Resolv DeFi Platform Suffers $24.5 Million Loss in Cyberattack

Resolv DeFi Platform Breached, Resulting in Significant Losses

Decentralized finance (DeFi) platform Resolv recently confirmed a cyberattack that led to a substantial financial loss. A malicious actor gained unauthorized access to the company's infrastructure, enabling the creation of $80 million worth of its USR stablecoin without proper backing. The USR stablecoin, which is designed to maintain parity with the U.S. dollar, saw its value plummet after the incident. The attacker exchanged the illicitly minted coins for roughly 11,408 ETH, valued at approximately $24.5 million.

Details of the Attack and Immediate Aftermath

Resolv issued a statement acknowledging the security breach. Following the attack, the USR stablecoin depegged from the U.S. dollar, with its value dropping to about 26 cents. The company explained that the attacker compromised a private key, which granted them unauthorized access to Resolv's systems, allowing them to mint the uncollateralized USR.

Resolv has initiated efforts to track the illicitly obtained coins and prevent further dissemination of the unbacked USR. In an attempt to recover the stolen assets, Resolv sent a message to the attacker via the blockchain. The company offered a 10% bounty, equivalent to $2.45 million, from the $24.5 million in ETH if the attacker returned the remaining funds and ceased all further activity with the exploited assets.

Resolv emphasized that despite the presence of a vulnerability, the exploit was carried out with clear malicious intent, leading to the creation of unbacked assets and potential negative impacts on the secondary market. The platform requested the attacker to transfer all remaining USR back within 72 hours. Resolv also warned of potential collaboration with centralized exchanges to restrict or freeze the illicit assets, and threatened to involve law enforcement, blockchain analytics firms, and pursue legal action.

Analysis by Chainalysis

Blockchain security firm Chainalysis conducted a post-mortem analysis of the incident, describing it as a "case of overly trusting off-chain infrastructure." Chainalysis noted that while Resolv had implemented standard security measures and undergone as many as 18 audits, the hack was fundamentally simple: an attacker acquired a key, used it to generate unbacked currency, and then sold it before detection.

According to Chainalysis, the attacker initially deposited a relatively small amount, between $100,000 and $200,000 in USDC, to interact with Resolv's USR stablecoin minting system. Typically, users deposit USDC and receive an equivalent amount of USR. However, in this instance, the attacker was able to mint approximately 80 million USR tokens, significantly exceeding what their deposit should have allowed.

Chainalysis explained that this was possible because minting approvals relied on an external service that used a private key to authorize the amount of USR that could be created. Once this private key was compromised, Resolv's system failed to enforce a maximum limit on the amount of USR that could be minted.

Resolv's Response and Recovery Efforts

On Monday afternoon, Resolv announced a temporary pause of its application to mitigate the impact of the incident. The company stated that all functionalities would be restored once a protocol recovery plan is finalized and the application is deemed safe for use again.

Resolv has established contact with all verified users who held USR at the time of the incident, and redemptions have been enabled. The platform advised customers to refrain from trading USR or other Resolv tokens while it works to recover the illicitly generated coins.

Start using Conzent today

Privacy-first consent management for modern websites.