Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Resupply Faces Major Security Breach Resulting in Massive Financial Loss

Resupply Faces Major Security Breach Resulting in Massive Financial Loss

CointurkCointurk2025/06/26 09:56
By:Fatih Uçar

In Brief The Resupply protocol faced an attack causing a $9.5 million loss. Price manipulation exploited vulnerabilities in the collateral model. Measures are being taken to compensate users and prevent future attacks.

The Altcoin Resupply protocol suffered a devastating attack on June 26, resulting in a loss of approximately $9.5 million due to price manipulation. The attacker artificially inflated the share price of wrapped cvcrvUSD staked in Convex Finance through donations. This inflation affected Resupply’s CurveLend: crvUSD/wstUSR contract, causing a disruption in the collateral ratio calculations. Consequently, the attacker was able to borrow 10 million reUSD with minimal cvcrvUSD collateral, subsequently exchanging the reUSD for other assets in external markets. Resupply’s team has paused the affected contract.

Price Manipulation Exploited a Vulnerability

According to a report by PeckShield, the attacker raised the cvcrvUSD’s share price by donating to its vault. When the price per share increased, it skewed the protocol’s lending formula in the attacker’s favor, creating an opportunity for uncollateralized lending contracts.

Resupply Faces Major Security Breach Resulting in Massive Financial Loss image 0

A single wei of cvcrvUSD, generally deemed worthless, was treated as substantial collateral thanks to the artificial inflation. Analysts highlighted that such vulnerabilities could arise in collateral models relying on liquidity pools if price feeds are not verified with reliable sources.

The collapse of the contract was primarily due to its reliance on a single oracle for price determination. Despite Resupply’s intentions to expand liquidity through its “lend” module, its price control layer was insufficient. Security experts suggest that incorporating diverse oracles and implementing cap controls could prevent such attacks.

Ongoing Impact of the Attack

The withdrawal of 10 million reUSD coins from the protocol post-attack led to temporary fluctuations in the Resupply market. The project team announced suspending affected contracts and pledged to unveil a compensation plan for affected users soon. Though the cvcrvUSD price reverted to its original level post-donations, the imbalance in debt and collateral caused permanent loss in lending portfolios.

PeckShield reported that during the incident, the attacker swiftly traded reUSD across various decentralized exchanges, complicating the tracking process. Analysts noted that retrieving reUSD would be challenging due to its issuance from a limited pool, although blockchain freezing scenarios are being considered to mitigate the damage.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Mars Morning News | Federal Reserve Hawks Speak Out, Asset Price Crash Risk May Become New Obstacle to Rate Cuts

JPMorgan warns that if Strategy is removed from MSCI, it could trigger billions of dollars in outflows. The adjustment in the crypto market is mainly driven by retail investors selling ETFs. Federal Reserve officials remain cautious about rate cuts. The President of Argentina has been accused of being involved in a cryptocurrency scam. U.S. stocks and the cryptocurrency market have both declined simultaneously. Summary generated by Mars AI. This summary is produced by the Mars AI model and its accuracy and completeness are still being iteratively improved.

MarsBit2025/11/21 06:08
Mars Morning News | Federal Reserve Hawks Speak Out, Asset Price Crash Risk May Become New Obstacle to Rate Cuts

Pantera Partner: In the Era of Privacy Revival, These Technologies Are Changing the Game

A new reality is taking shape: privacy protection is the key to driving blockchain toward mainstream adoption, and the demand for privacy is accelerating at cultural, institutional, and technological levels.

深潮2025/11/21 04:36
Pantera Partner: In the Era of Privacy Revival, These Technologies Are Changing the Game