T
iTokenly

Resupply hack — June 2025

Verified — 5 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJune 26, 2025
Target typeLending protocol
Loss$10,000,000Published estimates range $9,300,000 to $10,000,000Price at time of incident
MethodContract logic errorDonation-based share-price inflation against an empty CurveLend vault, which then triggered an integer-division rounding flaw. Resupply's market computed its exchange rate as 1e36 divided by the reported price; because the manipulated price exceeded 1e36, the result rounded down to zero, producing a zero loan-to-value that let the solvency check pass for an arbitrarily large borrow.
ChainsEthereum
OutcomeUnresolved

What happened

Resupply is a DeFi lending protocol that issues the reUSD stablecoin against yield-bearing collateral. On 26 June 2025 at 01:53:59 UTC, roughly 90 minutes after a new crvUSD-wstUSR market went live, an attacker drained it in a single transaction. The incident is widely dated 25 June because of US time zones. BlockSec's analysis sets out the mechanism. The attacker took a 4,000 USDC flash loan, swapped it for crvUSD, donated 2,000 crvUSD to a CurveLend controller that held none, then deposited about 2 crvUSD to mint a single share. One share now appeared to be worth an enormous amount. Resupply's market derived its exchange rate by dividing 1e36 by that reported price; because the price exceeded 1e36, integer division rounded the exchange rate down to zero. A zero exchange rate produced a zero loan-to-value, the solvency check passed, and the attacker borrowed 10,000,000 reUSD. Resupply's post-mortem stresses that the oracle reported the inflated value correctly and that the decisive flaw was the rounding in the exchange-rate calculation, describing it as a targeted attack on the solvency logic rather than a conventional inflation attack. Published figures for the value actually realised differ, because the borrowed reUSD had to be sold: Cyvers told DL News about $9.3 million, most analyses settled on $9.6 million, and Halborn put it at $9.8 million. The protocol's own accounting treats the hole as $10 million of reUSD bad debt. About $2.86 million was repaid from the treasury, a governance proposal burned 6 million reUSD from the insurance pool, and the remaining $1.13 million was carried by the DAO. The proceeds went through Tornado Cash and no arrests have been reported.

On-chain references

Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.

Transactions

  • 0xffbbd492e0605a8bb6d490c3cd879e87ff60862b0684160d08fd5711e7a872d3

Sources

  1. BlockSecSecondary · retrieved 2026-08-01
  2. DL NewsSecondary · retrieved 2026-08-01
  3. The BlockSecondary · retrieved 2026-08-01
  4. crypto.newsSecondary · retrieved 2026-08-01
  5. HalbornSecondary · retrieved 2026-08-01

Official post-mortem: https://mirror.xyz/0x521CB9b35514E9c8a8a929C890bf1489F63B2C84/ygJ1kh6satW9l_NDBM47V87CfaQbn2q0tWy_rtp76OI

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Resupply hack — June 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/resupply
https://itokenly.com/hacks/resupply

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.