Skip to main content
AVOID.NET

ResupplyFi

avoid.net/resupplyfi27/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·4siiHn…8Z5o

Summary

ResupplyFi is a decentralized stablecoin lending protocol developed as a subDAO by Convex Finance and Yearn Finance, launched in March 2025. On June 25–26, 2025, an attacker exploited an ERC-4626 first-donation vulnerability in a newly deployed vault, draining approximately $9.3–9.8 million in user funds using a $4,000 flash loan. The exploit created $10 million in reUSD bad debt; following a governance-approved recovery plan, the bad debt was ultimately fully repaid through a combination of insurance pool burns, personal contributions from a core developer, Convex treasury funds, and a Yearn loan.

Connected Entities

1 entities
Protocols
ResupplyFi
Relationships
    Have evidence about ResupplyFi?

    Timeline(10 events)

    18 December 2024

    ResupplyFi publicly introduced by Convex Finance and Yearn Finance.

    Convex Finance on X

    20 March 2025

    ResupplyFi officially launches on mainnet, supporting Curve Lend and Fraxlend collateral positions for borrowing reUSD.

    Convex Finance on X

    February 2025

    Security audits by ChainSecurity and yAudit (Electi) completed approximately three to four months before the exploit, covering the ResupplyPair codebase but not deployment initialization procedures.

    Rekt News — ResupplyFi Rekt

    25 June 2025

    A new crvUSD-wstUSR lending pair vault is deployed on ResupplyFi. Within approximately two hours, an attacker executes an ERC-4626 first-donation attack, inflating vault share price to corrupt the exchange rate calculation and borrow $10 million in reUSD against 1 wei of collateral, stealing approximately $9.3 to $9.8 million. The exploit transaction hash is 0xffbbd492e0605a8bb6d490c3cd879e87ff60862b0684160d08fd5711e7a872d3.

    Ackee Blockchain Hack Analysis

    25 June 2025

    ResupplyFi team identifies and pauses the affected wstUSR market. Protocol issues initial statement confirming only the wstUSR market is impacted.

    DL News

    25 June 2025

    Stolen ETH begins moving through Tornado Cash. Attacker deposits approximately 1,607 ETH (roughly $6.5 million) into the mixer.

    PANews

    26 June 2025

    C2tP, a Convex Finance developer, publicly commits $1.4 million of personal funds toward covering user losses. Convex Finance contributes an additional $810,000 from its treasury.

    DL News

    30 June 2025

    ResupplyFi publishes a governance recovery proposal. The plan proposes burning $6 million reUSD from the insurance pool to cover remaining bad debt, with $1.13 million to be repaid gradually via protocol revenues and a Yearn loan. A shortened three-day voting period is requested.

    The Block

    July 2025

    Governance vote on recovery plan concludes. Insurance pool burn and resumption of withdrawal cooldown period proceed following approval.

    crypto.news

    August 2025

    ResupplyFi announces full repayment of the $10 million bad debt created by the exploit. $8.8 million repaid via the insurance pool burn and developer/treasury contributions; remaining $1.13 million covered by Yearn loan to be repaid through RSUP staking revenues.

    AInvest
    Provenance & Audit Trail

    Decision Log

    This investigation is cryptographically anchored to the Solana blockchain (3 events). 17 of 17 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 8/2/2026, 12:14:33 PM

    last updated: 8/26/2026, 2:08:44 PM

    3 views

    avoid.net — verified advice for a post-truth world