Resolv USR Minting-Key Compromise and Depeg (March 22, 2026)
- Date
- 2026-03-22
- Loss
- $25M
- Category
- Stablecoin minting-key compromise
- Attack vector
- Supply-chain intrusion beginning with a contractor's compromised GitHub credential and malicious CI workflows exfiltrated cloud credentials, escalated privileges to rewrite an AWS KMS key access policy, and seized Resolv's off-chain SERVICE_ROLE minting key. The on-chain USR Counter contract verified only that a valid signature existed, with no price oracle, mint-ratio check, or maximum cap, so two signed transactions minted 80 million unbacked USR against under $200,000 of USDC.
- Attribution
- Unattributed as of July 2026; the ~11,409 ETH of proceeds remained largely unmoved on-chain with no significant Tornado Cash or bridging activity. Tracked by Lookonchain, Chainalysis, Cyvers and Blockaid; Resolv Labs offered a 10% (~$2.45M) on-chain bounty on a 72-hour deadline before escalating to exchange coordination and law-enforcement referral; Korean DAXA exchanges including Upbit imposed trading alerts and deposit suspensions.
Overview
On March 22, 2026, an attacker who had already compromised Resolv Labs' cloud key-management infrastructure used the protocol's privileged SERVICE_ROLE signing key to mint 80 million unbacked USR stablecoins against less than $200,000 of USDC collateral, then converted the phantom supply through wrapped staked USR (wstUSR) and a chain of DEX venues into approximately 11,409 ETH, roughly $24.5 million. The intrusion did not touch a Solidity bug: Resolv's own postmortem describes a multi-stage breach that began when a contractor's GitHub credential, exposed through a previously compromised third-party project, gave attackers a foothold in Resolv's repositories; malicious GitHub workflows then exfiltrated cloud credentials, and a higher-privileged role's policy-management capability was used to rewrite the AWS KMS key access policy, granting the attackers signing authority over the key that authorized USR minting. Because the on-chain minting contract enforced no price oracle, no collateral-to-mint ratio, and no maximum cap, whatever the key holder signed was minted: a 100,000 USDC deposit produced 50 million USR at 02:21 UTC, followed by a 30 million USR mint at 03:41. USR crashed as low as roughly $0.025 in thin Curve liquidity within seventeen minutes, a roughly 70% depeg on consolidated feeds, before stabilizing near $0.26. Resolv paused its pausable contracts at 05:16 UTC and revoked compromised credentials by 05:30, stressing that the collateral pool itself was intact. Contagion still propagated through DeFi composability, leaving Morpho vaults with about $6.2 million and Fluid with more than $10 million of bad debt. Resolv burned 36.73 million attacker-held wstUSR and stUSR on April 6, neutralizing roughly 46 million USR in total, pledged 1:1 redemptions for all pre-exploit holders, allocated 10% of the RESOLV token supply to recovery, and opened a claims portal running May 26 through August 26, 2026. The stolen ETH remained largely unmoved and unattributed as of mid-2026, and the incident became the canonical demonstration that a stablecoin's mint key is its central bank, and that cloud and CI/CD infrastructure sit squarely inside the trust boundary that audits must cover.
Timeline of events
The on-chain phase began at 02:21:35 UTC on March 22, 2026, when an address beginning 0x04A2 deposited roughly 100,000 USDC into Resolv's minting flow and received 50 million USR in one transaction, about 500 times what the deposit should have produced. Within seventeen minutes the unbacked supply hit Curve pools and USR printed as low as roughly $0.025 in the thinnest venues; consolidated feeds recorded an approximately 70% depeg, and the token stabilized near $0.26-$0.27 the following day. A second signed mint of 30 million USR followed at 03:41 UTC, bringing the total to 80 million USR created against under $200,000 of real collateral. Lookonchain flagged the anomalous mints publicly while the attacker wrapped USR into wstUSR and rotated it through Curve, KyberSwap and Uniswap into USDC and USDT and finally into approximately 11,409 ETH, about $24.5 million. Resolv's postmortem records the attackers last active on its infrastructure at 05:15 UTC; pausable contracts were frozen on-chain at 05:16 and compromised credentials were revoked by 05:30. The team then published an incident statement confirming a compromised private key, offered the attacker a 10% bounty of roughly $2.45 million on a 72-hour deadline, and Korean exchanges under DAXA, including Upbit, imposed trading alerts with deposit suspensions through April 24. On April 6 a contract upgrade burned 36.73 million wstUSR and stUSR still under attacker control, and the Resolv Recovery Portal opened claims from May 26 through August 26, 2026.
