Exchanging 200,000 for nearly 100 million, DeFi stablecoins face another attack
Written by: Eric, Foresight News
Around 10:21 Beijing time today, Resolv Labs, which issues the stablecoin USR using a Delta neutral strategy, was hacked. An address starting with 0x04A2 minted 50 million USR from the Resolv Labs protocol using 100,000 USDC.
As the incident came to light, USR plummeted to around $0.25, and as of the time of writing, it has rebounded to about $0.8. The price of the RESOLV token also saw a temporary drop of nearly 10%.
Subsequently, the hacker replicated the method and minted 30 million USR again using 100,000 USDC. With the significant decoupling of USR, arbitrage traders quickly acted, and many lending markets on Morpho that support USR, wstUSR, and other collateral types have been nearly emptied, while Lista DAO on the BNB Chain has also suspended new loan requests.
The impact is not limited to these lending protocols. In the design of the Resolv Labs protocol, users can also mint a more volatile and higher-yielding RLP token, but they need to bear compensation responsibilities when the protocol incurs losses. Currently, the circulation of RLP tokens is nearly 30 million, with the largest holder, Stream Finance, holding over 13 million RLP, resulting in a net risk exposure of about $17 million.
Indeed, Stream Finance, which previously suffered due to the xUSD incident, may be hit again.
As of the time of writing, the hacker has converted USR into USDC and USDT and continues to buy Ethereum, having already purchased over 10,000. With 200,000 USDC, they have extracted over $20 million in assets, finding their "hundredfold coin" during the bear market.
Another Exploitation Due to "Lack of Rigor"
The sharp decline on October 11 last year caused many stablecoins issued using Delta neutral strategies to incur collateral losses due to ADL (automatic deleveraging). Some projects that executed strategies using altcoins suffered even heavier losses or went directly bankrupt.
The attacked Resolv Labs also issued USR using a similar mechanism. The project announced in April 2025 that it had completed a $10 million seed round led by Cyber.Fund and Maven11, with participation from Coinbase Ventures, and launched the RESOLV token in late May to early June.
However, the reason for Resolv Labs being attacked was not due to extreme market conditions, but rather the "lack of rigor" in the design of the USR minting mechanism.
Currently, no security company or official has analyzed the reasons for this hacking incident. The DeFi community YAM has preliminarily concluded through analysis that the attack was likely caused by the hacker controlling the SERVICE_ROLE used by the protocol's backend to provide parameters for the minting contract.
According to Grok's analysis, when users mint USR, they initiate a request on-chain and call the contract's requestMint function, with parameters including:
_depositTokenAddress: the address of the deposited token;
_amount: the amount deposited;
_minMintAmount: the minimum expected amount of USR to receive (to prevent slippage).
Afterward, users deposit USDC or USDT into the contract, and the project's backend SERVICE_ROLE monitors the request, using the Pyth oracle to check the value of the deposited assets, and then calls the completeMint or completeSwap function to determine the actual amount of USR minted.
The problem lies in the fact that the minting contract completely trusts the _mintAmount provided by the SERVICE_ROLE, believing that this number has been verified off-chain by Pyth, thus no upper limit was set, nor was there any on-chain oracle verification, directly executing mint(_mintAmount).
Based on this, YAM suspects that the hacker controlled the SERVICE_ROLE that should have been controlled by the project team (possibly due to internal oracle failure, collusion, or key theft), directly setting the _mintAmount to 50 million during minting, achieving the attack event of minting 50 million USR with 100,000 USDC.
Ultimately, Grok concluded that Resolv did not consider the possibility that the address (or contract) used to receive user minting requests could be controlled by hackers when designing the protocol. When the request to mint USR was submitted to the contract that ultimately mints USR, no maximum minting amount was set, nor was there a secondary verification using an on-chain oracle, directly trusting all parameters provided by the SERVICE_ROLE.
Prevention Measures Were Also Inadequate
In addition to speculating on the reasons for the hack, YAM also pointed out the project's inadequate preparation for crisis response.
YAM stated on X that Resolv Labs only paused the protocol three hours after the hacker's first attack, with about one hour of that delay coming from the need to collect four signatures for the multi-signature transaction. YAM believes that an emergency pause should only require one signature, and that authority should be distributed as much as possible to team members or trusted external operators, which would increase awareness of on-chain anomalies, improve the likelihood of a quick pause, and better cover different time zones.
While the suggestion that a single signature could pause the protocol is somewhat radical, requiring multiple signatures across different time zones to pause the protocol could indeed delay significant matters in an emergency. Introducing trusted third parties that continuously monitor on-chain behavior or using monitoring tools with emergency pause protocol authority are lessons learned from this incident.
Hacker attacks on DeFi protocols are no longer limited to contract vulnerabilities. The incident involving Resolv Labs serves as a warning to project teams: assumptions about protocol security should not trust any single link, and all parameter-related processes must undergo at least secondary verification, including those operated by the project team itself.
You may also like

Pantera Capital Partner: How Tokenization is Restructuring the Private Equity and Early Investment Ecosystem?

