Futures
Hundreds of contracts settled in USDT or BTC
TradFi
Gold
One platform for global traditional assets
Options
HOT
Trade European-style vanilla options
Unified Account
Maximize your capital efficiency
Demo Trading
Futures Kickoff
Get prepared for your futures trading
Futures Events
Participate in events to win generous rewards
Demo Trading
Use virtual funds to experience risk-free trading
Launch
CandyDrop
Collect candies to earn airdrops
Launchpool
Quick staking, earn potential new tokens
HODLer Airdrop
Hold GT and get massive airdrops for free
Launchpad
Be early to the next big token project
Alpha Points
New
Trade on-chain assets and enjoy airdrop rewards!
Futures Points
New
Earn futures points and claim airdrop rewards
Investment
Simple Earn
Earn interests with idle tokens
Auto-Invest
Auto-invest on a regular basis
Dual Investment
Buy low and sell high to take profits from price fluctuations
Soft Staking
Earn rewards with flexible staking
Crypto Loan
0 Fees
Pledge one crypto to borrow another
Lending Center
One-stop lending hub
VIP Wealth Hub
Customized wealth management empowers your assets growth
Private Wealth Management
Customized asset management to grow your digital assets
Quant Fund
Top asset management team helps you profit without hassle
Staking
Stake cryptos to earn in PoS products
Smart Leverage
New
No forced liquidation before maturity, worry-free leveraged gains
GUSD Minting
Use USDT/USDC to mint GUSD for treasury-level yields
#ResolvLabsHitByExploitAttack
Full Breakdown of the Incident
What Happened
On March 23, 2026, Resolv Labs, a DeFi protocol focused on delta‑neutral stablecoin infrastructure, suffered a critical security breach. The attacker exploited a vulnerability in the protocol’s smart contract architecture—specifically in the mint function of the RSLV stablecoin contract. By manipulating input validation logic, the attacker was able to bypass collateral checks and mint an excessive amount of RSLV tokens without depositing equivalent collateral.
Attack Flow & On‑Chain Evidence
According to blockchain security firms monitoring the event, the exploit occurred in a single transaction (hash: 0x…c3a7). The attacker:
1. Called a deprecated deployment wallet that still held administrative privileges.
2. Used those privileges to invoke a privileged minting function not protected by the protocol’s multi‑signature governance.
3. Minted 1,400,000 RSLV tokens in one batch.
4. Swapped the newly minted RSLV for ~420 ETH on a decentralized exchange.
5. Bridged the ETH to another chain (Avalanche) via a cross‑chain bridge to obfuscate funds.
Immediate Impact
· Total loss: Approximately $1.4 million at current market rates.
· Protocol TVL: Dropped from $8.2M to $6.8M within minutes as liquidity providers rushed to withdraw.
· Stablecoin peg: RSLV de‑pegged to $0.92 briefly before the team paused the contract, stabilizing near $0.98.
Team Response
Resolv Labs acknowledged the incident within 30 minutes. Actions taken:
· Paused all contract interactions via an emergency multisig.
· Disabled the compromised deployment wallet.
· Engaged with Chainalysis and three independent on‑chain forensics teams to track the stolen funds.
· Advised users to revoke approvals for the RSLV contract address and any associated LP pools.
· Announced a post‑mortem to be released within 72 hours, along with a compensation plan for affected liquidity providers.
Security Lessons
This exploit highlights two critical vulnerabilities that continue to plague DeFi:
· Privileged key management: The compromised deployment wallet retained minting rights long after deployment—a common oversight.
· Granular access controls: Functions that can alter token supply must be governed by time‑locks and multi‑step approvals, not single private keys.
The incident serves as a reminder that even protocols with multiple audits remain at risk if operational security around privileged addresses is not rigorously maintained.
Next Steps
Resolv Labs has stated that they will deploy a new contract suite after a third‑party audit, and will airdrop recovery tokens to affected users. The community is awaiting the detailed post‑mortem to understand whether any insurance or treasury funds will be used to cover the loss.
---
#DeFiExploit #ResolvLabs #SmartContractVulnerability #StablecoinSecurity