Resolv USR

Green · 75/100

Executive summary

Resolv USR is a delta-neutral, overcollateralized stablecoin on Ethereum targeting a $1 peg, backed by ETH, staked ETH, BTC, and stablecoins with perpetual-futures hedging; it scores 50/100 (orange band) primarily due to an unresolved March 2026 incident.

  • Security: Multiple audits by MixBytes, Pashov, Pessimistic, and Sherlock (2024) covered core contracts, staking, treasury, and connectors; findings included 1 critical stUSR inflation attack (fixed), 2 high staking issues (3 fixed, 1 acknowledged), and medium treasury/slippage issues (mixed resolution); all audits verified deployed code where documented, but none flagged the off-chain mint-key architecture as a critical risk.
  • Incidents: On March 22, 2026, attackers compromised an AWS KMS-hosted SERVICE_ROLE signing key and minted ~80M unbacked USR from ~$200K USDC, extracting ~$23–25M and causing USR to depeg from $1 to ~$0.025; Resolv paused operations, burned illicit USR, blacklisted exploiter wallets, and enabled staged recovery (>$77M redeemed for pre-incident holders, 0.5 USDC per post-incident USR/wstUSR offered); however, full reimbursement and protocol restart remain unverified, and the incident is classified as unresolved with a -10 penalty.
  • Governance & custody: Hybrid governance led by Resolv Labs Ltd and Resolv Digital Assets Ltd (BVI); a reported 3-of-5 Gnosis Safe controls admin roles with a 72-hour timelock for upgrades, but operational powers (pause, mint, role grants) can bypass the timelock; Snapshot voting by stRESOLV holders is advisory only and does not control upgrades or company funds; custody is mixed on-chain treasury plus institutional custodians (Fireblocks, Ceffu), with exact wallet balances and segregation not verifiable as of September 5, 2026.
  • Top risks: Catastrophic privileged-minting failure demonstrated in March 2026 via single AWS KMS key compromise, enabling unbacked issuance and severe depeg; high counterparty/dependency risk from centralized exchanges, custodians, oracles, and derivatives venues for hedging and collateral management; incomplete recovery with protocol still restricted and some holder categories not fully reimbursed; missing on-chain mint caps and oracle validation at time of incident; current reserve composition, collateralization ratio, and withdrawal status are not verifiable.
  • Strengths: Delta-neutral design hedges ETH/BTC exposure via perpetual futures to support $1 peg; native yield generation from staking and funding rates; crypto-native collateral base reduces fiat-banking reliance; transparent proof-of-reserves dashboards and auditable on-chain structure; capital-efficient compared to traditional overcollateralized stablecoins; active Immunefi bug bounty ($500K max) and multiple independent audits.
  • Unverified: Current Ethereum reserve balances, liabilities, collateralization ratio, TVL, and on-chain supply are not verifiable as of September 5, 2026 due to unavailable Dune access; exact counterparty exposures, leverage ratios, and post-incident remediation steps (role holders, timelock execution, renunciation) are not verifiable; full founder roster, legal entity details, and physical offices are not verifiable; organic vs. subsidized yield breakdown is not quantifiable.
  • Recommended exposure: Zero or minimal allocation until incident remediation is independently verified and protocol operations fully resume; if considering exposure post-recovery, limit to <1% of portfolio, require third-party verification of reserve composition and collateralization >120%, confirm on-chain mint caps and oracle validation are implemented, verify multisig controls for all privileged roles, and monitor redemption queue and depeg risk daily; treat as high-risk experimental exposure only after full transparency is restored.
  • Open questions: Has the protocol fully resumed minting/redemptions and lifted all restrictions? What are the current on-chain reserve balances, liabilities, and collateralization ratio? Have multisig controls replaced the single AWS KMS key for minting authority? What on-chain mint caps and oracle validation have been implemented post-incident? What is the exact counterparty exposure to CEXs, custodians, and derivatives venues? Have all affected holders been fully reimbursed, and what is the final recovery rate by holder category? What independent verification exists for the claim that the collateral pool remained intact during the incident?

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 18 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 100 20.0 full audit within 365 days (latest 2026-01-15)
Incidents 20% 100 20.0 1 open incident(s), $0 at risk = 0.0% of TVL (threshold 10%)
Governance 20% 75 15.0 a single party can withdraw funds (admin_can_drain)
TVL 20% 0 0.0 TVL $6,304,743 = 0% of reference ($17,538,184,136)
Data confidence 91 7/7 critical categories; 25/47 verified facts; 47/47 fresh (180d)

Identification

protocol identification

two sources

Resolv USR (USR) is a delta‑neutral, overcollateralized stablecoin protocol on Ethereum, issuing USR as the senior, dollar‑pegged asset in a multi‑token system with RLP and RESOLV. ### Protocol identification

  • Name & category: Resolv (Resolv Labs); DeFi stablecoin / yield stablecoin, delta‑neutral and overcollateralized.
  • Core product: USR – crypto‑native stablecoin targeting a $1 peg, backed mainly by ETH, staked ETH, BTC and stablecoins via delta‑neutral strategies (long spot, short perps).
  • Website: resolv.xyz (protocol/app).
  • Docs: docs.resolv.xyz with a litepaper and product pages; USR is described as overcollateralized, mintable/redeemable 1:1 vs liquid collateral, with an insurance layer via RLP and a staked version stUSR.
  • Token ecosystem:
  • USR – senior stablecoin, non‑yielding; users stake into stUSR for yield.
  • RLP – junior/insurance tranche absorbing CeFi/DeFi and strategy risks, earning leveraged yield.
  • RESOLV – governance/rewards token for the protocol.
  • Chains: Natively on Ethereum, with multichain support/bridging to Base and BNB Chain via LayerZero and the app.
  • Launch date: Public narratives and Binance/Medium pieces describing Resolv as “new” and explaining architecture appear in 2023–2025, with a Binance explainer dated August 2025; precise on‑chain launch block/time is Not verifiable as of 2026‑09‑03.
  • Main contract addresses (Ethereum):
  • Wrapped stUSR (wstUSR) ERC‑20 at 0x1202F5C7b4B9E47a1A484E8B270be34dbbC75055, labeled “Resolv USR: wstUSR Token” on Etherscan; contract is verified with source code published.
  • Addresses for USR, stUSR, RLP, and core vault/treasury contracts are referenced in docs/app but specific contract lists and cross‑checks are Not verifiable as of 2026‑09‑03 without direct on‑chain querying. ### Fork lineage & design origin
  • Fork / lineage: External sources describe Resolv/USR as a delta‑neutral stablecoin similar in narrative to Ethena, but as a distinct architecture issued by Resolv Labs; it is *not explicitly documented as a direct smart‑contract fork* of Ethena or another protocol. Any precise fork status is Not verifiable as of 2026‑09‑03.
  • What changed vs upstream: Public materials emphasize risk‑tranching (USR senior, RLP junior) and an insurance layer on top of overcollateralized delta‑neutral strategies, differentiating it from typical single‑tranche funding‑rate stablecoins.
  • Audits: References to audits are not visible in the retrieved third‑party sources; the existence, scope, and auditors of any security review are Not verifiable as of 2026‑09‑03.
  • Malicious‑modification history in similar forks: No credible reports of Resolv USR being a malicious fork or of exploit incidents specifically tied to forked codebases were found; nonetheless, absence of evidence is not proof of safety, and detailed incident history is Not verifiable as of 2026‑09‑03.
Evidence (10)

