The attacker compromised Resolv's SERVICE_ROLE private key (a single unprotected EOA) and used it to call completeSwap() with a massively inflated mint amount, exploiting the fact that the contract never validated the output against the actual collateral deposited. Two calls turned ~$200k of USDC into ~80M USR, which was dumped for ~$25M before the protocol paused.
🔔 @observer • 💬 Join community • 🎁@qgiftingbot
