Hacker walks away with $24.5 million after breaching Resolv DeFi platform
嗯,用户让我用中文总结一下这篇文章,控制在100字以内,而且不需要用“文章内容总结”之类的开头。好的,我先看看文章讲的是什么。 文章主要讲的是去中心化金融平台Resolv遭受了网络攻击,导致价值8000万美元的USR稳定币被非法创建。USR原本是与美元挂钩的,但这次攻击后,它的价值暴跌到26美分。攻击者利用了一个被窃取的私钥,创建了大量没有抵押的USR,并用这些代币换取了以太坊。 Resolv公司正在追踪这些非法代币,并威胁要与交易所合作限制这些资产。他们还联系了执法部门和区块链分析公司,并可能采取法律行动。此外,Chainalysis分析指出,这次攻击是因为过度信任链下基础设施,尽管Resolv通过了多次安全审计,但仍然被攻破。 现在我需要把这些信息浓缩到100字以内。重点包括:Resolv遭遇网络攻击、价值8000万美元的USR被非法创建、导致USR脱钩美元、公司采取措施应对、Chainalysis的分析结果。 再检查一下字数,确保不超过限制。可能需要删减一些细节,比如具体的金额或步骤,但保留关键点。 最终总结应该是:去中心化金融平台Resolv遭网络攻击,价值8000万美元的USR稳定币被非法创建。攻击者利用私钥生成无抵押代币并兑换以太坊。公司追踪非法资产并威胁限制交易。区块链安全公司Chainalysis指出事件因过度信任链下基础设施所致。 </think> 去中心化金融平台Resolv遭网络攻击,价值8000万美元的USR稳定币被非法创建。攻击者利用私钥生成无抵押代币并兑换以太坊。公司追踪非法资产并威胁限制交易。区块链安全公司Chainalysis指出事件因过度信任链下基础设施所致。 2026-3-24 00:45:43 Author: therecord.media(查看原文) 阅读量:12 收藏

Decentralized finance platform Resolv said a recent cyberattack allowed a threat actor to compromise the company’s infrastructure and illicitly create $80 million worth of its USR stablecoin.

USR is pegged to the U.S. dollar but plummeted in value on Saturday when the hacker created the uncollateralized coins and traded them for about 11,408 ETH, which is worth about $24.5 million

The company published a statement confirming the incident. USR was depegged from the U.S. dollar after the incident and is now worth about 26 cents.

“Earlier today, a malicious actor gained unauthorized access to Resolv infrastructure through a compromised private key, resulting in the minting of approximately $80 million of uncollateralized USR,” the company said

The company said it is tracing the coins and trying to contain the spread of the illicitly minted USR. 

In a message to the attacker on the blockchain, Resolv offered the person 10% of the $24.5 million in ETH if they returned the rest and ceased all further activity with the exploited funds.

"While this incident involved a vulnerability, the exploit was executed with clear malicious intent resulting in the creation of unbacked assets and potential secondary market impact," they wrote

They asked the person to transfer all remaining USR to them within 72 hours. Resolv threatened to coordinate with centralized exchanges to restrict or freeze the illicit assets. They also threatened to contact law enforcement and blockchain analytics firms as well as pursue legal action.

Blockchain security company Chainalysis published its own post mortem explaining the incident. The company called the situation a “case of overly trusting off-chain infrastructure.”

“While Resolv had undergone all the classic security measures, and had undergone as many as 18 audits, the hack on Resolv is, in one sense, a simple story: an attacker got a key, used it to print money, and sold the fake money before anyone noticed,” Chainalysis said. 

“The attacker started by depositing a relatively small amount (around $100K–$200K in USDC) and used it to interact with Resolv’s USR stablecoin minting system. Normally, users deposit USDC and receive an equivalent amount of USR in return. However, in this case, the attacker was able to mint around 80 million USR tokens, far beyond what their deposit should have allowed.”

This was possible, according to Chainalysis, because minting approvals depend on another service that relies on a private key signing off on how much USR could be created. Once this was stolen, the company’s system did not enforce a maximum limit on minting. 

On Monday afternoon, Resolv said that it is temporarily pausing its app to contain the impact of the incident. 

“Once the protocol recovery plan is finalized and the application is safe to use again, all functionalities will be restored,” they said. 

Resolv said it is now in contact with all verified users with USR holdings at the time of the incident and redemptions are now enabled. They urged customers not to trade USR or other Resolv tokens as they work to recover the illicitly made coins.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.


文章来源: https://therecord.media/hacker-breaches-resolv-defi-25-million
如有侵权请联系:admin#unsafe.sh