maturity

two sources

Resolv USR appears to have a real product portal, not just a static landing page: the main site describes the protocol, and the documentation exposes operational mint/burn flows plus developer-oriented contract references and an API-style docs endpoint. The docs indicate live user functionality for minting and burning USR via request-based flows, with supported deposit/withdrawal assets and cancellation paths, which is consistent with an active app rather than a brochure-only site. The interface maturity looks moderate: there is enough documentation to explain supply operations and user flows, but the product appears partially mediated by backend processing and whitelisting, so it is not a fully permissionless self-serve app.

I did not find reliable evidence of broken links or fake metrics in the material surfaced here, and those specific issues are not verifiable as of 2026-09-03. An open API is likely available for documentation queries: the docs explicitly provide an HTTP GET endpoint using an ask parameter for dynamic questions. That said, a broader public trading or account API is not verifiable as of 2026-09-03.

Evidence (4)

Security

bug bounty

two sources

Resolv maintains an active public bug bounty program hosted on Immunefi. The program is listed by Resolv’s security page as public and ongoing, and Immunefi’s scope page shows multiple targets added over time, with the latest listed addition on 15 January 2026 and earlier scope entries dating to 31 March 2025. Reported program parameters include an ongoing responsible-disclosure bounty program and a stated maximum bounty level of $500,000 in secondary coverage.

In March 2026, Resolv separately offered an ad hoc 10% white-hat-style bounty to the attacker after the USR exploit, asking for 90% of funds returned within 72 hours; that was an incident response offer, not the standing program. Publicly reported results include the March 2026 exploit response and recovery ultimatum, but no verifiable public tally of bounty payouts or completed awards was found.

Active
Yes
Platform
Immunefi
Max payout
$500K
Since
2025-03-31
Evidence (3)

counterparty risks

two sources

Assessment — HIGH counterparty/dependency risk; current failure state. On-chain verification is unavailable in this run: Not verifiable as of 2026-09-05. Resolv’s own documentation describes dependence on ETH/staked ETH, BTC, USD-neutral assets, staking, futures hedges, lending, tokenized RWAs, CEX/DEX execution, and institutional custodians; disclosed allocation percentages and counterparty limits are unavailable. These are issuer claims and should be treated as unverified marketing claims. Active incident / issuer failure: On March 22, 2026, a compromised privileged signing key enabled approximately 80M unbacked USR to be minted from roughly $200K of USDC.

USR reportedly fell from $1 to approximately $0.025, while the attacker extracted approximately $23–26.8M. The failure was primarily operational/key-management and missing on-chain mint bounds, not an oracle-price manipulation. Independent tracking still describes the protocol as restricted and recovery as unresolved; the issuer states the underlying collateral pool remained intact, but this cannot be independently verified here. Dependency map and scenarios:

  • Off-chain signer / AWS KMS: demonstrated single-key failure can create unbacked liabilities and immediate depeg.
  • CEXs, market makers, custodians and derivatives venues: hedging and margin depend on centralized execution, custody, liquidation, withdrawal and counterparty solvency. Exact exposure is Not verifiable as of 2026-09-05.
  • DeFi integrations: USR/wstUSR collateral use transmitted losses and liquidity stress to lending markets after the depeg. Smart-contract, oracle, liquidation and liquidity cascades remain material risks.
  • RWA/tokenized assets: issuer/SPV, custodian, legal enforceability, NAV/redemption and oracle risks apply. Resolv’s reported JAAA/Centrifuge/Aave deployment is an issuer disclosure, not independently verified here.
  • Bridges: Ethereum-only bridge exposure and the existence of any active bridge dependency are Not verifiable as of 2026-09-05. Worst case: further unauthorized minting, loss of collateral access, hedge/custodian/CEX insolvency, RWA redemption failure, or a USR depeg causing protocol and integrated-lending bad debt. RLP may absorb some losses, but its capacity and current status are Not verifiable as of 2026-09-05.
Dependency failure active
Yes
Evidence (5)

crypto custody

two sources

Resolv USR’s custody structure is not fully verifiable as of 2026-09-05 from the available sources. The best-supported picture is a mixed model: most backing appears to sit in on-chain treasury/contracts, while some collateral and hedging margin is handled through institutional custodians (named in prior disclosures as Ceffu and Fireblocks) and exchange-facing settlement arrangements. Because there is no on-chain verification available here, the exact split, wallet segregation, and control model remain unconfirmed.

Withdrawal status for the protocol is not verifiable as of 2026-09-05. Segregated assets: not verifiable as of 2026-09-05.

Evidence (3)

incident

one source

Resolv USR: Frontend & Infrastructure via Key Leaked via Infrastructure on Ethereum; loss $24,500,000 (DeFiLlama hacks registry).

Date
2026-03-21
Cause
Frontend / infrastructure hack
Loss
$24.5M
Status
status unknown
Classification
Frontend & Infrastructure
Technique
Key Leaked via Infrastructure
Evidence (1)

incident

two sources

Ethereum incident on March 22, 2026: an attacker compromised Resolv’s AWS KMS-hosted SERVICE_ROLE key and used completeSwap() to mint approximately 80M unbacked USR against roughly $200K of USDC. The missing controls were privileged single-key signing, no oracle/collateral validation, and no mint cap. USR fell from $1 to approximately $0.025; affected parties included pre- and post-incident USR/wstUSR holders, RLP holders, LPs, lending protocols and ecosystem counterparties.

The reported incident loss is $24.5M; this figure is close to the attacker’s realized extraction, while Resolv initially reported approximately $0.5M of redemptions before the pause and third-party analyses identified additional downstream bad debt. The attacker’s proceeds were approximately $23–25M, primarily ETH/stablecoins. Response: contracts and operations were paused; approximately 9M illicit USR was burned, approximately 36M wstUSR was blacklisted, and remaining exploiter-held USR was burned.

Resolv enabled staged recovery: more than $77M was redeemed for allowlisted pre-incident wallets, and Stage 2 offered 0.5 USDC per post-incident USR/wstUSR, up to 95% reference recovery for certain LP positions, and partial RLP recovery plus RESOLV vesting. Users were therefore partially reimbursed, but full reimbursement and final protocol restart/recovery were not verified. Remediation included key/infrastructure containment, contract and issuance-process changes, external investigations, and ecosystem settlements; the post-incident recovery framework remains incomplete.

Current status: unresolved.

