A Contractor's Old GitHub Login Led to Resolv's $80 Million USR Mint
A $300,000 deposit was enough to trigger an $80 million overprint of Resolv's USR stablecoin, once an attacker gained control of the single off-chain key responsible for authorizing mints. Resolv's own post-incident report later traced the intrusion not to a flaw inside Resolv itself, but to a supply chain attack that started at an unrelated third-party project where one of Resolv's contractors had previously worked.
According to that account, a compromised GitHub credential belonging to the contractor gave attackers entry into Resolv's code repositories. From there they planted a malicious CI/CD workflow that quietly siphoned off signing credentials, spent several days mapping Resolv's cloud environment, and eventually landed on the one key that mattered.

That key, held within Resolv's cloud infrastructure, carried unrestricted authority to mint USR — no multisig, no oracle sanity check, and no cap written into the contract on how much could be created. The system did not glitch; it simply executed the permissions it had been given.
By the following morning roughly $25 million in ETH had been swept into one wallet controlled by the attacker. Resolv, a protocol that had recorded $684 million in TVL more than a year earlier, was left with mint and redeem functions locked indefinitely.
Resolv would later maintain that its collateral reserves were never touched — a statement that is technically correct, though it offers little consolation to anyone who held USR near a dollar and then watched its price collapse toward pennies.
Credit for reporting and analysis: Chainalysis, CoinTelegraph, DefiLlama, PeckShield, Resolv Labs, YAM, Hacken, QuillAudits, Vadim, The Defiant, Omer Goldberg, 9summits, OAK Research, Morpho, Paul Frambot, Steakhouse, Lido Finance, Stani Kulechov, Samyak Jain, Inverse Finance, Gauntlet, Fluid, kooone, TheBlock, Upbit Korea, Venus Protocol, Midas, Lista DAO, and BitcoinEthereumNews.
01How the alarm went up
On a Sunday evening, the trading desk YAM was already monitoring on-chain activity when it flagged something wrong: USR had fallen to one cent, and someone had just minted 50 million USR against only $100,000 in USDC. The transaction sat openly on Etherscan — nothing about it was hidden, because the contract permitted exactly what had happened.
About an hour later, PeckShield surfaced the same activity, pointing to both the 50 million mint and a second transaction minting another 30 million, and urged the community to stay alert.
Roughly two hours after YAM's initial alert, Resolv Labs issued its first public statement: an exploit had let an attacker mint 50 million unbacked USR, all protocol functions had been paused, and the team was working on remediation. A follow-up shortly after insisted the collateral pool remained fully intact — no underlying assets lost, with the damage confined to USR's issuance mechanism. Accurate, perhaps, but it did nothing to soften the operational fallout.
Cyvers then laid out the fuller picture: roughly 80 million unbacked USR had been printed against somewhere between $100,000 and $200,000 in collateral — a 500-to-1 mismatch — and USR was still sliding, down to $0.257. On Curve, the token had already touched $0.025, a 97% collapse, just 17 minutes after the first mint confirmed on-chain. By the time Resolv's statement reached the public, the attacker had already spent hours converting the proceeds.
The next morning, PeckShield tallied the damage: 11,400 ETH — about $24 million — sitting in a single consolidation wallet, plus a further $1.3 million in wstUSR still in the attacker's possession.
02The mechanism: a single key with no ceiling
USR minting was never fully permissionless. It depended on a privileged off-chain backend role, SERVICE_ROLE, that finalized every swap request as a deliberate two-step control between deposits and issuance. That same key had been in place since May 2024 and governed not only minting but also two other infrastructure contracts, ExternalRequestsCoordinator and ResolvRequestsMgr — one credential controlling several points of failure.
Compromised SERVICE_ROLE EOA: 0x15CAd41e6BdCaDc7121ce65080489C92CF6de398
Per Resolv's post-mortem, this was not a direct breach of Resolv but a supply chain attack rooted in a third-party project where a Resolv contractor had previously done work. Once that outside project was compromised, attackers recovered a GitHub credential tied to the contractor and used it to enter Resolv's repositories. From there they deployed a malicious CI/CD workflow engineered to pull sensitive infrastructure credentials out without generating detectable outbound traffic, then scrubbed their own access to cover tracks.
Those credentials opened access to Resolv's cloud environment, where the attackers spent the following days quietly enumerating services and hunting for usable API keys. Escalating to actual signing authority over the mint key was not simple — several attempts were rejected — until the attackers found a working path: using a more privileged role's policy-management permissions to rewrite the key's own access policy and grant themselves signing rights.
