Hacker Drains .6 Million From DeFi Stablecoin Protocol Resupply Hacker Drains .6 Million From DeFi Stablecoin Protocol Resupply

Hacker Drains $9.6 Million From DeFi Stablecoin Protocol Resupply

In brief

  • A hacker drained nearly $9.6 million from Resupply by exploiting a vulnerability in its exchange rate system tied to the cvcrvUSD token.
  • The attacker manipulated token prices in Resupply’s low-liquidity market, triggering a zero exchange rate bug that let them borrow millions with one wei of collateral.
  • Resupply confirmed the exploit, paused the impacted wstUSR market, and said the stolen funds were laundered through Tornado Cash and split across multiple wallets.

A hacker drained $9.6 million from Resupply, a decentralized stablecoin protocol linked to major DeFi players Convex Finance and Yearn Finance. They did it by manipulating token prices to exploit a critical vulnerability in the platform’s exchange rate calculations.

The attacker artificially inflated the price of the cvcrvUSD, or Curve Vault for CurveUSD, token through targeted “donations” into an extremely thin market. Then they leveraged this manipulated price to borrow nearly $10 million worth of reUSD tokens against just one wei of collateral, according to blockchain security firm Phalcon.

The exploit is the latest in a string of major crypto security breaches that have cost the industry over $2.1 billion this year, pointing to persistent vulnerabilities in decentralized finance protocols despite growing security awareness.

“The attacker manipulated token prices, triggering a bug (zero exchange rate) in Resupply’s smart contract, letting them borrow a ton of money for almost nothing,” Hakan Unal, senior security operations lead at Cyvers, told Decrypt.

This zero exchange rate allowed the attacker to completely bypass solvency checks and borrow massive amounts with negligible collateral.

After securing the loans, they quickly swapped the tokens through Curve and Uniswap for USDC and wrapped Ethereum, generating their $9.5 million profit.

“Users should avoid reUSD vaults and withdraw funds if possible,” Unal advised.

Additional analysis from PeckShield revealed the attack’s entry point: a transaction on Cow Swap involving 2 ETH, which was then funneled through anonymous coin mixer Tornado Cash for anonymity.

Cow Swap is a decentralized exchange that enables users to trade crypto without front-running protection. The attacker ultimately extracted approximately 1,581 ETH from the protocol.

“Resupply has experienced an exploit in the wstUSR market,” the platform confirmed the breach through its official X account. “The affected contract has been identified and paused. Only the wstUSR market was impacted and the protocol continues to function as intended.”

The platform announced it had paused the affected market while maintaining normal operations elsewhere, promising “a full post-mortem will be shared as soon as a complete analysis of the situation has been conducted.”

CertiK reported the exploiter moved approximately $5.56 million to one address and $4 million to another, consolidating the stolen funds across two wallets containing 2.2K ETH and 1.6K ETH respectively.

The Resupply exploit continues a troubling pattern of major crypto breaches this year.

Just over a week earlier, Iranian crypto exchange Nobitex suffered a $49 million breach attributed to the pro-Israel hacker group “Gonjeshke Darande.”

The group used provocatively named wallet addresses and effectively burned the stolen funds to make a political statement rather than profit from the theft.

Edited by Stacy Elliott.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Source link

Stacy Elliott

https://decrypt.co/327148/hacker-drained-9-6-million-from-defi-stablecoin-protocol-resupply

2025-06-26 14:51:38

bitcoin
Bitcoin (BTC) $ 121,748.00 0.07%
ethereum
Ethereum (ETH) $ 4,410.90 1.21%
bnb
BNB (BNB) $ 1,301.26 0.93%
tether
Tether (USDT) $ 1.00 0.02%
xrp
XRP (XRP) $ 2.81 1.59%
solana
Solana (SOL) $ 223.90 1.27%
usd-coin
USDC (USDC) $ 0.999697 0.00%
staked-ether
Lido Staked Ether (STETH) $ 4,410.87 1.13%
dogecoin
Dogecoin (DOGE) $ 0.246507 0.19%
tron
TRON (TRX) $ 0.338618 0.39%
cardano
Cardano (ADA) $ 0.812664 0.60%
wrapped-steth
Wrapped stETH (WSTETH) $ 5,367.65 1.12%
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 4,761.76 1.20%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 121,706.00 0.01%
chainlink
Chainlink (LINK) $ 21.90 0.13%
ethena-usde
Ethena USDe (USDE) $ 0.998542 0.21%
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.02 2.07%
sui
Sui (SUI) $ 3.44 1.04%
hyperliquid
Hyperliquid (HYPE) $ 45.25 2.44%
stellar
Stellar (XLM) $ 0.377412 0.51%
avalanche-2
Avalanche (AVAX) $ 28.34 0.29%
wrapped-eeth
Wrapped eETH (WEETH) $ 4,763.50 1.10%
bitcoin-cash
Bitcoin Cash (BCH) $ 577.67 0.08%
weth
WETH (WETH) $ 4,420.75 1.01%
hedera-hashgraph
Hedera (HBAR) $ 0.212592 2.07%
litecoin
Litecoin (LTC) $ 116.94 0.52%
leo-token
LEO Token (LEO) $ 9.66 0.05%
mantle
Mantle (MNT) $ 2.65 11.28%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.99668 0.65%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 121,798.00 0.09%
usds
USDS (USDS) $ 0.999268 0.05%
usdt0
USDT0 (USDT0) $ 1.00 0.03%
shiba-inu
Shiba Inu (SHIB) $ 0.000012 0.36%
the-open-network
Toncoin (TON) $ 2.73 0.63%
crypto-com-chain
Cronos (CRO) $ 0.19283 3.80%
whitebit
WhiteBIT Coin (WBT) $ 43.72 0.75%
monero
Monero (XMR) $ 336.39 4.43%
polkadot
Polkadot (DOT) $ 4.05 2.61%
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.20 0.05%
world-liberty-financial
World Liberty Financial (WLFI) $ 0.177788 0.68%
uniswap
Uniswap (UNI) $ 7.82 0.54%
dai
Dai (DAI) $ 0.999822 0.08%
okb
OKB (OKB) $ 212.03 2.44%
aave
Aave (AAVE) $ 279.12 0.15%
ethena
Ethena (ENA) $ 0.563674 4.41%
bitget-token
Bitget Token (BGB) $ 5.68 1.22%
pepe
Pepe (PEPE) $ 0.000009 0.89%
near
NEAR Protocol (NEAR) $ 2.89 2.11%
aptos
Aptos (APT) $ 5.04 4.53%
memecore
MemeCore (M) $ 2.04 2.31%