Date
2026-03-22
Cause
Key compromise
Loss
$24.5M
Attacker proceeds
$24.5M
Status
unresolved
Recovered
$77.0M
Reimbursed
Yes
Evidence (5)

incident

one source

Affected parties explicitly named by Resolv include holders of USR and wstUSR, RLP users, lending-market participants, and other ecosystem integration counterparties. Resolv says the collateral pool remained intact, with the damage concentrated in illicit USR issuance and downstream market disruption rather than a drain of backing assets.

Date
2026-03-22
Cause
Other
Evidence (3)

key management

two sources

Resolv’s key management for USR minting was organized around a privileged off-chain signer rather than fully autonomous on-chain control. In the normal flow, users deposited USDC and submitted a requestSwap, then an off-chain service operating under SERVICE_ROLE used a private key to call completeSwap and finalize the exact USR amount to mint. The critical security detail is that this signing key was stored in AWS Key Management Service (KMS) infrastructure, and multiple incident reports say the attacker compromised that KMS environment and obtained the minting authority key associated with wallet 0x15CAd41e6BdCaDc7121ce65080489C92CF6de398.

That means the protocol’s minting control depended on a cloud-hosted key custody setup with privileged signing access, not on a purely on-chain cap or oracle-enforced limit. From a risk-organization perspective, this is a single privileged signing path for mint authorization: the contract checked that a valid signature existed, while the off-chain signer determined the minted amount. The reports I found do not verify the use of multisig for this minting role; they instead point to a single compromised private key inside AWS KMS.

Therefore, the key-management structure can be described as centralized operational signing with cloud key custody, and the compromise of that signer was sufficient to mint unbacked USR.

Evidence (7)

smart-contract

two sources

Assessment date: September 5, 2026. Critical admin/key risk. Dune MCP was unavailable; therefore proxy-admin events, current role holders, renunciation, timelock execution delay, and post-incident remediation are Not verifiable as of September 5, 2026. Addresses / architecture (Ethereum)

  • USR proxy: 0x66a1e37c9b0eaddca17d3662d6c05f4decf3e110; verified EIP-1967 Transparent Proxy; implementation reported as 0xef4c4bcbe105170810b6ef58a286d9ce97a1fabe.
  • stUSR proxy: 0x6c8984bc7DBBeDAf4F6b2FD766f16eBB7d10AAb4; wstUSR proxy: 0x1202F5C7b4B9E47a1A484E8B270be34dbbC75055; RewardDistributor: 0xbE23BB6D817C08E7EC4Cd0adB0E23156189c1bA9 (reported non-proxy).
  • Reported governance path: 3/5 Gnosis Safe 0xd6889f307be1b83bb355d5da7d4478fb0d2af547 → 3-day TimelockController 0x290d9544669c9c7a64f6899a0a3b28d563f6ebee → proxy upgrades. Current configuration is not independently confirmed. Control surface / user exit
  • Historical audited code states admins could withdraw all funds; mint/burn and collateral management were controlled by privileged accounts.
  • Minting/redemption used allowlisted, backend-completed request flows; wrap/unwrap and staking were permissionless. Thus users could exit to USR through wrapping paths, but final redemption depended on whitelist/backend availability.
  • Pause, withdrawal, fee, oracle, strategy, role-grant/revoke functions and renounced roles: Not verifiable as of September 5, 2026. Incident / worst case On March 22, 2026, unauthorized minting entered the market; Resolv says the protocol paused and entered recovery mode. Public analysis attributes this to compromised privileged USR Counter minting controls, with approximately 80M unbacked USR reported minted. A compromised upgrade/admin key could replace logic; a compromised mint/service key could inflate supply; compromised treasury roles could withdraw collateral or freeze operations. The March incident demonstrates material rug, freeze, and insolvency risk. ``text Users → USR / stUSR / wstUSR ↓ Requests Manager / USR Counter → privileged mint/burn service ↓ Treasury / collateral / external strategies ↑ Safe / Timelock → proxy upgrades + admin parameters `` Contradiction: Resolv markets audited, transparent, instant-liquidity products, but its own recovery notice confirms a security incident, pause, and impaired post-incident USR recovery terms.
Admin can drain
Yes
Audited deployment
Yes
Upgradeable
Yes
Evidence (5)

audit

one source

Corrected publication record.

Auditor
MixBytes
Report date
2024-12-26
Scope
PoR oracles and redemption-price support, including UsrRedemptionExtension and price handling.
Findings
1 Critical plus lower-severity findings: redemption-price calculation flaw; redundant validation; hardcoded decimals; unsafe cast; unused return variable; additional low-severity issues.
Fix status
Findings marked Fixed with remediation commits; deployed-code match documented in the report.
Report url
https://github.com/mixbytes/audits_public/blob/master/Resolv/PoR%20Oracles/README.md
Report id
doc:238fedaea1c117a5
Covers deployed code
Yes
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

New publication indexed after the prior check.

Auditor
MixBytes
Report date
2026-01-15
Scope
ExternalRequestsCoordinator.
Findings
Not verifiable as of 2026-09-05 from the retrieved report text.
Fix status
Not verifiable as of 2026-09-05.
Report url
https://mixbytes.io/reports/resolv
Report id
doc:728f07d329b0e125
Evidence (1)

audit

one source

New published report.

Auditor
MixBytes
Report date
2025-05-27
Scope
Resolv staking system: ResolvStaking, ResolvStakingV2, checkpoints, silo, distributor and ResolvToken.
Findings
0 Critical, 2 High, 0 Medium, 2 Low: zero-address checkpoint can reset totalEffectiveSupply; self-transfer inflates effective balance; unrestricted emergency withdrawal of RESOLV; exact-balance reward check rejects valid funding.
Fix status
Three findings marked Fixed; emergency withdrawal restriction remains Acknowledged.
Report url
https://github.com/mixbytes/audits_public/blob/master/Resolv/Staking/README.md
Report id
doc:9537590409ebd6ca
Covers deployed code
Yes
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

New published report.

Auditor
MixBytes
Report date
2025-03-14
Scope
TreasuryIntermediateEscrow and UsrRedemptionExtension; Ethereum deployment reviewed.
Findings
0 Critical, 0 High, 0 Medium, 3 Low: FORCE_RELEASER_ROLE accounting underflow; unlimited token transfers through prior approvals; weak native-ETH/escrow association.
Fix status
All 3 marked Fixed with remediation commits.
Report url
https://github.com/mixbytes/audits_public/blob/master/Resolv/Treasury%20Escrow/README.md
Report id
doc:a008d04ba42fdeee
Covers deployed code
Yes
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

one source

Corrected publication record: official MixBytes index dates the report November 8, 2024.

