A hacker turned roughly $200,000 into $25 million on Sunday by exploiting a privileged administrative key in Resolv’s USR minting contract, crashing the stablecoin 97% within minutes in what analysts say is a textbook case of off-chain key mismanagement.

The attacker gained access to Resolv’s key management system on Amazon Web Services, where a single externally owned account controlled the protocol’s SERVICE_ROLE, the function that processes mint requests. That account had no oracle checks, no maximum mint limits, and no amount validation. The attacker deposited roughly $100,000 to $200,000 in USDC and received 80 million USR in return, about 500 times the expected amount. USR crashed to $0.025 on its Curve Finance pool within 17 minutes of the first transaction, then partially recovered to around $0.85.


This story is an excerpt from the Unchained Daily newsletter.

Subscribe here to get these updates in your email for free


The attacker converted the minted tokens into approximately 11,409 ETH worth around $23.7 million. Resolv paused all protocol functions and said its collateral pool “remains fully intact” with “no underlying assets” lost. That framing is technically accurate but overstates the situation: the 80 million new tokens diluted existing USR holders and the rapid sell-off obliterated pool liquidity. Anyone holding USR during the depeg absorbed the loss in real time.

The damage rippled outward. USR and its staked derivative wstUSR were accepted as collateral on roughly 15 Morpho lending vaults curated by Gauntlet, Re7 Labs, and others. Opportunistic traders bought discounted USR and borrowed USDC against it at the hardcoded $1 valuation, draining stablecoin liquidity from those vaults before curators could respond. Resolv’s RLP insurance layer had about $38.6 million in circulation before the attack, and Stream Finance, already carrying $17 million in RLP exposure after its own $93 million loss in November 2025, now faces additional pain.