MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Hacker Drains $9.6 Million From DeFi Stablecoin Protocol Resupply – Decrypt
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$77,726.00-0.19%
  • ethereumEthereum(ETH)$2,326.660.20%
  • tetherTether(USDT)$1.000.01%
  • rippleXRP(XRP)$1.440.65%
  • binancecoinBNB(BNB)$638.100.10%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$86.811.33%
  • tronTRON(TRX)$0.323964-1.58%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.040.02%
  • dogecoinDogecoin(DOGE)$0.0993492.76%
Blockchain Security

Hacker Drains $9.6 Million From DeFi Stablecoin Protocol Resupply – Decrypt

Last updated: June 26, 2025 11:24 pm
Published: 10 months ago
Share

Resupply confirmed the exploit, paused the impacted wstUSR market, and said the stolen funds were laundered through Tornado Cash and split across multiple wallets.

A hacker drained $9.6 million from Resupply, a decentralized stablecoin protocol linked to major DeFi players Convex Finance and Yearn Finance. They did it by manipulating token prices to exploit a critical vulnerability in the platform’s exchange rate calculations.

The attacker artificially inflated the price of the cvcrvUSD, or Curve Vault for CurveUSD, token through targeted “donations” into an extremely thin market. Then they leveraged this manipulated price to borrow nearly $10 million worth of reUSD tokens against just one wei of collateral, according to blockchain security firm Phalcon.

The exploit is the latest in a string of major crypto security breaches that have cost the industry over $2.1 billion this year, pointing to persistent vulnerabilities in decentralized finance protocols despite growing security awareness.

“The attacker manipulated token prices, triggering a bug (zero exchange rate) in Resupply’s smart contract, letting them borrow a ton of money for almost nothing,” Hakan Unal, senior security operations lead at Cyvers, told Decrypt.

This zero exchange rate allowed the attacker to completely bypass solvency checks and borrow massive amounts with negligible collateral.

After securing the loans, they quickly swapped the tokens through Curve and Uniswap for USDC and wrapped Ethereum, generating their $9.5 million profit.

“Users should avoid reUSD vaults and withdraw funds if possible,” Unal advised.

Additional analysis from PeckShield revealed the attack’s entry point: a transaction on Cow Swap involving 2 ETH, which was then funneled through anonymous coin mixer Tornado Cash for anonymity.

Cow Swap is a decentralized exchange that enables users to trade crypto without front-running protection. The attacker ultimately extracted approximately 1,581 ETH from the protocol.

“Resupply has experienced an exploit in the wstUSR market,” the platform confirmed the breach through its official X account. “The affected contract has been identified and paused. Only the wstUSR market was impacted and the protocol continues to function as intended.”

The platform announced it had paused the affected market while maintaining normal operations elsewhere, promising “a full post-mortem will be shared as soon as a complete analysis of the situation has been conducted.”

CertiK reported the exploiter moved approximately $5.56 million to one address and $4 million to another, consolidating the stolen funds across two wallets containing 2.2K ETH and 1.6K ETH respectively.

The Resupply exploit continues a troubling pattern of major crypto breaches this year.

Just over a week earlier, Iranian crypto exchange Nobitex suffered a $49 million breach attributed to the pro-Israel hacker group “Gonjeshke Darande.”

The group used provocatively named wallet addresses and effectively burned the stolen funds to make a political statement rather than profit from the theft.

Read more on Decrypt

This news is powered by Decrypt Decrypt

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Zoomex Lab Sponsors Web3 Year-End Gala: Seoul 2025, Ushering in a ‘User-First’ Payment Era for 2026
Comparing Proof-of-Stake And Delegated Proof-of-Stake
GeniZenith Launches Proactive Security and Transparency Initiative to Combat Industry-Wide Misinformation and Enhance User Trust
MOBU is Top Crypto Presale to Buy as TRX, XMR Stay Volatile
CrossBar Inc. and CertiK Unite at TOKEN2049 Singapore to Showcase Enhanced Multi-Party Computation (EMPC) and Open-Source Hardware to Redefine Blockchain Security.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Why Ozak AI Is Being Called the Next Big AI-Powered Gem
Next Article Codename: Pepe (AGNT) Explodes in Popularity as Investors Rethink the Top Long-Term Pepe Coin
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d