Auditor
MixBytes
Report date
2024-11-08
Scope
stUSR token and associated staking/reward logic.
Findings
Not verifiable as of 2026-09-05 from the retrieved report text.
Fix status
Not verifiable as of 2026-09-05.
Report url
https://github.com/mixbytes/audits_public/tree/master/Resolv/stUSR
Report id
doc:b0fda7c9fed90af5
Evidence (1)

audit

one source

Corrected publication record: official MixBytes index dates the report November 4, 2024, not September 2024.

Auditor
MixBytes
Report date
2024-11-04
Scope
Treasury, AaveV3/Dinero/Lido connectors, request managers and related treasury logic.
Findings
0 Critical, 0 High, 3 Medium, additional Low findings: missing slippage protection; whitelist-related locked funds; low-value transaction inefficiency.
Fix status
Mixed: some findings Fixed; slippage and low-value transaction findings Acknowledged.
Report url
https://github.com/mixbytes/audits_public/blob/master/Resolv/Treasury/README.md
Report id
doc:b6b7e9107c4f2132
Covers deployed code
Yes
Unresolved critical
0
Unresolved high
0
Evidence (1)

audit

two sources

Public audit materials for Resolv’s stUSR include a project log showing audit/re-audit timelines, a public-report issuance step contingent on deployed-code verification, and a finding list that includes a critical inflation-attack issue on the empty StUSR pool. The README states the timeline was May 14, 2024 to June 7, 2024, with the audited code later published from a public repo commit; the report also says the critical issue was fixed in commit a1575cdc00cf04cc1f4344f5db268670c093dc2b. The available source does not give a complete critical/high/medium summary for all findings in the snippet, but it clearly identifies at least one critical issue and states it was fixed before the public report.

The audit note explicitly says the contractor verifies the deployed code against the re-audited version before issuing the public report, which is the clearest available Bytecode-match-style evidence in the provided sources.

Auditor
MixBytes
Report date
2024-06-07
Scope
stUSR
Evidence (2)

audit

one source

Resolv Security Audit Report

Auditor
MixBytes
Report date
2024-06-10
Scope
USR/RLP, stUSR, whitelist, request managers, RewardDistributor
Findings
Critical: 1; High: 0; Medium: 4; Low: 0. stUSR inflation attack.
Fix status
Fixed; deployed-code match documented.
Evidence (1)

audit

one source

Resolv Treasury audit

Auditor
MixBytes
Report date
2024-09
Scope
Treasury, AaveV3 connector, Lido connector, request managers
Findings
Not verifiable as of 2026-09-04.
Fix status
Not verifiable as of 2026-09-04.
Evidence (1)

audit

two sources

Additional audits in October–December 2024 on Treasury, connectors, price storage (RlpPriceStorage, UsrPriceStorage), ExternalRequestsManager, UsrRedemptionExtension, LidoTreasuryExtension, TheCounter, and related modules. One December core audit report by MixBytes is cited in media as finding no vulnerabilities in the reviewed contracts.

Auditor
MixBytes / Pashov (late-2024 components)
Report date
2024-12-15
Scope
Treasury, treasury connectors, price storage contracts, ExternalRequestsManager, UsrRedemptionExtension, LidoTreasuryExtension, TheCounter and other support modules for USR.[1][5][13]
Findings
Media referencing the January 2026 MixBytes audit states that their checklist-based review reported *no vulnerabilities found* in the USR mechanism as implemented on-chain.[13] However, incident analyses later highlight that the off-chain mint key architecture remained unbounded and was not captured as a smart-contract issue.[8][10][15]
Fix status
MixBytes’ claim of no findings applies to the specific code version and checklist; no separate fix tracking is needed, but this leaves the architectural mint-key exposure unaddressed. For other late‑2024 audits (e.g., LidoTreasuryExtension, TheCounter, price storages), detailed issue status is Not verifiable as of 2026‑09‑03.[5][13]
Evidence (2)

audit

one source

Resolv security review

Auditor
Pashov
Report date
2024-08
Scope
wstUSR
Findings
4 Medium and 3 Low reported; all resolved according to independent audit summary.
Fix status
Reported resolved; bytecode match not verifiable as of 2026-09-04.
Evidence (1)

audit

one source

Resolv security review — August

Auditor
Pashov
Report date
2024-09
Scope
Treasury, AaveV3/Lido connectors, request managers
Findings
Not verifiable as of 2026-09-04.
Fix status
Not verifiable as of 2026-09-04.
Evidence (1)

audit

one source

Resolv security review — October

Auditor
Pashov
Report date
2024-10
Scope
Treasury, Dinero connector
Findings
Not verifiable as of 2026-09-04.
Fix status
Not verifiable as of 2026-09-04.
Evidence (1)

audit

one source

A security review of Resolv’s wstUSR contract was performed over July 27–29, 2024. The scope was wstUSR in the resolv-contracts repository. The report lists 7 total findings: 4 medium and 3 low, with all 4 medium issues marked Resolved and 2 of the 3 low issues marked Resolved; 1 low issue remained Acknowledged.

No critical or high findings are shown in the provided excerpt. The report is a review of the repository code, but the excerpt does not explicitly prove bytecode/deployed-code matching for the production deployment, so deployed-code coverage is not verifiable from the provided snippet alone.

Auditor
Pashov Audit Group
Report date
2024-07-29
Scope
wstUSR
Evidence (1)

audit

one source

Resolv Security Analysis

Auditor
Pessimistic
Report date
2024-06
Scope
Core tokens, stUSR, whitelist, request managers, RewardDistributor
Findings
Not verifiable as of 2026-09-04.
Fix status
Not verifiable as of 2026-09-04; deployed-code match not established.
Evidence (1)

audit

one source

Resolv WstUSR Security Analysis

Auditor
Pessimistic
Report date
2024-08
Scope
wstUSR
Findings
Not verifiable as of 2026-09-04.
Fix status
Not verifiable as of 2026-09-04; deployed-code match not established.
Evidence (1)

audit

one source

Core protocol audit (Audit #5, November 2024) covering Treasury, AaveV3TreasuryConnector, DineroTreasuryConnector, LidoTreasuryConnector, ExternalRequestsManager, LPExternalRequestsManager, RewardDistributor, SimpleToken, stUSR, WstUSR, Treasury, AddressesWhitelist, plus USR and RLP tokens as part of the wider system. Sherlock’s own report is linked in Resolv docs.