Attack mechanism
USR minting ran in two steps. On-chain, a user deposited collateral and registered a mint request with the USR Counter contract; off-chain, a backend service computed the appropriate issuance against the protocol's delta-neutral hedging position and authorized the mint by signing with a privileged key called SERVICE_ROLE, stored in AWS Key Management Service. The fatal asymmetry was that the contract trusted the signature absolutely. As Chainalysis put it, there was no on-chain ratio check between the collateral deposited and the USR to be minted, no price oracle, no cap, and no maximum mint ratio: whatever the key holder signed would get minted. Once the attackers held signing authority over SERVICE_ROLE, a $100,000 deposit could authorize 50 million USR, and the contract executed it as designed. The extraction phase showed notable operational sophistication. Rather than dumping raw USR into shallow pools, the attacker converted much of it into wstUSR, the wrapped staked version, muting immediate price impact and preserving exit liquidity, then rotated proceeds through Curve, KyberSwap and Uniswap into USDC and USDT before consolidating into ETH. Roughly 20 million wstUSR, worth about $1.1-$1.3 million after the depeg, was stranded in a secondary address (0x04a288a7789dd6ade935361a4fb1ec5db513caed) as pool liquidity collapsed faster than it could be exited. The dump itself was the depeg: 80 million phantom tokens against a pre-exploit market capitalization of roughly $100 million meant sell pressure that no arbitrage could absorb, and USR briefly traded for pennies.
Root cause analysis
Resolv's postmortem describes a multi-stage event spanning multiple organizations and infrastructure layers rather than a single vulnerability. The initial foothold was external: a contractor's GitHub credential from prior work at a third-party project was compromised when that project was breached, giving the attackers access to Resolv's code repositories. From there they deployed malicious GitHub workflows that exfiltrated cloud infrastructure credentials from CI/CD environments, then exploited a higher-privileged role's policy-management capability to modify the KMS key's access policy directly, granting themselves signing authority over SERVICE_ROLE without ever needing to extract the raw key material. Three design failures converted that infrastructure breach into a $25 million loss. First, the minting authority was a single externally owned account with no multisig or MPC protection, even though the protocol's administrative pause key did have multisig, so one compromised credential path sufficed. Second, the contract enforced no on-chain invariants: no oracle-based price validation, no collateral-to-mint ratio check, and no maximum mint cap, leaving the off-chain service as the only line of defense. Third, the gap was known and unaddressed: a documented audit finding labeled 'missing upper limit' had surfaced the absent mint cap, yet it survived through what researchers counted as eighteen security reviews, because infrastructure and key custody sat outside the audit scope that Resolv's otherwise heavily reviewed contracts had passed. The contracts behaved exactly as written; the trust model behind the signature did not.
Initial response and depeg containment
Resolv's team began response efforts roughly an hour after the initial mint and moved quickly once engaged: attackers were last active on infrastructure at 05:15 UTC, pausable contracts were frozen at 05:16, and all potentially compromised credentials were revoked by 05:30 across CI/CD, cloud services, exchanges, custodians and VPN, with personal access tokens prohibited organization-wide. The team emphasized that the collateral pool backing USR remained fully intact and that the incident was isolated to issuance mechanics, which proved decisive for the eventual recovery. The depeg still tore through integrated protocols. Morpho vaults curated by Gauntlet, Re7, MEV Capital and 9summits absorbed about $6.2 million in bad debt, with Gauntlet's vaults accounting for roughly 96% of it. Fluid (Instadapp) absorbed more than $10 million in bad debt and suffered over $300 million of outflows in a single day, the worst in its history, before its team secured short-term loans to cover 100% of the hole and committed to making users whole. Euler, Venus, Inverse Finance and Lista DAO paused USR-related markets as a precaution, and Curve pool LPs were left holding depegged inventory. Resolv's 10% bounty offer to the attacker lapsed without a return of funds. Co-founder Ivan Kozlov publicly pledged 1:1 redemptions for all pre-exploit USR holders, and within days reported that 98% of whitelisted holders had already been redeemed at par, the first concrete recovery milestone.
Funds tracking and laundering
The attacker's flow was fast on extraction and then unusually static. The primary address beginning 0x04A2 swapped minted USR for USDC and USDT across decentralized exchanges and consolidated into approximately 11,409 ETH, worth about $23.7-$24.5 million at prevailing prices, while a secondary address retained roughly 20 million stranded wstUSR. From there, on-chain analysts tracking the wallets through the spring reported a pattern that diverged from the 2026 exploit norm: the bulk of the stolen ETH remained unmoved in self-custodied addresses, with no significant Tornado Cash deposits confirmed at scale and no major bridging activity detected, even as other 2026 exploiters routed proceeds into mixers within hours. That stillness cut both ways: it preserved the theoretical possibility of negotiated return or seizure while giving investigators time to map the infrastructure intrusion. No formal attribution has been issued. Analyst hypotheses have ranged from state-aligned infrastructure intrusion crews to a DeFi-native professional, the latter argued from the attacker's intimate familiarity with wstUSR conversion mechanics, venue-by-venue liquidity depth and slippage management during the exit. On the recovery side of the ledger, Resolv used a contract upgrade on April 6 to burn 36.73 million wstUSR and stUSR clawed back from attacker-controlled addresses, and combined burns and blacklisting neutralized roughly 46 million USR in total, capping the residual unbacked supply. Independent accounting placed total economic damage near $34 million: about $24.5 million extracted as ETH plus roughly $10 million of remaining unbacked token value absorbed by markets.
