Unchained
Unchained

Uneasy Money: How the Resolv Hack Shows an Audit Doesn't Mean 'Secure'

Chaos Labs’ Omer Goldberg joins the crew to dig into the Resolv Labs exploit. Why was the USR minting function controlled by a single key? And how did audits miss it? Thank you to our sponsors! ⁠⁠⁠⁠⁠⁠Fuse: The Energy Network ⁠⁠⁠⁠⁠ – Shift your energy use and earn rewards. ⁠⁠⁠⁠⁠⁠MultiChain Advisors -

Topics Discussed

Episode Summary

Executive Summary: The episode centers on the Resolve hack and its ripple effects across DeFi, using it as a case study for why basic operational security, threat modeling, and conservative risk controls matter more than flashy smart-contract audits. The hosts and guest argue that infinite-mint risks, poor key management, weak monitoring, and overly permissive lending/curation designs created preventable contagion across protocols like Morpho, Curve, Fluid, and Venus. The discussion ends with Aave v4 as a more granular, risk-segregating evolution of lending architecture.

Main Topics: Resolve hack: AWS key compromise and infinite mint exploit (Priority: 5/5): The core incident involved a compromised AWS-hosted private key that allowed an attacker to mint unbacked USR, dump it for ETH, and trigger large downstream losses and depegs. The speakers emphasize that this was fundamentally a basic key-management failure, not a sophisticated on-chain exploit. Operational security and threat modeling failures (Priority: 5/5): The conversation repeatedly stresses that DeFi teams often obsess over complex on-chain risks while neglecting basic OpSec: single-key custody, alerting, multi-party approval, and secure secret storage. The speakers argue that these basics should be part of any real security review. Contagion across DeFi lending and liquidity venues (Priority: 5/5): Because USR was widely composable, the hack spread into Curve pools, lending markets, and vaults. The episode explains how bad collateral, thin liquidity, and overly broad integrations amplified the original failure into protocol-level bad debt. Curated vaults, responsibility, and accountability (Priority: 4/5): The hosts debate whether vault curators and protocol integrators are effectively taking on fiduciary-like duties when they whitelist assets or route liquidity. The guest argues that curators need stronger due diligence, ceilings, and transparency because users delegate risk judgment to them. Aave v4 and the move toward segregated risk architecture (Priority: 4/5): The discussion shifts to Aave v4’s hub-and-spoke design, which aims to isolate risk more deliberately than monolithic pooled lending. The guest frames v4 as an evolution that preserves capital efficiency while improving configurability and limiting contagion. Institutional standards, market power, and forcing functions (Priority: 3/5): The panel argues that institutional capital and major protocols can improve ecosystem security by demanding baseline diligence, disclosures, and secure default configurations. They compare this to exchange listings and SOC2-style expectations in TradFi.

Key Arguments: The Resolve incident was primarily a web2-style key compromise: once an attacker accessed AWS, they could instruct the mint key to create unlimited USR. Moving sensitive keys from a laptop to AWS does not eliminate risk; it only changes the attack path, so multi-sig, 2FA, biometrics, monitoring, and approval thresholds are still necessary. Audit counts alone are meaningless if they are narrow in scope; repeated point audits can become security theater without an upfront threat model. Stablecoin and asset issuers should impose velocity caps, debt ceilings, and reserve checks to limit the blast radius of a compromise. Composability is both DeFi’s strength and its weakness: once an asset is integrated broadly, a single upstream failure can cascade across multiple protocols. Curators are implicitly paid to deliver better risk-adjusted returns, not just more yield; if they ignore risk, they are failing their role. Unlimited credit lines against questionable collateral are indefensible; risk controls should scale with asset quality and observed demand. Aave v4’s hub-and-spoke model is meant to preserve the benefits of pooled liquidity while reducing cross-market contamination. Institutions and large protocols can act as a forcing function for better security standards by requiring diligence before integration.

Data Points: Funds stolen / bad debt created in Resolve exploit: $54 million - Stated as the amount ultimately lost after the attacker compromised AWS and exploited the mint process. Initial exploit cost: $300,000 - The attacker spent a relatively small amount to begin the exploit and mint unbacked USR. Unbacked USR minted: $80 million - The attacker minted a large amount of USR with no corresponding backing. ETH extracted: $24 million - Described as the amount of ETH the attacker walked away with after dumping USR. Price collapse of USR: from $1 to about $0.025 - The hosts described the stablecoin as crashing to roughly two and a half cents. Mint-to-backing ratio: 266:1 - The guest cited the ratio between USR minted and what was actually backed at the end of the incident. Morpho exposure at time of hack: about $5K - At the moment of the exploit, Morpho’s direct exposure was initially very small before allocator-driven contagion expanded it. Morpho losses after contagion: around $8M to $10M - The guest estimated aggregate losses across Morpho markets after automated allocation and borrowing against USR. Fluid losses: over $20M - One of the main venues that accepted USR collateral and saw significant draining. Venus losses: over $20M - Another major lending venue that was heavily impacted by the USR contagion. Public allocator open duration: 90 minutes to 10 hours - Different curators/vaults remained exposed for varying lengths of time due to allocator behavior. Response timing referenced: about 3 hours - The protocol was reportedly pulled/pause after roughly three hours, which the hosts questioned as slow relative to the severity. Security coverage reference: 14 audits - A figure mentioned in discussion, with the caveat that the audits were narrow and not holistic. Aave v4 structure: hub-and-spoke - Used to describe the proposed architecture intended to separate risk across markets. Curation/Org security example: head of security + six-figure salary - Luca described Pudgy Penguins’ dedicated OpSec role as evidence of the seriousness of the security posture.

Pivotal Quotes: "what happens on chain never stays on chain" — Kane Warwick: Opening framing for the show and the reason protocol failures can cascade across DeFi. "this is a very web 2-oriented hack" — Taylor Monahan: Her characterization of the Resolve exploit as fundamentally a key-management and OpSec failure rather than a novel smart-contract attack. "yield should reflect units of risk that you're taking" — Omer Goldberg: Used in the discussion of curators, vaults, and why higher returns must imply higher risk.

Implications: DeFi teams, curators, and lenders need stricter OpSec, clearer asset controls, and explicit risk segmentation. The industry is moving toward institutional-grade diligence and architectures like Aave v4 that can contain failures instead of broadcasting them.

🔓 Sign Up for Unlimited Episode Search

About Unchained

View all episodes from Unchained