Auditor
Sherlock
Report date
2024-11-30
Scope
Treasury smart contract; connectors; request managers; stUSR, wstUSR, USR, RLP, RewardDistributor, whitelist and related infra.[1][5]
Findings
Specific critical/high/medium counts not visible in snippets; Sherlock report likely lists them, but they are Not verifiable as of 2026‑09‑03 from retrieved text alone. External commentary stresses that all audits, including Sherlock’s, found the code operated as designed and did not flag the off‑chain mint key risk.[10][15]
Fix status
Sherlock’s issue status per item cannot be extracted from snippets; Not verifiable as of 2026‑09‑03. Post‑incident reports emphasize that audited on‑chain code remained unchanged and that the exploit stemmed from off‑chain key compromise rather than unresolved on‑chain bugs.[6][10][11][15]
Evidence (2)

audit

one source

Resolv Core Audit Report

Auditor
Sherlock
Report date
2024-12-02
Scope
Full core protocol
Findings
1 Medium: wstUSR inflation attack via stUSR share-price manipulation.
Fix status
Fixed via initial-deposit mitigation/PR #222; deployed-code match not independently verified.
Evidence (1)

Team & Reputation

founders

two sources

Resolv USR appears to be built by a small but identifiable team operating under the Resolv Labs brand, with partial founder disclosure and an offshore corporate setup; however, there is limited independent verification of the full team, legal entity details, or physical offices. Founders & team disclosure

  • Public materials consistently refer to Resolv Labs as the developer of the Resolv/USR protocol, but they do not list a full founding team or executive roster in the docs or app.
  • An external profile on IQ.wiki identifies Fedor Chmilev as a co‑founder of Resolv Labs and Resolv USR, stating he co‑founded Resolv Labs in 2023.
  • That same profile says Resolv Labs was established in the British Virgin Islands (BVI), which implies an offshore corporate structure.
  • I could not find independent confirmation of other named co‑founders, C‑level titles, or a formal team page on neutral sites. Not verifiable as of 2026-09-03. Public vs. anonymous, credibility signals
  • At least one founder (Chmilev) is publicly doxxed with a personal profile describing his role at Resolv Labs.
  • Mainstream aggregators (CoinMarketCap, CoinGecko) list Resolv/USR and attribute it to Resolv Labs, which is consistent but not a strong governance or identity proof.
  • I did not find prior, well‑documented large DeFi projects or major hacks linked to this founder in neutral sources. Not verifiable as of 2026-09-03 for broader founder track record. Jurisdiction, office, and “real business” checks
  • IQ.wiki states Resolv Labs is incorporated in the British Virgin Islands, suggesting an offshore jurisdiction commonly used for token projects and investment funds.
  • No independent evidence of a registered office address, regulated entity status, or licensing in major onshore jurisdictions (US/EU/UK/Singapore, etc.) surfaced in the time‑bounded search. Not verifiable as of 2026-09-03.
  • There is no clear indication of a traditional, revenue‑generating operating company beyond the on‑chain protocol and web front (app + docs). All visible activity is typical of a crypto‑native protocol business (token issuance, DeFi integrations, marketing content). Reality check for institutional risk
  • Pros: at least one identifiable co‑founder; consistent branding under Resolv Labs; listings on major data aggregators.
  • Cons / gaps: offshore (BVI) setup; no complete, independently verifiable team roster; no visible onshore regulated entity; no public confirmation of physical offices or board/governance structure. For institutional‑grade counterparty assessment, these are material information gaps that would warrant direct clarification from the team and legal DD on Resolv Labs’ corporate filings.
Evidence (6)

general reputation

two sources

Resolv’s reputation is mixed to negative: it is viewed as an innovative delta-neutral stablecoin project, but its credibility was materially damaged by a major March 2026 security incident in which attackers minted about 80 million unbacked USR and extracted roughly $23M–$25M, causing a sharp de-peg and protocol pause. Independent incident coverage also notes that the protocol’s collateral pool was not directly drained, but the exploit undermined confidence in USR’s minting and recovery process. Hindenburg-style risk scoring sources are not available here; the only score-like source in the results is Hindenrank, which rates Resolv D+/62 and explicitly calls it insolvent with an estimated ~$78M gap, a severe criticism that conflicts with the protocol’s own claim that collateral remains intact.

That contradiction is unresolved from the provided sources. On auditors, Resolv states its onchain code is audited by independent security firms, and third-party coverage names MixBytes, Pessimistic, Pashov Audit Group, and others; Nexus Mutual also said 18 audits had reviewed the contracts. The audit history does not prevent the incident, so the audits support diligence but not immunity.

Founder/investor sentiment is hard to verify from the provided material. A cited note says Aave founder Stani Kulechov stated zero exposure to USR, which is a neutral rather than supportive signal for investors. No reliable investor roster or endorsement set is verifiable as of 2026-09-03.

Legal/regulatory and sanctions issues are limited in the sources. One report says South Korea’s Upbit designated RESOLV as a trading caution item after the exploit, indicating exchange-level risk scrutiny. No sanctions, lawsuits, or regulator actions are verifiable as of 2026-09-03.

Unresolved concerns remain around recovery mechanics, the completeness of post-mortem disclosure, and whether trust can be restored after the exploit.

Evidence (9)

Economy

TVL: $6.3M

model

one source

Economic model — Resolv USR (Ethereum; reviewed September 5, 2026)

  • Strategy / directionality: Intended delta-neutral stablecoin. Collateral yield comes from ETH/BTC staking and short-perpetual funding carry; ETH price direction is hedged. Losses and funding-rate volatility are primarily subordinated to RLP, the junior/insurance tranche.
  • Assets in/out: USR is minted 1:1 against liquid assets such as USDC/USDT and redeemed 1:1 in notional value. Plain USR does not yield; users stake into stUSR/wstUSR. Regular redemption is fee-free and generally processed within 24 hours. RLP redemption is subject to the USR collateralization ratio remaining above 110%; instant redemption is allowlisted, capped, and carries a 0.05% fee.
  • Yield distribution: Current stated allocation is 76.5% of positive profit pro rata to stUSR/RLP, 13.5% risk premium to RLP, and 10% protocol fee. Losses during an epoch are allocated to RLP and distributions stop. Protocol fees apply only to positive yield.
  • Organic vs subsidized: Core yield is strategy-generated, but partnership rewards and ecosystem incentives contribute to broader protocol revenue. The organic share of user APY is not quantifiable from available evidence; set organic_yield_pct=null.
  • Leverage / external exposure: RLP is explicitly a leveraged junior layer, but no current numerical leverage ratio is disclosed; set leverage_ratio=null. External exposures include centralized/decentralized futures venues, liquid-staking products, lending protocols and an Aave Horizon RWA cluster—these are protocol-reported claims, not independently on-chain verified.
  • Fees / revenue: Minting and regular redemption: 0%; protocol fee: 10% of positive collateral-pool returns. Q4 2025 reported revenue was $970,231, including $635,657 core fees and $255,608 partnership rewards.
  • APY sustainability: Historical protocol modeling cited roughly 5–10% for USR and 20–30% for RLP, but these are backtests/benchmarks. Current DeFiLlama reports average tracked yield-pool APY of 3.8%, so APY is volatile and not demonstrably sustainable from the available time series.
  • TVL: DeFiLlama currently reports $12.66m TVL, 100% Ethereum; USR market cap is $723k. Dune TVL, product split, trend, collateral composition, and block-level metrics: Not verifiable as of September 5, 2026. > Contradiction: Resolv’s Q4 report claimed TVL above $470m by year-end 2025, versus DeFiLlama’s current $12.66m. The on-chain/aggregator current figure wins operationally; the gap is a material data-quality, depeg, or post-event finding.
Evidence (5)

reserves

two sources

Assessment date: September 5, 2026 — Ethereum only. Dune/raw-chain verification was unavailable in this run; therefore no current Ethereum reserve balance, wallet-balance, or liability calculation is asserted.

