# Resolv signing-infrastructure compromise enabled 80M unbacked USR mint

> Resolv halted backend services, paused relevant contracts, revoked and rotated compromised credentials, and neutralized approximately 46 million illicit USR through burns and blacklist functionality.

- URL: https://riadefi.com/on-chain/2026-03-22-resolv-usr-signing-infrastructure-compromise/
- Type: Security incident
- Stage: Postmortem
- Evidence: mixed
- Materiality: critical
- Event date: 2026-03-22
- Version: 1, published 2026-08-22 (first published 2026-08-22)
- Advisor-relevant: yes
- Affects: Resolv USR (protocol)

Developing. Some claims here are not yet confirmed; they are listed apart from the confirmed facts. A new version replaces this one when the primary evidence changes.

## What happened

Attackers traversed compromised third-party and Resolv infrastructure, obtained authority over the signing key used by Resolv's off-chain minting service, and executed two Counter transactions that created 80 million unbacked USR and extracted approximately $25 million in ETH.

## What changed

Resolv halted backend services, paused relevant contracts, revoked and rotated compromised credentials, and neutralized approximately 46 million illicit USR through burns and blacklist functionality. The incident demonstrated that an off-chain signing compromise could become an unconstrained on-chain mint.

## What did not change

Resolv reported that its collateral pool was not directly compromised. The postmortem did not establish complete recovery, a protocol restart, full compensation for every holder category, or that the rebuilt system was safe or advisor-appropriate.

## Confirmed

- The official postmortem dates the incident to March 22, 2026.
- Two illicit Counter transactions minted 50 million and 30 million USR, respectively.
- Resolv attributed approximately $25 million of extracted value to the attack.
- Relevant contracts with pause functionality were paused and identified compromised credentials were revoked.
- Approximately 46 million of the 80 million illicit USR had been neutralized when the postmortem was published.
- Most pre-incident USR holders had received or were in the pipeline for 1:1 compensation.

## Still open

- The external forensic investigation, attacker attribution, and upstream compromise remained open.
- The disposition of the remaining illicit USR and recovery of extracted value were incomplete.
- Final outcomes for post-incident holders, liquidity providers, RLP holders, and other affected integrations were not established.
- Deployment and independent verification of the planned on-chain mint caps, oracle validation, and automated pause controls remained pending.
- The timeline and conditions for resuming paused protocol operations were unresolved.

## What it means for an advisor

- The Resolv USR diligence file should treat off-chain signing infrastructure and cloud access policy as direct mint-authority dependencies, not merely operational support.
- The later Resolv rejection should be checked to ensure it records the unconstrained mint path, pause and blacklist powers, incomplete recovery, and cross-organization credential risk.
- Compensation of some holders and planned safeguards do not satisfy reopening criteria or establish advisor suitability.

## Sources

1. [Resolv Postmortem: March 22, 2026 Incident](https://resolv.xyz/blog/resolv-postmortem-march-22-2026-incident) · Resolv · 2026-04-04


---

Published by Ketju Research on RIADeFi (https://riadefi.com). Educational research for financial professionals; not investment, legal, tax, or compliance advice.
