The Resolv exploit was a private‑key compromise that let an attacker mint 80 million unbacked USR stablecoins and then rippled into Morpho-integrated USDC vaults curated by Gauntlet, MEV Capital, Steakhouse and others. On 22 March 2026, Resolv Labs’ USR stablecoin was exploited when an attacker gained access to a privileged signing key in the protocol’s AWS Key Management Service environment. That key was used by an off‑chain component to authorize USR mints; once compromised, the attacker could approve arbitrarily large mints that the on‑chain contracts did not cap as long as the signature was valid. By depositing roughly $100,000–$200,000 in USDC, the attacker triggered Resolv’s two‑step minting flow and minted about 80 million unbacked USR, then converted USR into staked wstUSR, other stablecoins and ultimately ETH, extracting around $23–25 million in value. The sudden flood of unbacked USR drove the stablecoin badly off‑peg, at one point dropping more than 80% and trading for just a few cents before partially recovering. Because USR was integrated across DeFi, the depeg propagated into external protocols that had treated USR as a dollar‑like asset. Morpho’s design kept its core lending contracts safe, but curator‑run vaults with USR exposure suffered bad debt as their positions were marked against the collapsing stablecoin price. Reporting from Resolv post‑mortems and DeFi risk analysts notes that around 15 Morpho vaults were affected, including curator strategies from Gauntlet, MEV Capital, Steakhouse and other managers, where automated liquidity or hard‑coded pricing caused strategies to keep providing liquidity or holding USR even after the exploit, amplifying losses. The episode has become a case study in the systemic risk of off‑chain key management and of integrating newer stablecoins into lending and vault products without robust circuit‑breakers and real‑time risk controls.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Exploit

Comments