logo

Resolv Protocol Incident Analysis

ID: c781aac0-1629-5d1c-9dea-842d6d068f65

STIX ID: report--c781aac0-1629-5d1c-9dea-842d6d068f65

Feed Name: CertiK Blog

Threat Score
88/100

Date Published: 2026-03-23

Date Updated: 2026-06-11

...
...

On 22 March 2026, Revolv (Resolv) suffered a cloud key compromise: an attacker gained access to an AWS KMS signing key bound to a SERVICE_ROLE and used it to sign completeSwap() calls that over-minted ~80M USR against small USDC deposits, producing an estimated ~$26.8M loss, a collapse in USR price, and paused pools on dependent platforms. The report provides a step-by-step attack flow, exploited and victim addresses, timestamps, wallet balances, and attributes the root cause to the KMS/private key compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.