Exchanging 200,000 for nearly 100 million, DeFi stablecoins face another attack
Written by: Eric, Foresight News
Around 10:21 Beijing time today, Resolv Labs, which issues the stablecoin USR using a Delta neutral strategy, was hacked. An address starting with 0x04A2 minted 50 million USR from the Resolv Labs protocol using 100,000 USDC.
As the incident came to light, USR plummeted to around $0.25, and as of the time of writing, it has rebounded to about $0.8. The price of the RESOLV token also saw a temporary drop of nearly 10%.
Subsequently, the hacker replicated the method and minted 30 million USR again using 100,000 USDC. With the significant decoupling of USR, arbitrage traders quickly acted, and many lending markets on Morpho that support USR, wstUSR, and other collateral types have been nearly emptied, while Lista DAO on the BNB Chain has also suspended new loan requests.
The impact is not limited to these lending protocols. In the design of the Resolv Labs protocol, users can also mint a more volatile and higher-yielding RLP token, but they need to bear compensation responsibilities when the protocol incurs losses. Currently, the circulation of RLP tokens is nearly 30 million, with the largest holder, Stream Finance, holding over 13 million RLP, resulting in a net risk exposure of about $17 million.
Indeed, Stream Finance, which previously suffered due to the xUSD incident, may be hit again.
As of the time of writing, the hacker has converted USR into USDC and USDT and continues to buy Ethereum, having already purchased over 10,000. With 200,000 USDC, they have extracted over $20 million in assets, finding their "hundredfold coin" during the bear market.
Another Exploitation Due to "Lack of Rigor"
The sharp decline on October 11 last year caused many stablecoins issued using Delta neutral strategies to incur collateral losses due to ADL (automatic deleveraging). Some projects that executed strategies using altcoins suffered even heavier losses or went directly bankrupt.
The attacked Resolv Labs also issued USR using a similar mechanism. The project announced in April 2025 that it had completed a $10 million seed round led by Cyber.Fund and Maven11, with participation from Coinbase Ventures, and launched the RESOLV token in late May to early June.
However, the reason for Resolv Labs being attacked was not due to extreme market conditions, but rather the "lack of rigor" in the design of the USR minting mechanism.
Currently, no security company or official has analyzed the reasons for this hacking incident. The DeFi community YAM has preliminarily concluded through analysis that the attack was likely caused by the hacker controlling the SERVICE_ROLE used by the protocol's backend to provide parameters for the minting contract.
According to Grok's analysis, when users mint USR, they initiate a request on-chain and call the contract's requestMint function, with parameters including:
_depositTokenAddress: the address of the deposited token;
_amount: the amount deposited;
_minMintAmount: the minimum expected amount of USR to receive (to prevent slippage).
Afterward, users deposit USDC or USDT into the contract, and the project's backend SERVICE_ROLE monitors the request, using the Pyth oracle to check the value of the deposited assets, and then calls the completeMint or completeSwap function to determine the actual amount of USR minted.
The problem lies in the fact that the minting contract completely trusts the _mintAmount provided by the SERVICE_ROLE, believing that this number has been verified off-chain by Pyth, thus no upper limit was set, nor was there any on-chain oracle verification, directly executing mint(_mintAmount).
Based on this, YAM suspects that the hacker controlled the SERVICE_ROLE that should have been controlled by the project team (possibly due to internal oracle failure, collusion, or key theft), directly setting the _mintAmount to 50 million during minting, achieving the attack event of minting 50 million USR with 100,000 USDC.
Ultimately, Grok concluded that Resolv did not consider the possibility that the address (or contract) used to receive user minting requests could be controlled by hackers when designing the protocol. When the request to mint USR was submitted to the contract that ultimately mints USR, no maximum minting amount was set, nor was there a secondary verification using an on-chain oracle, directly trusting all parameters provided by the SERVICE_ROLE.
Prevention Measures Were Also Inadequate
In addition to speculating on the reasons for the hack, YAM also pointed out the project's inadequate preparation for crisis response.
YAM stated on X that Resolv Labs only paused the protocol three hours after the hacker's first attack, with about one hour of that delay coming from the need to collect four signatures for the multi-signature transaction. YAM believes that an emergency pause should only require one signature, and that authority should be distributed as much as possible to team members or trusted external operators, which would increase awareness of on-chain anomalies, improve the likelihood of a quick pause, and better cover different time zones.
While the suggestion that a single signature could pause the protocol is somewhat radical, requiring multiple signatures across different time zones to pause the protocol could indeed delay significant matters in an emergency. Introducing trusted third parties that continuously monitor on-chain behavior or using monitoring tools with emergency pause protocol authority are lessons learned from this incident.
Hacker attacks on DeFi protocols are no longer limited to contract vulnerabilities. The incident involving Resolv Labs serves as a warning to project teams: assumptions about protocol security should not trust any single link, and all parameter-related processes must undergo at least secondary verification, including those operated by the project team itself.
You may also like

6MV Founder: In 2026, the "landmark turning point" for crypto investment has arrived

Abraxas Capital Mints $2.89 Billion USDT: Liquidity Boost or Just More Stablecoin Arbitrage?
Abraxas Capital just received $2.89 billion in freshly minted USDT from Tether. Is this a bullish liquidity injection for crypto markets, or is it business as usual for a stablecoin arbitrage giant? We analyze the data and the likely impact on Bitcoin, altcoins, and DeFi.

