Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Resupply Faces Major Security Breach Resulting in Massive Financial Loss

Resupply Faces Major Security Breach Resulting in Massive Financial Loss

CointurkCointurk2025/06/26 09:56
By:Fatih Uçar

In Brief The Resupply protocol faced an attack causing a $9.5 million loss. Price manipulation exploited vulnerabilities in the collateral model. Measures are being taken to compensate users and prevent future attacks.

The Altcoin Resupply protocol suffered a devastating attack on June 26, resulting in a loss of approximately $9.5 million due to price manipulation. The attacker artificially inflated the share price of wrapped cvcrvUSD staked in Convex Finance through donations. This inflation affected Resupply’s CurveLend: crvUSD/wstUSR contract, causing a disruption in the collateral ratio calculations. Consequently, the attacker was able to borrow 10 million reUSD with minimal cvcrvUSD collateral, subsequently exchanging the reUSD for other assets in external markets. Resupply’s team has paused the affected contract.

Price Manipulation Exploited a Vulnerability

According to a report by PeckShield, the attacker raised the cvcrvUSD’s share price by donating to its vault. When the price per share increased, it skewed the protocol’s lending formula in the attacker’s favor, creating an opportunity for uncollateralized lending contracts.

Resupply Faces Major Security Breach Resulting in Massive Financial Loss image 0

A single wei of cvcrvUSD, generally deemed worthless, was treated as substantial collateral thanks to the artificial inflation. Analysts highlighted that such vulnerabilities could arise in collateral models relying on liquidity pools if price feeds are not verified with reliable sources.

The collapse of the contract was primarily due to its reliance on a single oracle for price determination. Despite Resupply’s intentions to expand liquidity through its “lend” module, its price control layer was insufficient. Security experts suggest that incorporating diverse oracles and implementing cap controls could prevent such attacks.

Ongoing Impact of the Attack

The withdrawal of 10 million reUSD coins from the protocol post-attack led to temporary fluctuations in the Resupply market. The project team announced suspending affected contracts and pledged to unveil a compensation plan for affected users soon. Though the cvcrvUSD price reverted to its original level post-donations, the imbalance in debt and collateral caused permanent loss in lending portfolios.

PeckShield reported that during the incident, the attacker swiftly traded reUSD across various decentralized exchanges, complicating the tracking process. Analysts noted that retrieving reUSD would be challenging due to its issuance from a limited pool, although blockchain freezing scenarios are being considered to mitigate the damage.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

2025 TGE Survival Ranking: Who Will Rise to the Top and Who Will Fall? Complete Grading of 30+ New Tokens, AVICI Dominates S+

The article analyzes the TGE performance of multiple blockchain projects, evaluating project performance using three dimensions: current price versus all-time high, time span, and liquidity-to-market cap ratio. Projects are then categorized into five grades: S, A, B, C, and D. Summary generated by Mars AI This summary was generated by the Mars AI model, and the accuracy and completeness of its content are still being iteratively updated.

MarsBit2025/11/28 16:26
2025 TGE Survival Ranking: Who Will Rise to the Top and Who Will Fall? Complete Grading of 30+ New Tokens, AVICI Dominates S+

Mars Finance | "Machi" increases long positions, profits exceed 10 million dollars, whale shorts 1,000 BTC

Russian households have invested 3.7 billion rubles in cryptocurrency derivatives, mainly dominated by a few large players. INTERPOL has listed cryptocurrency fraud as a global threat. Malicious Chrome extensions are stealing Solana funds. The UK has proposed new tax regulations for DeFi. Bitcoin surpasses $91,000. Summary generated by Mars AI. The accuracy and completeness of this summary are still being iteratively updated by the Mars AI model.

MarsBit2025/11/28 16:26
Mars Finance | "Machi" increases long positions, profits exceed 10 million dollars, whale shorts 1,000 BTC

How much is ETH really worth? Hashed provides 10 different valuation methods in one go

After taking a weighted average, the fair price of ETH exceeds $4,700.

ForesightNews 速递2025/11/28 15:05
How much is ETH really worth? Hashed provides 10 different valuation methods in one go

Dragonfly partner: Crypto has fallen into financial cynicism, and those valuing public blockchains with PE ratios have already lost

People tend to overestimate what can happen in two years, but underestimate what can happen in ten years.

深潮2025/11/28 14:53
Dragonfly partner: Crypto has fallen into financial cynicism, and those valuing public blockchains with PE ratios have already lost