  • Liquid reserves (USD): Not verifiable as of September 5, 2026. liquid_reserves_usd: null
  • Liabilities (USD): Not verifiable as of September 5, 2026. liabilities_usd: null Known reserve design: Resolv documents describe a collateral pool containing ETH/staked ETH, BTC, and USD-neutral assets such as USDC/USDT, with portions deployed in DeFi clusters and hedged using short futures. The pool has both on-chain and off-chain components. Custody and locations: The documented structure is an on-chain smart-contract wallet plus institutional custody. Named custodians/venues include Fireblocks with delegated Deribit and Bybit exposure, and Ceffu with Binance exposure; the documentation states assets are held outside exchanges where applicable. Exact current Ethereum wallet addresses and balances were not available from the indexed sources. Not verifiable as of September 5, 2026. Composition/current size: Apostro provides a third-party reserve dashboard, but the accessible snapshot is historical and reports approximately $109.86M of backing assets, including weETH, USDT0, LBTC, JAAA, USDC, GHO and other positions. It should not be treated as a September 5, 2026 balance. Control/policy: RDAL issues and redeems USR and retains discretion over the collateral pool and redemption mechanics; terms allow postponement of redemption in cases of illiquidity, asset unavailability, or loss. RLP is designed as the junior/insurance layer absorbing losses, while protocol fees are allocated to the treasury. Attestations: Apostro is the identified third-party reserve verifier/dashboard. No current accounting-firm attestation was independently confirmed. Not verifiable as of September 5, 2026. > Contradiction / material change: Earlier materials described a fully intact, overcollateralized reserve model; the March 22, 2026 incident involved unauthorized minting of approximately $80M unbacked USR, followed by a recovery process. Current reserve coverage after recovery is not independently verifiable here. On-chain via Dune: Not verifiable as of September 5, 2026; no Dune query ID or execution ID is available.
Evidence (5)

tokenomics

two sources

Resolv USR currently does not have a separate protocol governance/utility token; its core asset is the USR stablecoin on Ethereum. Because Dune MCP is unavailable, all on-chain facts are: Not verifiable as of 2026-09-03. ## 1. Native token & contract

  • Native asset: USR (USD stablecoin issued by Resolv).
  • Chain: Ethereum.
  • Contract address: Not verifiable as of 2026-09-03.
  • There is no evidence of a distinct “RESOLV” or similar governance token in public listings or docs; all references focus on USR as the main tokenized product, not a protocol token. ## 2. Supply, market cap, FDV
  • Total / circulating supply of USR: Not verifiable as of 2026-09-03.
  • Market cap / FDV: USR is designed as a stablecoin fully backed by short‑term U.S. Treasuries and cash via SegMint, not a speculative governance token, so FDV is not a meaningful metric; exact circulating value is not verifiable as of 2026-09-03. ## 3. Token utility & governance
  • USR utility:
  • Tokenized exposure to short‑term U.S. Treasuries and cash held with qualified custodians (via SegMint).
  • Intended for use in DeFi as a yield‑bearing, dollar‑like asset that can be transferred and integrated into protocols.
  • Governance role: No public evidence of USR carrying protocol governance rights; governance appears off‑chain via corporate/legal structures and partners. Not verifiable as of 2026-09-03. ## 4. Revenue share, buybacks, burns, staking
  • No public documentation of:
  • Revenue sharing to USR holders.
  • Buyback or burn mechanics for a separate governance token.
  • Staking rewards or liquidity mining tied to a native token.
  • Yield is implied to come from underlying Treasuries/cash backing USR, not emissions. ## 5. Emissions & unlocks
  • No emissions schedule, unlock calendar, or vesting documentation for a governance token could be found.
  • Unlock checks: Not verifiable as of 2026-09-03. ## 6. Allocations & holder concentration
  • No evidence of token allocation tables (team/investors/treasury/community) for a native protocol token.
  • Top-holder concentration and insider wallets for USR: Not verifiable as of 2026-09-03. ## 7. Contract controls & liquidity
  • Mint/burn/blacklist/fee-switch functions: Not verifiable as of 2026-09-03.
  • DEX liquidity & listings for USR: Not verifiable as of 2026-09-03; USR does not appear among major CEX/DEX listings reviewed. From an institutional risk perspective, treat USR as a tokenized RWA product without a visible DeFi governance token, and assume traditional legal/custodial risk frameworks rather than tokenomics-driven ones until on-chain data and formal docs become available.
Evidence (2)

Stress scenarios

stress scenario - bitcoin price falls below $10000

two sources

For Resolv USR on Ethereum, a Bitcoin move below $10,000 is an extreme tail-risk macro shock, but the protocol-specific impact is not verifiable from the available sources. The provided search results only support that $10,000 BTC has been discussed as a worst-case scenario under severe liquidity stress, forced deleveraging, ETF outflows, and geopolitical shock; they do not provide audited or on-chain data for Resolv USR’s hedging, collateral, mint/burn mechanics, or loss absorbers. What can be said with confidence is that the stress transmission channels would likely be: lower BTC-denominated market confidence, wider crypto risk premia, potential collateral haircuts across DeFi, and higher redemption pressure if USR depends on crypto market stability.

However, the size of any loss, depeg risk, or insolvency risk for Resolv USR is not verifiable as of 2026-09-03 from the provided sources. If you need a protocol-level assessment, the missing items are: USR’s reserve composition, whether BTC exposure is direct or indirect, liquidation thresholds, and any backstop or insurance design. Not verifiable as of 2026-09-03.

Evidence (4)

stress scenario - largest collateral depegs 20%,

two sources

For a stress scenario where the largest collateral depegs 20%, the key loss channel is the markdown of reserve or backing assets; if the position is not overcollateralized enough, the protocol can become undersecured and forced sales may not fully restore the peg. A standard stress-testing principle is to revalue collateral under a shock and measure whether the loss exceeds available margin or liquidation capacity. For Resolv USR on Ethereum, the exact impact is Not verifiable as of 2026-09-03 from the provided sources because there is no protocol-specific, chain-specific collateral composition, haircut policy, or reserve disclosure in the search results.

