On March 22, 2026, Resolv Labs suffered a DeFi exploit in which an attacker used a compromised off-chain signing key tied to its AWS KMS setup to mint about 80 million unbacked USR, far beyond what the attacker’s small USDC deposits should have allowed. Chainalysis says the attacker then moved the minted tokens through wstUSR and other liquidity venues before cashing out roughly $23 million to $25 million in ETH, while USR rapidly de-pegged and the protocol halted core functions. The key issue was not a conventional smart-contract bug, but a trust failure in off-chain infrastructure: Resolv’s minting flow depended on a privileged private key to authorize issuance, and the contract did not enforce a hard on-chain cap or collateral check beyond verifying the signature. That design meant that once the signing environment was compromised, the attacker could create unbacked supply at scale, illustrating a broader DeFi risk where cloud services, key management, and automated signing systems become part of the attack surface. The incident matters because it shows how quickly a stablecoin system can unravel when issuance controls are centralized off-chain, and because the fallout extended beyond Resolv itself into connected liquidity and lending venues that had exposure to USR and wstUSR. Chainalysis framed the event as a security lesson for DeFi protocols: real-time monitoring, tighter mint limits, and automated response mechanisms may be essential when privileged keys and external infrastructure are involved.

AI-generated background, compiled from web sources β€” not editorial content.

More coverage

Explore the topic

More on Compromised

Comments