Resolv Says No Assets Lost After USR Stablecoin Exploit

Resolv Says No Assets Lost After USR Stablecoin Exploit
Binance


Thank you for reading this post, don't forget to subscribe!

Resolv Labs moved Sunday to reassure users after an exploit hit the issuance mechanics of its USR stablecoin, knocking the token off its dollar peg and prompting decentralized finance (DeFi) protocols with exposure to move quickly to contain any fallout.

Cointelegraph reported earlier Sunday that an attacker exploited USRโ€™s minting mechanics, creating tens of millions of unbacked tokens and dumping them through DeFi pools, which broke the stablecoinโ€™s peg and prompted Resolv to pause protocol functions as it assessed the damage.

The token dropped as low as $0.14 (86% below its intended $1 price) after the exploit before rebounding to $0.42 at the time of writing, according to data from CoinGecko.

In a recent statement on X, the Resolv team said that the collateral pool โ€œremains fully intact,โ€ and that the problem appears โ€œisolated to USR issuance mechanics.โ€ Containment and impact assessment remain ongoing.

Onchain data from Arkham, corroborated by Web3 security firm Cyvers, showed that the attacker had converted most of the minted USR into Ether (ETH), selling part of the haul for about 11,400 ETH (around $24 million). Independent analysts also noted that the remaining 36.74 million USR was โ€œstill being continuously dumped.โ€

USR dropped 86% off its peg. Source. CoinGecko

Michael Pearl, vice president GTM and strategy at Cyvers, told Cointelegraph that since the supply had inflated faster than the market could absorb and the token had immediately depegged, the value of the remaining tokens was significantly impaired.

Related: Google Threat Intel flags ‘Ghostblade’ crypto-stealing malware

DeFi protocols move to contain fallout

Decentralized finance (DeFi) protocols with exposure to Resolv raced to clarify their positions. Liquid staking provider Lido said that Lido Earn user funds were safe. Morpho cofounder Merlin Egalite emphasized that the lending protocolโ€™s own contracts were unaffected and that only certain vaults had exposure, and Aaveโ€™s founder, Stani Kulechov, said that the platform had no direct USR exposure and that Resolv was repaying its outstanding debt.

The X account โ€œyieldsandmoreโ€ pointed to potential losses in Resolvโ€™s junior RLP tranche, highlighting possible knock-on effects for yield platforms such as Stream and yoUSD that used RLP as collateral.ย 

Pearl told Cointelegraph that, based on available data, the exposure appeared to be โ€œrelatively concentratedโ€ in lending markets and leverage loops โ€œrather than system-wide,โ€ and primarily in protocols that integrated USR, wstUSR, or RLP into lending, leverage or yield strategies.

Related: Hacked crypto tokens drop 61% on average and rarely recover, Immunefi report says

He said that several protocols, such as Euler, Venus, Lista and Fluid, had taken precautionary actions such as pausing markets or isolating vaults, while others had declared no exposure at all. โ€œIt is more accurate to describe the risk as concentrated with localized spillover, rather than widespread contagion,โ€ he said.

Ledger chief technical officer Charles Guillemet also assessed the fallout on X, stating that, due to the relatively small size of USR, โ€œthis is not a Terra Luna-type event.โ€

Questions around limitations of security audits

Resolvโ€™s smart contracts have undergone multiple audits since 2024, but Pearl said that, while audits were โ€œnecessary,โ€ they were also โ€œinherently static and scoped.โ€ Real-time, artificial intelligence-powered monitoring to โ€œcontinuously analyze protocol activityโ€ was needed, he argued, to detect anomalies as they emerge.

For stablecoin systems specifically, he said that meant monitoring mint and burn flows against expected behavior in real time, continuously validating supply against reserves and backing assets, and detecting anomalies in oracle inputs, pricing and liquidity conditions.ย 

Security firm Pashov, which audited Resolvโ€™s staking module in July 2025, told Cointelegraph that Resolvโ€™s design was โ€œgood,โ€ and that the root cause was โ€œnot the design so much as the private key compromise,โ€ which was likely an operational security flaw. โ€œWe have to understand how that happens,โ€ he said.

Cointelegraph reached out to Resolv Labs for comment but had not received a response by publication.

AI Eye: IronClaw rivals OpenClaw, Olas launches bots for Polymarket

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraphโ€™s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently. Read our Editorial Policy https://cointelegraph.com/editorial-policy



Source link