Incident case file
Sign in to watchResolv Labs — AWS KMS Private Key Compromise / USR Stablecoin Depeg
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0x15cad41e6bdcadc7121ce65080489c92cf6de398
Timeline: March 22, 2026, ~02:21 UTC — Attacker gains access to SERVICE_ROLE private key (AWS KMS infrastructure compromise). Calls completeSwap() with arbitrary _targetAmount — no oracle check, no mint cap, no multisig protection. First mint: 50M USR against 100,000 USDC. USR crashes to $0.025 on Curve within 17 minutes. Second mint: 30M USR. Resolv pauses all contracts; announces 10% bounty (~$2.45M) for fund return — no response. April 4 — Post-mortem confirms AWS KMS compromise as root cause. April 6 — Resolv deploys contract upgrade burning 36.73M wstUSR/stUSR held by attacker. Net loss capped at ~$34M; 11,409 ETH (~$23.7M) still with attacker.
Sources and coverage
- Articlechainalysis.comhttps://www.chainalysis.com/blog/lessons-from-the-resolv-hack/
- Articlecoindesk.comhttps://www.coindesk.com/markets/2026/03/23/resolv-stablecoin-drops-70-after-usd80-million-exploit-after-attacker-mints-usr
- Articletheblock.cohttps://www.theblock.co/post/394582/resolvs-usr-stablecoin-depegs-after-attacker-mints-80-million-unbacked-tokens-extracts-roughly-25-million
- Articlehalborn.comhttps://www.halborn.com/blog/post/explained-the-resolv-hack-march-2026
- Articleblockaid.iohttps://www.blockaid.io/blog/how-a-compromised-key-minted-80m-in-resolvs-usr-stablecoin-and-triggered-a-depeg
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)