Chainalysis notes that once armed with that authority, the attacker simply submitted mint values the system was never designed to question.
Mint transaction 1 — 50 million USR: 0xfe37f25efd67d0a4da4afe48509b258df48757b97810b28ce4c649658dc33743 — 100,000 USDC deposited, 50,000,000 USR minted.
Mint transaction 2 — 30 million USR: 0x41b6b9376d174165cbd54ba576c8f6675ff966f17609a7b80d27d8652db1f18f — another 100,000 USDC deposited, another 30,000,000 USR minted.
The contract's only real check was confirming a valid signature — it never evaluated whether the requested amounts made sense. It behaved exactly as it had been built to behave. Hacken pointed out the key had held SERVICE_ROLE for nearly two years with no multisig backstop and, per Chainalysis, no on-chain cap on what it could authorize. As Vadim summarized it: "The threat model was simply: the key won't leak. It did."
Pausing the protocol required multi-signature approval through Resolv's Governance Safe, and gathering the needed signatures took roughly three hours — a delay largely attributable to the multisig process itself. In that window, the exploit was repeated across several wallets before anyone with the authority to halt it could actually do so.
03Laundering an $80 million mint
Moving 80 million freshly minted USR without collapsing its own price required a plan, and the attacker followed one closely.
First, rather than dumping raw USR — which would have deepened the depeg working against their own position — the attacker converted it into wstUSR, the wrapped, staked variant that represents a share of the staking pool rather than a fixed token count, giving it access to deeper liquidity and easier fungibility.
Second, that wstUSR was routed through multiple DEXs, including Curve and Uniswap, and swapped into USDC and USDT.
Third, the stablecoins were converted into ETH, the attacker's final destination — by the time Resolv managed to pause the protocol, most of the position had already been liquidated.
The attacker spread activity across several addresses before consolidating:
Attacker EOA 1: 0x04A288a7789DD6Ade935361a4fB1Ec5db513caEd Attacker EOA 2: 0xb945ec1be1f42777f3aa7d683562800b4cdd3890 Attacker EOA 3: 0x9feeeaec113e6d2dcd5ac997d5358eee41836e5f Primary consolidation wallet: 0x8ED8cF0C1c531C1b20848E78f1CB32fa5B99b81C
That last address ended up holding roughly 11,408 ETH — about $24.3 million — with no mixer and no bridge involved, sitting in plain view. A remaining $1.2–1.3 million in wstUSR stayed parked in Attacker EOA 1, a relatively small leftover against a roughly $25 million total haul.
QuillAudits calculated the operation returned roughly 83 times the attacker's original $300,000 outlay, and noted the exploit was repeated across three full cycles before anyone caught it publicly. Had real-time monitoring with automatic pause capability existed, QuillAudits estimated losses could have been contained to around $8 million by stopping the very first transaction. Chainalysis made the same point: with exploits now unfolding in minutes, automated detection and response are no longer optional. Resolv's systems, however, caught neither the first, second, nor third transaction.
The following morning, Resolv sent an on-chain message to the exploiter offering standard terms: return 90% (about $25 million in ETH), keep the remaining 10% as a settlement incentive, and transfer any remaining USR to a recovery address within 72 hours, or face escalation and legal action. That message is publicly visible on Etherscan. The attacker never replied, and the funds have not moved.
04Automation turns against the ecosystem
The direct exploit was only the first source of damage. What followed unfolded in two distinct waves within the wider DeFi ecosystem, each more deliberate than the last.
Before any curator stepped in, the exploit's initial footprint inside Morpho's lending markets was modest — around $4,900 in USDC borrowed against USR collateral. The real damage came afterward, once automated systems took over.
Morpho runs a feature called the Public Allocator, designed to let curators automatically move capital toward markets showing high utilization, normally a way to capture better yield for depositors. On the night of March 22nd, that same mechanism turned into an open credit line for anyone sitting on depegged USR.
Omer Goldberg reported that several curators — Gauntlet, Re7 Labs, kpk, and 9summits — had auto-supply enabled toward Resolv-linked markets. Twenty minutes into the exploit, at 2:41 AM UTC, Gauntlet's allocator began pushing funds into the compromised wstUSR/USDC market, which ran on hardcoded oracles unable to reflect USR's real-time collapse. Wallets drained each new allocation via borrow requests almost as soon as it landed. Gauntlet's auto-supply ran for about 90 minutes before it was spotted and switched off; Gauntlet's initial statement acknowledged limited exposure in a handful of high-yield vaults while saying most of its vaults were unaffected.
