Currencies33841
Market Cap$ 3.43T-0.34%
24h Spot Volume$ 49.94B-1.54%
DominanceBTC62.11%+0.24%ETH8.54%+0.95%
ETH Gas2.98 Gwei
Cryptorank

Stablecoin Protocol Resupply Exploited for $9.5M After Attacker Inflates Token Price


by Amin Ayan
for Cryptonews
Stablecoin Protocol Resupply Exploited for $9.5M After Attacker Inflates Token Price

Stablecoin platform Resupply suffered a major exploit worth $9.5 million after an attacker manipulated the price of a key collateral token, security firms reported.

Key Takeaways:

  • Resupply lost $9.5 million after an attacker manipulated the price of cvcrvUSD to borrow reUSD cheaply.
  • The exploit exploited faulty price logic in the CurveLend contract used by ResupplyPair.
  • Resupply paused the affected contract and is investigating the breach, with a full post-mortem pending.

The attack targeted cvcrvUSD, a wrapped version of Curve USD (crvUSD) staked on Convex Finance. By sending donations to the cvcrvUSD vault, the attacker inflated the token’s share price.

This inflated price was then used as collateral to borrow Resupply’s native stablecoin, reUSD, at a highly favorable exchange rate.

Resupply Exploit Linked to Manipulated Price Feed in CurveLend Contract

The Resupply smart contract involved, ResupplyPair (CurveLend: crvUSD/wstUSR), used the manipulated cvcrvUSD price in its calculations.

Once the attacker borrowed the reUSD, the manipulated exchange rate collapsed, triggering a major devaluation of the protocol’s reserves.

Analysts at Blocksec noted that the attacker primarily drained funds from the wstUSR market by exploiting the flawed price logic in the borrowing function.

The stolen reUSD was then swiftly converted into other crypto assets on external markets.

“As a result, the attacker borrowed massive reUSD with just 1 wei of cvcrvUSD as collateral, bypassing the insolvency check,” Blocksec wrote on X.

Resupply acknowledged the breach in a statement and confirmed that the compromised contract has been paused. The team is investigating the incident and has not yet confirmed any recovery plans.

“A full post-mortem will be shared as soon as a complete analysis of the situation has been conducted,” the team wrote.

Fuzzland Reveals $2M Insider Exploit on Bedrock’s UniBTC Protocol

On Wednesday, Fuzzland disclosed that a $2 million exploit targeting Bedrock’s UniBTC protocol in September 2024 was carried out by a former employee posing as an MEV developer.

The attacker used social engineering, inserted malware via a trojanized Rust crate, and maintained undetected access to engineering systems for over three weeks.

The breach culminated in the UniBTC protocol being exploited shortly after Fuzzland discussed a security vulnerability.

Notably, in the first three months of 2025, the crypto ecosystem lost a whopping $1,635,933,800 across 39 incidents, according to the blockchain security platform Immunefi.

Most of that was the result of only two hacks of two centralized exchanges. Phemex suffered a $69.1 million loss in January, while Bybit lost $1.46 billion in February.

Subsequently, the total number of losses in the first quarter marks a 4.7x increase compared to Q1 2024. At that time, hackers and fraudsters stole $348,251,217.

Notably, experts assume that the infamous North Korean Lazarus Group is behind the two largest attacks. They stole $1.52 billion, or 94% of total losses.

The post Stablecoin Protocol Resupply Exploited for $9.5M After Attacker Inflates Token Price appeared first on Cryptonews.

Read the article at Cryptonews

Read More

Citibank Accused of Ignoring Warnings in Alleged $20M Crypto Fraud Case

Citibank Accused of Ignoring Warnings in Alleged $20M Crypto Fraud Case

Citibank is facing a lawsuit from a man who claims the bank failed to flag suspicious...
ETH, XRP, SOL, TRX: GENIUS Act Lights a Fire Under Altcoins

ETH, XRP, SOL, TRX: GENIUS Act Lights a Fire Under Altcoins

In an important development, the Genius Act has officially passed the U.S. Senate and...

