-22
Resolv Labs pauses all protocol functions. Fluid/Instadapp records $300M+ in outflows and $10M+ in bad debt. Euler, Venus, Lista DAO, and Inverse Finance pause USR markets. 15 Morpho vaults affected. Gauntlet vaults lose approximately $6 million in USDC to secondary hardcoded-oracle exploit.
The Defiant / OAK Research2026-03-23
Resolv Labs publicly confirms the exploit. Protocol burns approximately 9 million USR from the attacker's account. Protocol reports functional insolvency: $95M assets vs $173M liabilities.
CoinDesk / Decrypt2026-03-24
Resolv issues 72-hour ultimatum to the attacker requesting return of 90% of funds in exchange for 10% white-hat bounty. No attacker response or fund movement publicly reported.
The Block2026-05-27
Resolv Foundation announces tiered compensation plan: 1:1 USDC for pre-incident USR/wstUSR holders; 1:0.5 USDC for post-incident holders; 0.71 USDC plus RESOLV tokens for RLP holders. Claims window runs May 26 to August 26, 2026.
CryptoNews.net2026-05-27
Resolv Labs reports over $77 million redeemed for allowlisted pre-exploit USR holders, representing more than 90% of that group, completing phase one of recovery. Vault Street institutional RWA product line announced.
Phemex News / MEXC NewsDecision Log
- hash: 7kt9f8YNVPFVnMSQ67WzVWBBkWX4Yntrbtc3ZMGMbBvq
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-code-investigator
generated: 6/7/2026, 11:29:48 PM
last updated: 6/8/2026, 1:35:05 AM
avoid.net — verified advice for a post-truth world