Recovery and remediation
The Resolv Foundation published a structured recovery plan built around the intact collateral pool. Pre-exploit USR holders were offered full 1:1 USDC compensation, with the majority of whitelisted redemptions processed within weeks; holders who acquired USR after the incident were offered half value, an explicit design choice to deter depeg profiteering. Ten percent of the total RESOLV token supply was allocated to the recovery, with 70% of that tranche directed to RLP holders, the protocol's junior insurance layer, whose roughly $38.6 million of pre-exploit circulation had absorbed first-loss risk. A dedicated Resolv Recovery Portal opened claims for affected USR and RLP positions from May 26 through August 26, 2026. Downstream, vault curators faced their own reckoning: Gauntlet and Resolv reached a compensation agreement on June 4 that opened more than 4.37 million USDC of claims to affected Gauntlet vault users on Morpho, and Re7 Labs opened a 223,000 USDC compensation pool for wallets hit through its vaults, early precedents for curator-level restitution in DeFi. Technical remediation tracked the postmortem's failure chain: CI/CD credentials are being replaced with OIDC authentication so long-lived personal access tokens cannot be harvested, on-chain mint caps and oracle-based price validation are being added so no single signature can authorize unbounded issuance, automated emergency pause mechanisms and infrastructure anomaly detection are being deployed, and a comprehensive external security review covering infrastructure, not just contracts, was commissioned before protocol operations resume at scale.
Industry implications
Resolv crystallized several uncomfortable truths for the stablecoin and broader DeFi industry. Most fundamentally, it demonstrated that a fiat-pegged token's real security perimeter is wherever its mint authority lives: eighteen security reviews of correct Solidity were irrelevant because the key that could print supply sat in cloud infrastructure reachable through a contractor's GitHub credential and a CI/CD pipeline. Audit scope, incident responders argued, must expand from contracts to the Web2 stack around them. Cyvers CEO Deddy Lavid drew the monitoring lesson bluntly: audits alone are not enough if you are not watching minting and supply in real time, since a $100,000 deposit authorizing 50 million USR is trivially detectable by ratio-anomaly rules that could trigger an automated pause before extraction. Sodot's Ido Sofer placed the incident in the year's dominant pattern: attackers increasingly target sensitive keys and credentials that do not hold funds directly but access them. The contagion also forced the curated-vault ecosystem to confront accountability, with Gauntlet and Re7 compensating users for bad debt their allocation decisions absorbed, a precedent risk curators now price in. The regulatory subtext was already live: landmark joint SEC/CFTC crypto guidance on digital-asset classification had been published days before the exploit, and Korean DAXA exchanges moved immediately to protect retail flow. PeckShield counted roughly $52 million of crypto hack losses in March 2026, with Resolv the month's dominant incident as 2026 DeFi losses passed $137 million by spring.
Verdict and lessons
Resolv is the stablecoin-native chapter of the key-compromise era: no contract was exploited, no oracle manipulated, no governance captured, and yet 80 million dollars of nominal supply was conjured because one signing key in AWS KMS functioned as an unguarded central bank. The verdict on the protocol is mixed. Resolv's architecture kept the collateral pool segregated and intact, its pause response landed within an hour of the team engaging, and its recovery program, 1:1 pre-exploit redemptions, a 10% token-supply allocation, and negotiated curator compensations, is among the more complete restitutions in recent DeFi history. But the loss was preventable at multiple layers, and every missing layer was known practice by 2026. The lessons are concrete. Mint authority must never be a single externally owned key; multisig or MPC distribution is the floor for any function that can create supply. On-chain invariants must backstop off-chain services: hard mint caps, oracle-checked collateral ratios, and rate limits turn a stolen key from a catastrophe into a bounded incident. CI/CD and cloud infrastructure are inside the trust boundary; contractor credentials, personal access tokens and KMS key policies deserve the same review intensity as Solidity, and OIDC-style short-lived credentials should replace static secrets. Real-time supply monitoring with automated pause authority would have capped this exploit at the first mint. And composability means a stablecoin depeg is never contained: lending markets, curated vaults and DEX LPs inherited Resolv's infrastructure risk without ever holding its key.
