CoinsValue.net logo CoinsValue.net logo
Crypto Potato 2026-03-23 22:23:01

How the $25M Resolv USR Minting Heist Happened

USR, an overcollateralized stablecoin natively backed by ETH and maintained by the Resolv protocol, lost its peg on March 22 after an attacker minted millions of unbacked tokens and reportedly extracted at least $25 million. Here’s how the incident went down, according to blockchain analytics firm Chainalysis. Attacker Exploits Minting Key to Create $80M in Unbacked USR In a thread posted on X earlier today, Chainalysis explained that the attacker gained access to Resolv’s AWS Key Management Service, where a privileged signing key was stored. The access allowed them to authorize minting operations using the protocol’s own permissions. There were two standout transactions, the first minting 50 million USR, and the second adding another 30 million to bring the total to 80 million tokens. But according to Chainalysis, the minting operations were backed by rather small USDC deposits worth between $100,000 and $200,000, which the criminal used to trigger inflated swap outputs. They then moved quickly, converting the newly minted USR into wrapped staked USR (wstUSR), which is a derivative that represents a share of a staking pool rather than a fixed token amount. After that, they swapped the funds into other stablecoins and then into ETH, obscuring their trail by rotating through several decentralized exchange pools and bridges. Resolv Labs confirmed the breach, stating that the unauthorized minting had been enabled by a compromised private key. The team paused contracts shortly after detecting the issue and managed to burn nearly 9 million USR that the attacker had in their possession. They also reported that about $0.5 million in redemptions had been processed before operations were halted. Per Chainalysis, the attacker controls about 11,400 ETH, worth about $25 million at the time the theft took place. They also hold about 20 million wstUSR, which were valued at much lower levels. USR Depegs Immediately after the attack, USR plunged to a new all-time low near $0.14 per CoinGecko data. However, it has since recovered slightly, but the value at press time still represented a drop of over 57% in the last 24 hours. According to the Resolv team, there are still at least 71 million illicitly minted tokens in USR’s circulating supply, which CoinGecko puts at just north of 176 million tokens. However, the team has initiated a redemption process for all USR minted before the incident, starting with allowlisted users. The episode is especially damaging, considering a recent survey by Ripple found that 74% of finance executives see stablecoins as useful tools for managing cash flow and treasury operations. At the same time, 89% of them said they give great priority to secure custody when selecting service providers, which points to the importance of infrastructure safeguards. Resolv has said that it is working with partners, law enforcement, and analytics firms to trace funds and recover assets, and it has warned users not to trade with the affected tokens during the recovery process. The post How the $25M Resolv USR Minting Heist Happened appeared first on CryptoPotato .

면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.