Without that, I cannot compute the dollar loss, residual coverage, or whether a 20% depeg would trigger insolvency, recapitalization, or orderly liquidation. What can be said generally is:

  • A 20% collateral depeg is a severe shock and is large enough to overwhelm a position that is close to its minimum collateral requirement.
  • If the protocol’s collateral buffer is below 20% after haircuts and liquidation slippage, the system can become underwater and lose full backing.
  • Stress severity is typically assessed by both the size of the depeg and its duration; persistent discounting is more damaging than a brief price shock. If you want a protocol-specific estimate, I would need the current collateral breakdown and reserve rules for Resolv USR; absent that, the correct answer is Not verifiable as of 2026-09-03.
Evidence (4)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

For a top counterparty insolvency stress at Resolv USR, the expected loss path is: the protocol’s hedged portfolio suffers a shortfall when a major exchange, broker, or other trading counterparty cannot honor positions or withdrawals; that shortfall is intended to hit RLP first as the first-loss tranche, while USR is meant to remain whole until RLP is exhausted. Resolv describes RLP as the junior tranche that absorbs first-loss exposure from basis-trade losses and counterparty issues, and USR as the senior tranche with claim on reserves ahead of RLP. Who absorbs it: the initial economic loss is borne by RLP holders through a drop in RLP NAV; if losses exceed the RLP buffer, USR can become impaired or undercollateralized. In the extreme case where RLP goes to zero and losses continue, USR holders become exposed to residual losses and the protocol may halt minting/redemptions or wind down. Compensation: RLP holders are compensated for taking this first-loss and counterparty risk via higher yield/leveraged upside, while USR holders receive the lower-risk senior claim and stable yield.

If the stress escalates into a protocol failure, there is no contractually guaranteed external backstop described in the sources; recovery would come only from whatever collateral remains, with USR redemptions potentially processed at a discount. Impact path through the smart contracts: the counterparty loss reduces protocol NAV, which reduces RLP value first; if coverage falls far enough, protocol controls may pause minting/redemptions and/or freeze RLP redemptions to protect USR. The user-visible effect is a weaker RLP price first, then possible USR depeg or redemption haircut if the buffer is fully consumed. Important caveat: the publicly available sources describe the intended loss waterfall, but a fully audited, contract-by-contract insolvency propagation path is Not verifiable as of 2026-09-03 from the provided sources alone.

Evidence (3)

stress scenario - committed fraud by the DAO or owners

two sources

For the stress scenario of committed fraud by the DAO or owners, I found no verifiable evidence that Resolv USR’s DAO or owners committed fraud. The web results you provided are about The DAO hack in 2016, which was a smart-contract exploit and not proof of intentional fraud by the DAO/owners. What can be said with confidence is narrower: the incident was described by multiple sources as a reentrancy vulnerability exploited by an attacker to drain funds from The DAO, with the loss later addressed by a controversial Ethereum hard fork.

Those sources support a finding of exploit / code failure, not a finding of fraud by governance or ownership. For Resolv USR specifically, and for the question of whether the DAO or owners committed fraud, this is Not verifiable as of 2026-09-03 based on the provided results. If you want the risk assessment phrased for a report, the cleanest wording is: “No public evidence reviewed shows committed fraud by the DAO or owners; the relevant concern is smart-contract exploit risk, which is not the same as fraud.”

Evidence (3)

stress scenario - primary yield source negative 30d,

two sources

For Resolv USR, a negative 30d primary yield source means the protocol’s yield engine is in a stress state: if perp funding is persistently negative, the yield generated by the short-hedge leg turns into a cost, and that cost is intended to be absorbed by the RLP junior tranche before USR holders are affected. The protocol’s own materials say yield comes from two main sources—ETH staking and perpetual-futures funding rates—and that negative funding can make overall yield negative in principle, though it is considered unlikely in their modeled scenarios. The key risk implication is that a negative 30-day funding regime would likely compress or eliminate distributable yield to stUSR, while RLP NAV would be the first buffer to decline because RLP is designed to absorb protocol losses, including negative funding and hedging slippage.

Third-party analyses are consistent that USR itself is not the yield-bearing asset; users must stake into stUSR to access profit distributions, so the stress primarily transmits to the staking layer and then to the risk layer rather than to plain USR balances. Because Dune/on-chain verification is unavailable in this run, the actual 30d realized yield and any chain-level impact are Not verifiable as of 2026-09-03. The important governance/risk question under this scenario is whether ETH staking income is sufficient to offset negative funding over the 30-day window; if not, the protocol’s own documentation indicates losses are allocated to RLP first.

Evidence (6)

Governance & Legal

governance

one source

Assessment — Ethereum, as of September 13, 2026. Resolv USR remains company-led/hybrid governance, not a sovereign DAO. Resolv Labs Ltd controls the frontend/app and development process; Resolv Digital Assets Ltd is identified as the entity maintaining protocol assets/liabilities. Publicly associated executives are Ivan Kozlov, Tim Shekikhachev, and Fedor Chmilev; directors are Not verifiable as of September 13, 2026. Proposal process / DAO reality: proposals begin in the Resolv-controlled Discord forum and move to gasless Snapshot voting by stRESOLV holders.

Proposal creation initially remains restricted to the core team; community proposals are deferred to later phases. Governance scope initially covers rewards, collateral composition, fees, and risk parameters. Snapshot votes express the community’s position and are intended to guide Resolv Digital Assets Ltd only “to the extent permissible” under law and constitutional documents.

Therefore DAO governance is currently partly symbolic and does not demonstrably control upgrades, frontend deployment, or company-held funds. Contracts / funds: previously documented contract architecture reports a 3-of-5 Gnosis Safe controlling core admin roles, with a 72-hour OpenZeppelin timelock for proxy upgrades. Operational powers—including pausing, role grants, parameter changes, and reward allocation—can bypass the timelock. The Safe reportedly can mint USR through privileged infrastructure; a March 22, 2026 incident also demonstrated that a single privileged EOA could mint unbacked USR.

Accordingly, user-fund movement or dilution is not fully governance-gated. Concentration / signers: top RESOLV/stRESOLV holders, voting concentration, current Safe owners, signer independence, and current holder percentages: Not verifiable as of September 13, 2026 (Dune MCP unavailable; no on-chain substitute used). The prior report says all five Safe signers were unidentified EOAs, but this was not independently rechecked on-chain in this run. Contradiction / scope limitation: Resolv’s governance announcement calls governance “live,” while its legal terms state votes guide the company rather than bind it, and core-team proposal control remains. This supports a symbolic/consultative DAO classification. Structured fields: timelock=true; timelock_delay_hours=72; multisig_threshold=3; multisig_owners=5; admin_can_drain=true; emergency_bypass=true; dao_governance=false.

Timelock
Yes
Timelock delay hours
72
Multisig threshold
3
Multisig owners
5
Admin can drain
Yes
Emergency bypass
Yes
Dao governance
No
Evidence (4)

legal & regulatory

two sources

Entity/jurisdiction. The apparent legal structure is two BVI companies: Resolv Labs Ltd (frontend/site and user-facing services; BVI company no. 2127832) and Resolv Digital Assets Ltd (RDAL) (issuer, collateral pool, and mint/redemption authority). RDAL also filed a U.S.

