T
iTokenly

Resolv (USR) hack — March 2026

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedMarch 22, 2026
Target typeStablecoin or yield protocol
Loss$25,000,000Published estimates range $23,000,000 to $25,000,000Price at time of incident
MethodPrivate key compromiseUnauthorised control of the SERVICE_ROLE signing key that authorises USR issuance, held in a cloud key management service. Resolv's post-mortem traces the chain of access to a compromised third-party project where a Resolv contractor had previously worked: the attackers obtained a broadly permissioned credential tied to that contractor's GitHub account, used malicious GitHub workflows to extract infrastructure credentials, moved into the cloud environment, then used a higher-privileged infrastructure role to rewrite the key's own access policy. The mint path had no maximum output, no collateral-to-mint ratio check and no oracle check, and SERVICE_ROLE was a single externally owned account rather than a multisig.
ChainsEthereum
OutcomeUsers reimbursed

What happened

Resolv issues USR, a dollar-pegged token backed by a delta-neutral position in ether and bitcoin. On 22 March 2026 at 02:21:35 UTC an attacker deposited about $100,000 of USDC into Resolv's USR Counter contract and received 50 million USR, roughly 500 times the correct amount. A second transaction at 03:41 UTC minted a further 30 million USR, for 80 million unbacked tokens in total.

The attacker had obtained control of the SERVICE_ROLE key that authorises issuance. Resolv's post-mortem traces the intrusion to a compromised third-party project where one of its contractors had previously worked: attackers took a broadly permissioned credential linked to that contractor's GitHub account, ran malicious GitHub workflows to pull infrastructure credentials, reached the cloud environment, then used a higher-privileged role to rewrite the signing key's access policy. The mint contract enforced a minimum USR output but no maximum and no collateral ratio check.

The attacker wrapped and sold the tokens through decentralised exchange pools, ending with 11,409 ETH. Figures for the value extracted differ: Resolv's post-mortem says approximately $25 million, The Block valued the attacker's ether at about $23.7 million plus $1.1 million in wrapped USR, and Chainalysis put it at roughly $23 million. USR fell to $0.025 on its largest Curve pool within 17 minutes.

Resolv paused its contracts at 05:16 UTC and revoked the compromised credentials at 05:30 UTC, then burned or blacklisted about 46 million of the minted USR. Its collateral pool was untouched; the loss fell on holders and liquidity providers. A 72-hour offer letting the attacker keep 10 percent went unanswered. Resolv says pre-incident USR holders are being compensated one for one.

Law enforcement

Resolv says relevant authorities were notified and that an investigation is running with outside counsel, blockchain forensics teams and on-chain analytics firms. No agency is named and no charges have been reported.

Sources

  1. Resolv LabsPrimary · retrieved 2026-08-01
  2. The BlockSecondary · retrieved 2026-08-01
  3. ChainalysisSecondary · retrieved 2026-08-01
  4. The BlockSecondary · retrieved 2026-08-01

Official post-mortem: https://resolv.xyz/blog/resolv-postmortem-march-22-2026-incident

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Resolv (USR) hack — March 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/resolv-usr
https://itokenly.com/hacks/resolv-usr

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.