Resolv reveals $25M exploit stemming from compromised contractor GitHub credential, 80M USR illicitly minted


3 recorded changes
Want your article here?
Promote with Leviathan News

3 recorded changes
Want your article here?
Promote with Leviathan NewsResolv Labs, the team behind the overcollateralized stablecoin USR, disclosed a detailed postmortem on a March 22, 2026 exploit in which an attacker illicitly minted roughly 80 million USR and extracted about $23–25 million in value. According to Resolv’s investigation, the root cause was not a Solidity bug but a compromised contractor GitHub credential that ultimately led to abuse of a privileged off‑chain signing service controlling USR mint approvals. The attacker deposited a low six‑figure amount of USDC, then used the compromised off‑chain authorization path to mint vastly more USR than was properly backed, exploiting the fact that the on‑chain contracts only checked for a valid signature and did not enforce a maximum mint amount tied to collateral. The incident unfolded through Resolv’s two‑step swap/mint mechanism, where an off‑chain backend with a privileged role (SERVICE_ROLE) signed messages indicating how much USR to mint. Once the attacker obtained access via the compromised GitHub credential, they were able to manipulate that off‑chain component and have the contracts accept signatures that approved minting around 80 million unbacked USR against roughly $100–300k in USDC deposits. The attacker then routed the newly minted USR into the staked wrapper wstUSR and systematically dumped it through liquidity on Curve, Uniswap, and other DEXs into other stablecoins and then ETH, ultimately ending with roughly $23–25 million in ETH. The sudden oversupply drove USR into a severe depeg—various post‑incident analyses report a crash of 80–97% from its intended $1 price—and forced Resolv to pause all protocol operations while they contained the attack vector, rotated keys, and began designing recovery measures for legitimate holders. The case has become a reference example of how off‑chain key management and privileged infrastructure can undermine otherwise audited on‑chain code. Security firms and analysts emphasize that the exploit combined a missing on‑chain “max mint” check with centralized off‑chain signing, creating a single point of failure in Resolv’s AWS‑backed key and CI/CD pipeline accessed via GitHub. Resolv’s postmortem states that all identified compromised credentials have been revoked, the vulnerable infrastructure has been re‑architected, and the exploit path is believed to be fully contained. The broader DeFi ecosystem is using the incident to highlight shifting risk from smart‑contract logic to ancillary systems—GitHub, cloud KMS, and backend services—and to argue for stricter key isolation, multi‑party controls, and on‑chain enforcement of economic limits for mintable assets.
AI-generated background, compiled from web sources — not editorial content.

𝕏/@PeckShieldAlert ·

𝕏/@DefimonAlerts ·

𝕏/@THORChain ·

The Block ·

𝕏/@axelar ·

𝕏/Pybast ·

𝕏/@PeckShieldAlert ·

𝕏/@DefimonAlerts ·

𝕏/@THORChain ·

The Block ·

𝕏/@axelar ·

𝕏/Pybast ·
🚀 Love DeFi? Ready to dive in and start earning $SQUID while making an impact?