Tag: Euler

Defi
FEATURED
Resolv Protocol's $25M AWS Key Compromise: How a $100K USDC Deposit Generated 80 Million Unbacked USR, Crashed the Stablecoin 95%, and Delivered DeFi's Clearest Warning Yet About Off-Chain Admin Key Security
On March 22, 2026, an attacker compromised Resolv Labs' SERVICE_ROLE private key — stored on Amazon Web Services — and used it to mint 80 million unbacked USR tokens using $100K–$200K in USDC. USR crashed 95.2% from $1.00 to $0.04751. The attacker extracted ~$23–$25M in ETH (9,100–11,409 ETH). Resolv had $500M+ TVL pre-hack. The SERVICE_ROLE was controlled by a single EOA with no multisig. The minting contract had no oracle checks, no amount validation, and no maximum mint cap. Resolv Labs paused all protocol functions and burned ~9M USR. Aave and Euler confirmed no exposure. Root cause: compromised AWS off-chain signer, not smart contract code.
Ethers News-