9summits intervened earlier, at 3:00 AM UTC, and documented 32 separate attack transactions hitting its vault by 12:33 PM UTC, holding its own bad debt to roughly $41,000. It has since fully settled 100% of the affected stUSR in its Usual Money vault for USDC with Resolv, with depositor redemptions expected in the following days.
In total, Morpho curators fed roughly $6.2 million in USDC exit liquidity into the broken markets, 96% of it from Gauntlet's vaults — liquidity that let borrowers exploit the gap between USR's crashed market price and its frozen oracle value, borrowing against effectively worthless collateral and simply walking away.
Goldberg, founder of Chaos Labs, detailed the failure in a 21-post thread: the automation had no circuit breaker, the oracles were hardcoded and immutable, and the system kept pushing liquidity into broken markets for hours. His conclusion: a Public Allocator that anyone can trigger mid-exploit, paired with a fixed oracle, effectively becomes a subsidy for the attacker.
That was only the first phase. A second, more calculated attack followed, per OAK Research. After curators responded by setting USR market supply caps to zero — the usual defensive step — the attacker turned to a documented weakness in Morpho's vault design: calling Morpho's supply() function with a vault's own address as beneficiary can force that vault to hold market shares it never opted into. Using a flash loan to briefly control a large share of the target vault's supply, the attacker appears to have force-injected USDC liquidity into the wstUSR/USDC market, deposited devalued wstUSR still priced at $1 by the frozen oracle, borrowed the newly available USDC, repaid the flash loan, and pocketed the difference. Morpho's documentation explicitly warns that zeroing supply caps does not stop this style of attack — a warning that evidently went unheeded in practice.
Morpho co-founder Merlin Egalite clarified that the protocol's core contracts were unaffected and only specific vaults carried exposure; CEO Paul Frambot confirmed about 15 vaults holding more than $10,000 in liquidity were impacted.
Notably, Steakhouse — engaged as Resolv's risk manager only days earlier and having published an assessment that specifically covered this exact exploit scenario while concluding Resolv "demonstrates institutional rigor" — had no exposure to the protocol whatsoever. Steakhouse later appended a note to that same report: "Unfortunately, one of the risks we highlighted in the below report materialized, leading to an exploit that allowed an attacker to mint new USR tokens."
The fallout reached well beyond Morpho, touching lending markets, yield products, and integrated protocols across the board. A compiled list of affected venues included:
- Morpho vaults: Gauntlet USDC Core, Gauntlet USDC Frontier, Resolv USDC, 9Summits USDC, Extrafi XLend USDC, Re7 USDC, Seamless USDC, Apostro Resolv USDC, August AUSD, Clearstar Yield USDC, kpk USDC Yield, MEV Capital USDC, and Keyrock USDC.
- Euler markets: Apostro Resolv and Euler Arbitrum Yield.
- Midas products: mBASIS, mAPOLLO, mEDGE, and msyrupUSDp.
- Other exposure confirmed or flagged: yoUSD, Fluid across Arbitrum, Base, Ethereum, and Plasma, Venus Protocol Flux, Lista DAO's USD1 vault, Inverse Finance's DOLA, and Upshift's coreUSDC, upUSDC, and earnAUSD products.

Lido Finance confirmed Lido Earn user funds were unaffected. Aave founder Stani Kulechov said Aave carried no direct USR exposure, with Resolv actively paying down outstanding debt. Fluid faced more than $11 million in potential bad debt tied to a separate hardcoded oracle issue unrelated to the Morpho situation, and secured short-term loans to cover the losses in full.
Inverse Finance's Risk Working Group paused its wstUSR-DOLA market within 15 minutes of the exploit; despite roughly $10 million in active debt, liquidations brought those positions to zero, leaving residual bad debt of 340,060 DOLA. Stream Finance — which had already disclosed a $93 million loss back in November 2025 — reportedly holds around 13.6 million RLP tokens representing roughly $17 million in pre-exploit net exposure, with the outcome still unresolved; the firm has posted nothing publicly since its November incident. Euler, Venus, and Lista each took defensive steps, pausing markets or isolating vaults.
