Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Attacker drains over $9 million from Resupply stablecoin protocol after manipulating token price

Attacker drains over $9 million from Resupply stablecoin protocol after manipulating token price

The BlockThe Block2025/06/25 16:00
By:By Danny Park and Vishal Chawla

Quick Take Resupply, a stablecoin protocol tied to lending market liquidity, was exploited for around $9.5 million. Resupply acknowledged the incident and said the compromised contract has been identified and paused.

Attacker drains over $9 million from Resupply stablecoin protocol after manipulating token price image 0

Stablecoin protocol Resupply was exploited for around $9.5 million through a market manipulation of exchange rates, according to security analysts.

Resupply is a stablecoin protocol that leverages the liquidity and stability of lending markets.

The exploit centered on cvcrvUSD, a wrapped version of Curve USD (crvUSD) staked in Convex Finance. Analysts said the attacker artificially inflated the price of cvcrvUSD by sending donations, which caused its share price to spike.

“The hacker exploited the cvcrvUSD vault, allowing the attacker to borrow $10 million in reUSD with only 1 wei of share as collateral,” said Xuxian Jiang, founder and CEO of PeckShield.

Resupply’s smart contract, known as ResupplyPair (CurveLend: crvUSD/wstUSR), used this inflated cvcrvUSD price in its exchange rate calculations. As a result, the rate crashed, noted security analysts.

The attacker took advantage of this price distortion by invoking the borrow function in the ResupplyPair contract. This allowed them to borrow 10 million reUSD (Resupply's native stablecoin) using only one wei of cvcrvUSD as collateral.

The missing funds originated from the wstUSR market, which the attacker exploited through borrowing, explained analysts at Blocksec.

Analysts added that the attacker later converted the borrowed reUSD into other assets on external markets for profit.

Resupply confirmed the exploit and said the affected contract has been identified and paused.


0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

PhotonPay wins Adam Smith Award for its innovative foreign exchange solution, reshaping the global forex management landscape

In the future, PhotonPay will continue to increase investment in both technology and compliance, aiming to build a more efficient, secure, and scalable payment and fund management network for global enterprises.

深潮2025/11/18 10:14
PhotonPay wins Adam Smith Award for its innovative foreign exchange solution, reshaping the global forex management landscape

When BTC treasury companies fall into a selling cycle, low-quality companies may become the ultimate winners

Bitcoin treasury companies that firmly hold their coins may ultimately emerge as the winners.

深潮2025/11/18 10:14

Taiko technology stack has been officially adopted by ENS, enabling Namechain to build a ZK Rollup scaling solution on Ethereum mainnet.

Namechain will leverage Taiko's pre-confirmation technology—which will be launched first on the mainnet—to reduce state update times from "hours" to "seconds," addressing the key performance bottleneck that ENS has faced for years with CCIP-Read.

深潮2025/11/18 10:13
Taiko technology stack has been officially adopted by ENS, enabling Namechain to build a ZK Rollup scaling solution on Ethereum mainnet.