Stablecoin Protocol Resupply Exploited for $9.5M After Attacker Inflates Token Price


by Amin Ayan
for Cryptonews
Stablecoin Protocol Resupply Exploited for $9.5M After Attacker Inflates Token Price

Stablecoin platform Resupply suffered a major exploit worth $9.5 million after an attacker manipulated the price of a key collateral token, security firms reported.

Key Takeaways:

  • Resupply lost $9.5 million after an attacker manipulated the price of cvcrvUSD to borrow reUSD cheaply.
  • The exploit exploited faulty price logic in the CurveLend contract used by ResupplyPair.
  • Resupply paused the affected contract and is investigating the breach, with a full post-mortem pending.

The attack targeted cvcrvUSD, a wrapped version of Curve USD (crvUSD) staked on Convex Finance. By sending donations to the cvcrvUSD vault, the attacker inflated the token’s share price.

This inflated price was then used as collateral to borrow Resupply’s native stablecoin, reUSD, at a highly favorable exchange rate.

Resupply Exploit Linked to Manipulated Price Feed in CurveLend Contract

The Resupply smart contract involved, ResupplyPair (CurveLend: crvUSD/wstUSR), used the manipulated cvcrvUSD price in its calculations.

Once the attacker borrowed the reUSD, the manipulated exchange rate collapsed, triggering a major devaluation of the protocol’s reserves.

Analysts at Blocksec noted that the attacker primarily drained funds from the wstUSR market by exploiting the flawed price logic in the borrowing function.

The stolen reUSD was then swiftly converted into other crypto assets on external markets.

“As a result, the attacker borrowed massive reUSD with just 1 wei of cvcrvUSD as collateral, bypassing the insolvency check,” Blocksec wrote on X.

Resupply acknowledged the breach in a statement and confirmed that the compromised contract has been paused. The team is investigating the incident and has not yet confirmed any recovery plans.

“A full post-mortem will be shared as soon as a complete analysis of the situation has been conducted,” the team wrote.

Fuzzland Reveals $2M Insider Exploit on Bedrock’s UniBTC Protocol

On Wednesday, Fuzzland disclosed that a $2 million exploit targeting Bedrock’s UniBTC protocol in September 2024 was carried out by a former employee posing as an MEV developer.

The attacker used social engineering, inserted malware via a trojanized Rust crate, and maintained undetected access to engineering systems for over three weeks.

The breach culminated in the UniBTC protocol being exploited shortly after Fuzzland discussed a security vulnerability.

Notably, in the first three months of 2025, the crypto ecosystem lost a whopping $1,635,933,800 across 39 incidents, according to the blockchain security platform Immunefi.

Most of that was the result of only two hacks of two centralized exchanges. Phemex suffered a $69.1 million loss in January, while Bybit lost $1.46 billion in February.

Subsequently, the total number of losses in the first quarter marks a 4.7x increase compared to Q1 2024. At that time, hackers and fraudsters stole $348,251,217.

Notably, experts assume that the infamous North Korean Lazarus Group is behind the two largest attacks. They stole $1.52 billion, or 94% of total losses.

The post Stablecoin Protocol Resupply Exploited for $9.5M After Attacker Inflates Token Price appeared first on Cryptonews.

Read the article at Cryptonews

Read More

Citibank Accused of Ignoring Warnings in Alleged $20M Crypto Fraud Case

Citibank Accused of Ignoring Warnings in Alleged $20M Crypto Fraud Case

Citibank is facing a lawsuit from a man who claims the bank failed to flag suspicious...
ETH, XRP, SOL, TRX: GENIUS Act Lights a Fire Under Altcoins

ETH, XRP, SOL, TRX: GENIUS Act Lights a Fire Under Altcoins

In an important development, the Genius Act has officially passed the U.S. Senate and...