Cyvers' VP of GTM and strategy, Michael Pearl, told CoinTelegraph that because supply had inflated faster than the market could absorb, and the token depegged almost immediately, the value of remaining tokens was significantly impaired. Ledger CTO Charles Guillemet offered a comparatively measured take: given USR's scale, "this is not a Terra Luna-type event" — cold comfort to the protocols still tallying their own losses.
05Where things stand
Resolv's official line remains that no underlying collateral was lost, and technically that holds: the collateral pool backing the protocol's delta-neutral strategy was left untouched. What was lost instead was harder to quantify — trust in USR's supply, confidence among holders, and around $25 million now parked in an attacker-controlled wallet.
The protocol has remained paused since the early hours of March 22nd, with most operations still halted according to the official post-mortem. Pre-exploit USR holders are being made whole on a 1:1 basis, with 98% of whitelisted redemptions already processed or underway, and work continuing on subsequent phases for remaining user groups.
Recovery signs have started to appear across the affected ecosystem. Gauntlet met with Resolv to discuss next steps and voiced confidence in a positive resolution for affected Morpho vault suppliers. Fluid confirmed debt repayments are underway, with roughly $70 million in USR-related debt cleared across BNB and Plasma, a governance proposal to shift remaining debt to a team multisig for settlement with Resolv, and a compensation plan for affected users still to come. Venus Protocol confirmed $31.6 million in USR-related debt on Flux has been cleared, with the balance expected within days and interest rates back to normal. Midas confirmed mAPOLLO fully redeemed its USR position, while mBASIS and msyrupUSDp pulled Fluid allocations on Plasma as a precaution despite carrying no direct USR exposure. Lista DAO confirmed $8.4 million of its $8.6 million in USR-related loans has been repaid in full at 1:1, with zero loss to users or the protocol and one $26,000 position still outstanding.
Resolv reported that more than $77 million had been redeemed by allowlisted pre-exploit USR holders within the first two days — over 90% of that group — with additional phases for remaining holders still in progress. A community-built tracker, Exposure.Forum, launched during the incident to consolidate which curators were hit, which protocols lost what, and which vaults remained safe.
The RESOLV governance token dropped about 8.5% in the 24 hours following the exploit and has continued to slide since. Upbit, South Korea's largest exchange, placed RESOLV on a trading-caution list. Separately, USR's market cap had already fallen from roughly $400 million in early February 2026 to about $100 million in the weeks leading up to the attack — a 75% contraction over six weeks that the team has not publicly explained.
The SERVICE_ROLE key never left Resolv's own infrastructure, and no evidence of insider trading has surfaced. Resolv has since brought in law enforcement and blockchain analytics firms, burned roughly 9 million of the attacker's illicitly minted tokens, and revoked the compromised SERVICE_ROLE. By March 26th, Resolv reported that roughly 46 million of the 80 million illicitly minted USR — about 57% — had been permanently removed via burning and blacklisting, with no illicit tokens remaining at exploiter-linked addresses. On April 6th, Resolv executed a smart contract upgrade to permanently destroy the remaining 36.73 million wstUSR and stUSR held in the hacker's wallets, unwrapping them into USR before sending everything to the zero address.
The forensic investigation, run by Mandiant and ZeroShadow, has found no evidence of insider involvement so far, and Resolv's post-mortem continues to attribute the breach to the third-party supply chain compromise rather than any internal actor. By Resolv's own accounting, the collateral pool holds approximately $141 million in assets, with only about $0.5 million in redemptions processed before the pause — limiting the confirmed direct loss to the protocol itself. The funds taken by the attacker still have not moved.
06The broader pattern
February 2026 had been the quietest month for crypto hacks since March 2025 — $26.5 million lost industry-wide, a 69.2% drop from January's $86 million. Then March arrived, and Resolv's $25 million loss landed in that ledger, notable less for its complexity than for how simple it was: one key, one function, no ceiling, and no check — despite the contracts having been audited 18 times.
That key had sat in the same environment for close to two years. The setup was never a hidden risk — it simply wasn't treated as one. And the point of entry wasn't even inside Resolv's own walls; it was a contractor's credential, compromised at an entirely separate project, long before the attackers ever touched Resolv's systems.
As Chainalysis put it, as DeFi systems grow more reliant on external services, privileged keys, and cloud infrastructure, the attack surface stretches well beyond the blockchain itself. Eighteen audits, a $500,000 bug bounty, and a risk assessment published just five days before the exploit — none of it mattered, because the weakest link was never in the code. It was in a contractor's GitHub account, tied to a project they had worked on months earlier.
Get new scam files the moment we publish them — usually 2–3 emails a week.