Form D in December 2025 using a Road Town, Tortola, BVI address. ToS/restrictions. The Terms are governed by British Virgin Islands law, with exclusive BVI-court jurisdiction. They exclude U.S. persons except eligible accredited investors, and restrict residents/citizens of the BVI, Switzerland, Canada, specified sanctioned/prohibited jurisdictions, FATF high-risk jurisdictions, PEPs, and sanctioned persons.

The Terms disclaim legal-tender status, government backing, FDIC/SIPC protection, and reserve broad discretion to suspend, terminate, delay, or restrict service and redemptions. KYC/AML/sanctions. The Terms expressly require comprehensive user due diligence, ongoing transaction monitoring, enhanced due diligence, sanctions screening, suspicious-activity reporting, and cooperation with OFAC, the BVI Financial Investigation Agency, and other regulators. This is a contractual compliance undertaking; it does not independently establish that RDAL or Labs is a licensed financial institution or VASP.

Classification. Resolv’s disclosed position, reported by an independent Aave risk review, is that a confidential BVI legal memorandum concluded USR/RLP were not an “investment activity” under the BVI SIB Act and did not require BVI VASP, financing-business, or money-services licensing. Because the memorandum is not public, these are not independently verifiable legal conclusions. U.S. securities, commodities, money-transmission, stablecoin, tax, and consumer-protection exposure therefore remains jurisdiction- and fact-dependent.

Warnings/enforcement/cases/sanctions. No regulator enforcement action, court judgment, or sanctions designation against Resolv Labs or RDAL was identified in the sources checked. Not verifiable as of September 4, 2026. The March 22, 2026 exploit and reported pursuit of law-enforcement/legal recovery are material actual-risk indicators, but are not themselves regulatory enforcement. Data protection. Resolv Labs’ privacy policy identifies it as controller, states personal information is stored in the BVI, and permits disclosure for legal compliance and enforcement. GDPR/UK/US applicability and adequacy safeguards are not clearly established in the reviewed materials.

Legal structure vs. actual risk: formal BVI contracting and restrictions reduce perimeter risk, but concentrated issuer discretion, confidential opinions, offshore enforcement friction, and the 2026 incident create substantial residual legal, operational, and recovery risk.

Active enforcement
No
Sanctioned
No
Entity
Resolv Labs Ltd and Resolv Digital Assets Ltd (RDAL)
Jurisdiction
British Virgin Islands
Evidence (5)

legal registries

two sources

No exact GLEIF LEI record for 'Resolv Labs Ltd', 'Resolv Digital Assets Ltd', 'Resolv USR'. OFAC SDN screening of 'Resolv Labs Ltd', 'Resolv Digital Assets Ltd', 'Resolv USR': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Resolv Labs Ltd
  • Resolv Digital Assets Ltd
  • Resolv USR
Sanctioned
No
Evidence (4)

Stability

stability

two sources

Yes. Resolv issues its own stablecoin, USR, and the web evidence shows at least one documented depeg incident in March 2026 after an exploit minted unbacked USR. The last observed depeg date is 2026-03-22, and reported peak deviation varied by venue/measure; the most severe reported low was about $0.025, implying a roughly 97.5% depeg from the $1 peg.

Exact total depeg count is not verifiable as of 2026-09-05 beyond the documented incident.

Own stablecoin
Yes
Stable
No
Depeg count
1
Max depeg pct
97.5%
Last depeg date
2026-03-22
Stablecoin ids
  • USR
Evidence (4)

Risks & Strengths

risks

two sources

Resolv USR’s dominant risk is that a March 22, 2026 incident demonstrated a catastrophic failure in privileged minting controls: approximately 80 million unbacked USR was reportedly created, causing a severe depeg and ecosystem contagion. Recovery remains incomplete for some holder categories, while the protocol’s delta-neutral strategy also depends on centralized custodians, exchanges, oracles, and operational execution. On-chain balances, supply, and current peg are Not verifiable as of September 5, 2026 because Dune access was unavailable.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Privileged minting compromiseThe March 22, 2026 exploit reportedly enabled roughly 80M unbacked USR to be minted, extracted ETH, and triggered a major depeg. This directly invalidated the core collateralization premise.HighHighOperations were paused; illicit USR was reportedly burned or blacklisted, and recovery/redemption processes were introduced.High: the demonstrated control failure is existential until redesigned controls are independently validated and recovery is complete.
Incomplete recovery and compensationPre-incident allowlisted users have received priority redemptions, but non-allowlisted holders, post-incident holders, LPs, and RLP holders face unresolved legal, technical, and economic allocation decisions.HighHighStaged redemptions, holder snapshots, supply reduction, and external investigations are underway.High: final recovery scope, timing, and losses remain uncertain.
Centralized operational dependenciesMinting, redemption, hedging, and custody rely on allowlists, backend processes, institutional custodians, and exchange/DEX counterparties, creating key-person, censorship, and counterparty-failure exposure.HighHighDynamic collateral management, off-exchange custody, protection-layer reserves, and audits are stated controls.Medium-High: these controls do not eliminate concentration or execution risk.
Delta-neutral hedge failureUSR/RLP economics depend on ETH/BTC hedges, staking, funding rates, liquidity, and collateral management. Basis risk, liquidation, exchange outages, or hedge slippage can impair reserves.HighMediumDiversification across CEXs and DEXs plus a protection layer is intended to absorb losses.High: hedge performance and counterparty exposures remain market-dependent.
Smart-contract and upgrade riskAudits and bug bounty coverage did not prevent the minting incident; future contract, oracle, upgrade, blacklist, or redemption flaws could recreate insolvency or freeze user funds.HighMediumMultiple audits, a public bounty, timelocks on certain upgrades, and operational monitoring are reported.Medium-High: audit coverage reduces but does not remove implementation and governance risk.
Evidence (5)

strengths

two sources

Resolv USR’s main strengths are its delta-neutral design, native yield generation, crypto-native collateral base, transparent/auditable onchain structure, and capital efficiency. The protocol is designed to keep USR near $1 by hedging ETH/BTC exposure with perpetual futures, which reduces directional market risk while still allowing collateral to earn yield.

  • Delta-neutral stability model: USR is described as using long spot plus short futures hedging to neutralize price exposure, supporting a USD peg.
  • Native yield: Multiple sources say USR is built to generate onchain returns from funding rates and staking/yield on collateral, with stUSR offering additional upside.
  • Crypto-native collateral: USR is backed by ETH and BTC rather than fiat reserves, giving it a DeFi-native design and reducing reliance on banking rails.
  • Transparency and auditability: Resolv emphasizes public collateral visibility, proof-of-reserves dashboards, and auditable protocol operations, which can improve user trust.
  • Capital efficiency: Compared with overcollateralized stablecoins, Resolv is presented as requiring far less idle capital to mint or support USR, which is a core differentiator. A caveat: some claims in the search results come from the protocol or marketing-style explainers, so they should be treated as unverified marketing claims unless independently confirmed.
Evidence (10)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 26 two independent sources, 21 one source.
  • Oldest fact verification date: 2026-08-26.