Panewslab Resolv Labs Faces $25M Exploit as USR Stablecoin Minting Mechanism Compromised
Article Content
- •An attacker exploited Resolv's minting mechanism to create 80 million unbacked USR tokens.
- •The exploit resulted in a loss of approximately $25 million, with USR dropping to $0.14.
- •Resolv Labs has paused all operations and destroyed 9 million illegally minted tokens.
On March 22, 2026, Resolv Labs reported a significant security breach where an attacker exploited the minting mechanism of its USR stablecoin, generating approximately 80 million uncollateralized tokens. The attacker gained access to the protocol's private keys, allowing them to mint the tokens with only $100,000 to $200,000 in collateral. Following the minting, the attacker swiftly converted the USR into Ethereum, extracting around $25 million in value. The exploit caused USR to depeg from its $1 value, dropping as low as $0.14 before partially recovering. Resolv Labs has since paused all protocol functions and destroyed 9 million of the illegally minted tokens to mitigate further impact. The incident highlights vulnerabilities in DeFi protocols, particularly regarding off-chain components and minting controls. Investigations are ongoing to assess the full scope of the damage and to recover lost funds.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (22)
Following this threat?
Track Lido Finance in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…