New York Proposes Stricter Stablecoin Issuer Rules Aligned With Federal GENIUS Act
NYDFS proposed stricter stablecoin issuer rules aligned with the GENIUS Act, covering reserves, custody, redemption timelines, audits, and capital buffers.

Every exchange is a "Universal Exchange."

The counterattack of traditional finance: Alliance chains are quietly reviving

CryptoQuant Says Bitcoin Profitable Supply Is Near 45% Pressure Zone as On-Chain Data Points to Market Repricing
CryptoQuant said Bitcoin’s profitable supply is nearing the 45% pressure zone, signaling rising market stress, unrealized losses, and a possible on-chain repricing phase.

Bitcoin Falls Below 200-Week Moving Average as On-Chain Data Shows Over Half of Supply in Loss
Bitcoin dropped below its 200-week moving average as on-chain data showed over 50% of circulating supply is now in loss, signaling rising market stress.

CFTC Reportedly Plans New Prediction Market Rules Focused on Manipulation Risk and Public Interest Review
The CFTC is reportedly preparing new prediction market rules focused on manipulation risk, public interest review, and retail trader protections.

Meet the new WEEX trial fund—your gateway to greater profits

WEEX Labs Lands at Dutch Blockchain Week: A Disruptive Crypto × AI Conversation Sets Sail in Amsterdam

SK Hynix Reportedly Plans U.S. ADR Listing as Early as August, With SEC Approval Possible in Late June
SK Hynix may pursue a U.S. ADR listing as early as August, with SEC approval reportedly possible in late June amid strong AI chip supply chain demand.

SpaceX vs Tesla vs xAI: Which Elon Musk Trade Has the Biggest Upside in 2026?

OpenAI Reveals It Has Confidentially Submitted an S-1 to the SEC, Keeping the Door Open for a Future IPO
On June 9, according to an OpenAI announcement, the company recently confidentially submitted a draft S-1 registration statement to the U.S. Securities and Exchange Commission (SEC), beginning the preliminary compliance process for a potential initial public offering. OpenAI said it chose to disclose this proactively because it expected the news might leak; however, the company has not yet set a specific listing timeline, and related arrangements may still take some time.

Latest research from 13 top universities including Cornell University: The current state, challenges, and misconceptions of the fusion of Crypto and AI

Deconstructing Anthropic: The Best AI Company, Possibly Also a Type of Organizational Invention

Apollo and Blackstone Reportedly Back $35 Billion Anthropic Chip Financing as Deal Details Remain Unclear
On June 9, according to currently available news alerts, Apollo and Blackstone Group participated in a $35 billion financing for an Anthropic “chip project.” Based on the original wording of the report, the funding has already been raised, but public information remains limited. The financing structure, use of proceeds, project entity, and whether Apollo and Blackstone participated through equity, debt, or project financing have not yet been disclosed.

Humanity Protocol Security Incident Escalates: More Than $31 Million Stolen From Related Addresses as Attacker Continues Selling H for ETH
On June 9, according to monitoring by Onchain Lens, more than $31 million has been stolen from addresses linked to Humanity Protocol, and the attack is still ongoing, with the hacker continuously swapping H tokens for ETH. Project founder Terence Kwok later confirmed the security incident on X, saying the issue involved a private key leak.

Bloomberg: As Bitcoin Weakens, Stablecoins and RWA Continue to Drive Expansion in Crypto Businesses
In June, Bloomberg reported that despite Bitcoin falling below $60,000 last week, wiping out about $235 billion in market value within seven days, and dropping close to 50% from last year’s peak, some core businesses in the crypto industry are still expanding, mainly in stablecoins, real-world asset tokenization (RWA), payments, and infrastructure. The report also noted that overall altcoin activity has contracted significantly: altcoin market capitalization has fallen from a peak of about $431 billion in November 2021 to around $170 billion, and among the tens of millions of tokens issued in recent years, fewer than 1,700 still maintain meaningful trading activity.

Galaxy Deep Research Report: How Hyperliquid's HIP-4 Upgrade Changes the Landscape of Prediction Markets?
Pantera Capital Partner: How Tokenization is Restructuring the Private Equity and Early Investment Ecosystem?
New York Proposes Stricter Stablecoin Issuer Rules Aligned With Federal GENIUS Act
NYDFS proposed stricter stablecoin issuer rules aligned with the GENIUS Act, covering reserves, custody, redemption timelines, audits, and capital buffers.
Every exchange is a "Universal Exchange."
The counterattack of traditional finance: Alliance chains are quietly reviving
CryptoQuant Says Bitcoin Profitable Supply Is Near 45% Pressure Zone as On-Chain Data Points to Market Repricing
CryptoQuant said Bitcoin’s profitable supply is nearing the 45% pressure zone, signaling rising market stress, unrealized losses, and a possible on-chain repricing phase.
Bitcoin Falls Below 200-Week Moving Average as On-Chain Data Shows Over Half of Supply in Loss
Bitcoin dropped below its 200-week moving average as on-chain data showed over 50% of circulating supply is now in loss, signaling rising market stress.




