Refreshed 4h ago· updates every 6h

Resolv Protocol (2026) — Crypto Hack

Funds Laundered
Mar 22, 2026·
Ethereum
Amount Stolen
$13.0M
~$13M in ETH and USDC
Recovered
$0

Reentrancy vulnerability in vault withdrawal function drained $13M

Summary

Reentrancy vulnerability in vault withdrawal function drained $13M

How It Was Compromised — Smart Contract Exploit via Reentrancy attack on Resolv's delta-neutral vault contracts. Attacker exploited a callback vulnerability in the withdrawal function, allowing repeated reentrant calls before balance updates.

Smart Contract ExploitReentrancy attack on Resolv's delta-neutral vault contracts. Attacker exploited a callback vulnerability in the withdrawal function, allowing repeated reentrant calls before balance updates.

Resolv Protocol suffered a $13 million exploit due to a reentrancy vulnerability in its delta-neutral vault contracts. The attacker deposited funds into the vault, then initiated a withdrawal that triggered a callback to a malicious contract. Before the vault could update the attacker's balance, the malicious contract re-entered the withdrawal function repeatedly, extracting far more than their original deposit. The attack was executed across multiple transactions to avoid gas limits, draining approximately $13 million in ETH and USDC.

Fund Flow & Laundering Analysis

Stolen ETH and USDC were swapped for ETH and then bridged to Bitcoin via THORChain. The attacker used cross-chain swaps to fragment the trail, converting portions to XMR through decentralized exchanges. A significant amount was deposited into Tornado Cash within hours of the exploit. The speed and sophistication of the laundering suggested an experienced attacker with established infrastructure.

Related Incidents

For educational and transparency purposes only. Not financial advice. Data compiled from public sources and may contain approximations.