A VC from the Crypto world said AI is too crazy, and they are very conservative

The Evolutionary History of Contract Algorithms: A Decade of Perpetual Contracts, the Curtain Has Yet to Fall

Kicked out by PayPal, Musk aims to make a comeback in the cryptocurrency market

Solana ETF News: What Is a Solana ETF and Why Is Goldman Sachs Betting $108 Million on SOL?
Solana ETF news today shows Goldman Sachs disclosed a $108M position while total SOL ETF inflows reached $1.45B. Analysts now expect up to $6B in institutional demand as Solana trades 71% below its all-time high.

Bitcoin ETF News Today: $2.1B Inflows Signal Strong Institutional Demand for BTC
Bitcoin ETFs news recorded $2.1B inflows over 8 consecutive days, marking one of the strongest recent accumulation streaks. Here’s what the latest Bitcoin ETF news means for BTC price and whether the $80K breakout level is next.

Michael Saylor: Winter is Over – Is He Right? 5 Key Data Points (2026)
Michael Saylor tweeted yesterday “Winter‘s Over.” It is short. It is bold. And it has the crypto world talking.
But is he right? Or is this just another CEO pumping his bags?
Let us look at the data. Let us be neutral. Let us see if the ice has really melted.

WEEX Bubbles App Now Live Visualizes the Crypto Market at a Glance
WEEX Bubbles is a standalone app designed to help users quickly understand complex crypto market movements through an intuitive bubble visualization.

Polygon co-founder Sandeep: Writing after the chain bridge chain explosion

Major Upgrade on Web: 10+ Advanced Chart Styles for Deeper Market Insights
To deliver more powerful and professional analysis tools, WEEX has rolled out a major upgrade to its web trading charts—now supporting up to 14 advanced chart styles.

Morning Report | Aethir secures a $260 million enterprise contract with Axe Compute; New Fire Technology acquires Avenir Group's trading team; Polymarket's trading volume surpassed by Kalshi

Why a Million-Follower Crypto KOL Chooses WEEX VIP?
Discover why top crypto KOL Carl Moon partnered with WEEX. Explore the WEEX VIP ecosystem, 1,000 BTC protection fund, and exclusive rewards for serious traders.

CoinEx Founder: The Crypto Endgame in My Eyes

Spark Coin (SPK): Explodes 73% as Aave Bleeds $15B, A Good Investment Now?
Spark coin (SPK) surged 73% as $15 billion fled Aave after the KelpDAO hack. This article explains what Spark is, why it’s pumping, and whether it is a good investment right now.

As Aave's building collapses, Spark's high-rise is rising

RootData: Q1 2026 Cryptocurrency Exchange Transparency Research Report

What Is Memecoin Trading? A Beginner's Guide to How It Works, the Risks, and 2026's Hottest Tokens
Memecoins surged 30%+ at the start of 2026 while Bitcoin was flat. RAVE spiked 4,500% then crashed 90% in days. MAGA jumped 350% overnight. This guide explains exactly how memecoin trading works — and how to not blow up your account doing it.
6MV Founder: In 2026, the "landmark turning point" for crypto investment has arrived
Abraxas Capital Mints $2.89 Billion USDT: Liquidity Boost or Just More Stablecoin Arbitrage?
Abraxas Capital just received $2.89 billion in freshly minted USDT from Tether. Is this a bullish liquidity injection for crypto markets, or is it business as usual for a stablecoin arbitrage giant? We analyze the data and the likely impact on Bitcoin, altcoins, and DeFi.
A VC from the Crypto world said AI is too crazy, and they are very conservative
The Evolutionary History of Contract Algorithms: A Decade of Perpetual Contracts, the Curtain Has Yet to Fall
Kicked out by PayPal, Musk aims to make a comeback in the cryptocurrency market
Solana ETF News: What Is a Solana ETF and Why Is Goldman Sachs Betting $108 Million on SOL?
Solana ETF news today shows Goldman Sachs disclosed a $108M position while total SOL ETF inflows reached $1.45B. Analysts now expect up to $6B in institutional demand as Solana trades 71% below its all-time high.
