Tools Crypto Exploit Tracker exploit-0060
Exploit record
Resolv Labs
- Loss
- $25M
- Attack vector
- Access Control
- Chain
- Ethereum
- Sector
- Stablecoin
What happened
On March 22, 2026, Resolv Labs suffered an infrastructure breach after attackers gained privileged access through a compromised private key and minted a large block of uncollateralised USR.
This was not a contract-logic failure so much as the old classic: somebody got access they should not have had. The attacker used the compromised mint authority to create roughly $80M in fake USR, staked part of it into wstUSR, swapped into real assets, and tried to force value out before the protocol could shut the doors. Resolv moved quickly, paused the relevant contracts, burned a chunk of attacker-held supply, and said the realised damage before the pause was far smaller than the headline nominal mint. The important distinction is that the collateral base was not directly emptied; the danger came from fake liabilities being created against it.
On-chain references
- Exploiter Address
0x8ed8cf0c1c531c1b20848e78f1cb32fa5b99b81c - $50M mint txetherscan.io/tx/0xfe37f25efd67d0a4da4afe48509b258df48757b978…
- $30M mint txetherscan.io/tx/0x41b6b9376d174165cbd54ba576c8f6675ff966f176…
- Follow-on attacker txetherscan.io/tx/0x7f914328a67f7094eedb0efda7aef74aafdb7f862a…
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026