Recovery
Resolv paused contracts at 05:16 UTC, revoked all compromised credentials by 05:30, and burned 36.73M attacker-held wstUSR/stUSR via an April 6 contract upgrade, neutralizing ~46M USR in total. With the collateral pool intact, the Foundation offered 1:1 USDC redemptions to pre-exploit holders (98% of whitelisted holders redeemed within days), half value to post-exploit buyers, and allocated 10% of RESOLV supply to recovery with 70% of that to RLP holders; a Recovery Portal ran claims May 26-August 26, 2026. Gauntlet opened $4.37M USDC of claims for affected Morpho vault users on June 4 and Re7 Labs opened a $223K pool. A 10% bounty offer to the attacker lapsed; the ~11,409 ETH remained largely unmoved.
Key lessons
- A stablecoin's mint key is its central bank: mint authority must be distributed via multisig/MPC and never rest on a single externally owned account in cloud KMS
- On-chain invariants must backstop off-chain signers: hard mint caps, oracle-checked collateral ratios and rate limits bound the damage of any stolen key
- CI/CD and cloud infrastructure are inside the trust boundary: contractor GitHub credentials, personal access tokens and KMS key policies need audit-grade review, with OIDC replacing static secrets
- Real-time supply and mint-ratio monitoring with automated pause authority converts a multi-hour drain into a single bounded transaction
- Composability spreads depeg losses to lending markets, curated vaults and LPs that never held the key; curators and integrators must price issuer infrastructure risk, not just contract risk
Frequently asked questions
What happened in the Resolv USR Minting-Key Compromise and Depeg?
Resolv's USR stablecoin was exploited on March 22, 2026 after attackers compromised the AWS KMS-hosted SERVICE_ROLE minting key through a supply chain that began with a contractor's GitHub credential and malicious CI workflows, minting 80M unbacked USR against under $200K of USDC and swapping it via wstUSR and DEXs into ~11,409 ETH (~$24.5M). USR crashed as low as ~$0.025 on Curve, a ~70% consolidated depeg; contracts were paused at 05:16 UTC and the collateral pool stayed intact. Contagion left Morpho vaults ~$6.2M and Fluid >$10M in bad debt. Resolv burned ~46M attacker-held USR, pledged 1:1 pre-exploit redemptions (98% of whitelisted processed), allocated 10% of RESOLV supply to recovery, and ran a claims portal from May 26 to August 26. The funds sat largely unmoved and unattributed, and the incident became the canonical proof that a stablecoin's mint key is its central bank and cloud infrastructure is in audit scope.
How much was lost?
Approximately $25M was lost on 2026-03-22.
How did the attack work?
Supply-chain intrusion beginning with a contractor's compromised GitHub credential and malicious CI workflows exfiltrated cloud credentials, escalated privileges to rewrite an AWS KMS key access policy, and seized Resolv's off-chain SERVICE_ROLE minting key. The on-chain USR Counter contract verified only that a valid signature existed, with no price oracle, mint-ratio check, or maximum cap, so two signed transactions minted 80 million unbacked USR against under $200,000 of USDC.
Who was responsible?
Unattributed as of July 2026; the ~11,409 ETH of proceeds remained largely unmoved on-chain with no significant Tornado Cash or bridging activity. Tracked by Lookonchain, Chainalysis, Cyvers and Blockaid; Resolv Labs offered a 10% (~$2.45M) on-chain bounty on a 72-hour deadline before escalating to exchange coordination and law-enforcement referral; Korean DAXA exchanges including Upbit imposed trading alerts and deposit suspensions.
Were the funds recovered?
Resolv paused contracts at 05:16 UTC, revoked all compromised credentials by 05:30, and burned 36.73M attacker-held wstUSR/stUSR via an April 6 contract upgrade, neutralizing ~46M USR in total. With the collateral pool intact, the Foundation offered 1:1 USDC redemptions to pre-exploit holders (98% of whitelisted holders redeemed within days), half value to post-exploit buyers, and allocated 10% of RESOLV supply to recovery with 70% of that to RLP holders; a Recovery Portal ran claims May 26-August 26, 2026. Gauntlet opened $4.37M USDC of claims for affected Morpho vault users on June 4 and Re7 Labs opened a $223K pool. A 10% bounty offer to the attacker lapsed; the ~11,409 ETH remained largely unmoved.
Related
- KelpDAO rsETH Cross-Chain Bridge Exploit (April 18, 2026)
- Radiant Capital Multisig/Device Compromise (Oct 16, 2024)
- Bybit Cold Wallet Compromise (Feb 21, 2025)
- Munchables Rogue-Developer Exploit on Blast (Mar 26-27, 2024)
- Terra/Luna Death Spiral and UST Depeg (May 8-12, 2022)
- curve
- morpho
- euler
- pendle
- gauntlet
- ethereum