The decentralized stablecoin protocol recently hit by a multi-million-dollar exploit has presented a formal recovery plan to address the fallout. According to Resupply’s latest announcement, the recovery plan will focus on stabilizing the protocol’s finances and supporting affected users. At…The decentralized stablecoin protocol recently hit by a multi-million-dollar exploit has presented a formal recovery plan to address the fallout. According to Resupply’s latest announcement, the recovery plan will focus on stabilizing the protocol’s finances and supporting affected users. At…

Resupply protocol outlines recovery plan post $10M exploit, proposes $6M token burn

3 min read

The decentralized stablecoin protocol recently hit by a multi-million-dollar exploit has presented a formal recovery plan to address the fallout.

According to Resupply’s latest announcement, the recovery plan will focus on stabilizing the protocol’s finances and supporting affected users.

At the core of the plan is a proposal to burn $6 million reUSD from the protocol’s insurance pool, which currently holds about $38.7 million. The exploit, which took place on June 25, 2025, resulted in losses reaching $10 million. Of this, the protocol emphasized that $2.87 million has already been repaid by the treasury and partners, leaving roughly $7.13 million.

The proposed six million burn would cover the majority of that debt, while the remaining $1.13 million would be carried by the DAO and gradually repaid using future revenue sources such as protocol fees or potential RSUP token sales.

All actions in the recovery plan are subject to governance vote. To speed up implementation, the team is proposing a shortened three-day voting period, rather than the usual seven.

If approved, the token burn will take place immediately, and insurance pool withdrawals, which were paused after the exploit, could resume within the original seven-day cooldown window.

How the Resupply exploit happened

According to the protocol’s post-mortem report, the attacker exploited a vulnerability in the crvUSD-wstUSR market. The exploit was made possible because the underlying CurveLend vault had no prior deposits, allowing the attacker to manipulate how the share value was calculated.

By donating a large amount of crvUSD to the vault and minting just 1 wei of shares, the attacker artificially inflated prices to make the collateral appear more valuable than the actual deposit.

While the oracle correctly reported the inflated value, a rounding issue in the contract’s exchange rate calculation caused the value to resolve to zero. This zero value broke the protocol’s solvency check, making every loan request appear safe. With the bypass, the attacker was able to borrow up to the pair’s full $10 million reUSD debt limit. 

Resupply stressed that the scheme was not a typical inflation attack, but a more targeted and sophisticated design aimed at nullifying the solvency logic.

“The exploit flow involved inflation of the CurveLend collateral shares, but differed from a classical ‘inflation attack’ as it was carefully designed to nullify a borrower solvency check,” Resupply stated.

The team added that the stolen funds remain on-chain and are actively being monitored. Furthermore, stronger security measures will be deployed going forward to permanently defend against similar exploits.

Market Opportunity
TokenFi Logo
TokenFi Price(TOKEN)
$0.003696
$0.003696$0.003696
-0.35%
USD
TokenFi (TOKEN) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Vitalik Buterin Challenges Ethereum’s Layer 2 Paradigm

Vitalik Buterin Challenges Ethereum’s Layer 2 Paradigm

Vitalik Buterin challenges the role of layer 2 solutions in Ethereum's ecosystem. Layer 2's slow progress and Ethereum’s L1 scaling impact future strategies.
Share
Coinstats2026/02/04 04:08
USAA Names Dan Griffiths Chief Information Officer to Drive Secure, Simplified Digital Member Experiences

USAA Names Dan Griffiths Chief Information Officer to Drive Secure, Simplified Digital Member Experiences

SAN ANTONIO–(BUSINESS WIRE)–USAA today announced the appointment of Dan Griffiths as Chief Information Officer, effective February 5, 2026. A proven financial‑services
Share
AI Journal2026/02/04 04:15
China drops Google antitrust case as U.S.-China talks focus on TikTok and Nvidia

China drops Google antitrust case as U.S.-China talks focus on TikTok and Nvidia

The post China drops Google antitrust case as U.S.-China talks focus on TikTok and Nvidia appeared on BitcoinEthereumNews.com. Beijing is shelving its antitrust case against Google, as the United States and China ramp up negotiations over TikTok and Nvidia during a tense period in relations. People briefed on the matter said China’s State Administration for Market Regulation chose to end the competition inquiry into Google, a status in Chinese called “zhongzhi”, the Financial Times reported on Thursday, The FT added that Google has not yet received formal paperwork confirming the closure of the case. After talks with Chinese counterparts in Madrid, U.S. Treasury Secretary Scott Bessent said a September 17 deadline that could have disrupted the popular social media app in the United States pushed negotiators toward a possible agreement. He noted the deadline could be extended by 90 days to finish the terms, without giving specifics. Bessent said that when commercial details are made public, the arrangement would keep cultural features of TikTok that Chinese negotiators want to protect. “They’re interested in Chinese characteristics of the app, which they think are soft power. We don’t care about Chinese characteristics. We care about national security,” Bessent told reporters at the close of two days of meetings. Trump hinted at possible Chinese stake in TikTok Asked whether China might hold a stake, former President Donald Trump said, “We haven’t decided that but it looks to me, and I’m speaking to President Xi on Friday, for confirmation of that.” A Trump has said the platform aided his re-election last year, and his personal account counts 15 million followers. The White House launched an official TikTok account last month. Any deal may still need approval from the Republican-led Congress. In 2024, Congress passed a law saying TikTok must be sold because of worries that China could access U.S. user data and use it for spying or influence. The Trump administration has…
Share
BitcoinEthereumNews2025/09/18 14:08