Risk transmission: Who was affected?

Author: KarenZ, Foresight News

On March 22, 2026, Resolv encountered a serious security incident. The attacker accessed Resolv's infrastructure without authorization using a leaked private key, minting 80 million uncollateralized USR stablecoins with just two transactions and 200,000 dollars.

The attacker's exit strategy was equally clean. The attacker split USR into USDC and USDT on multiple DEXs, then converted it into ETH, ultimately accumulating 11,408 ETH in the wallet, equivalent to about 24 million dollars.

The USR price once fell below 0.03 dollars and has now rebounded to around 0.3 dollars, with the peg still not restored.

This is one of the most representative DeFi security incidents of 2026 so far, and it has affected multiple protocols. Among them, the most controversial are Morpho and Fluid.

Risk Transmission: Who Got Hit?

USR, as collateral and trading pair, has been embedded in multiple DeFi protocols. The severe decoupling of USR triggered a chain reaction.

Morpho: The Failure of Oracles and Risk Management

Morpho's official stated immediately that the underlying contracts of the protocol had no vulnerabilities. However, 'no vulnerabilities' and 'no issues', 'no losses' are two different matters.

Morpho's official latest disclosure shows that among the 500 vaults with deposits exceeding 10,000 USD, about 15 vaults have significant exposure to the affected market.

Some arbitrageurs bought in at a discount after USR decoupled, and then pledged it into the protocol, while the internal oracle of the protocol still priced it at 1 USD. Arbitrageurs used this price difference to borrow real USDC, siphoning off the stablecoin liquidity from the vault.

Why did this happen? Aside from oracle issues, what truly caused the losses to spiral out of control was a function on Morpho called 'Public Allocator'.

The original intention of this feature's design was good: to monitor the utilization of various lending markets, and when a certain market's yield skyrocketed, to automatically allocate USDC from the vault to help curators capture higher yields. In a normal market, this is an elegant capital efficiency tool.

However, after the attack, the utilization of the USR market skyrocketed due to liquidations and arbitrage. Automated vaults from institutions like Gauntlet detected 'high yield signals'. They were unaware that it was a 'risky' market — thus, they began to inject capital continuously.

Omer Goldberg, founder of Chaos Labs, restored the timeline of this absurd drama: Gauntlet started automatic configuration 20 minutes after the attack began, lasting about 90 minutes; another curator, 9summits, even continued to provide funding for up to 10 hours after the attack, until it was manually discovered and stopped. Multiple curators, including Gauntlet, re7, kpk, and 9summits, automatically supplied funds to the Resolv market after the incident.

Omer Goldberg's statistics show that approximately 6.2 million USDC was used as 'exit liquidity' and 'fed' to borrowers of USR, of which 96% of the funds (about 6 million USD) came from the vault managed by Gauntlet.

Omer Goldberg also pointed out two fatal points: one is that Morpho's markets used hard-coded oracles, which could not timely reflect that assets had gone to zero or severely depreciated during extreme decoupling; the other is the negligence of risk management. The role of curators or risk managers should be to make manual judgments under stress testing, but the response to this incident was sluggish.

Fluid: The Most Hurt and Controversial

Among all affected protocols, Fluid is also one of the most discussed protocols in this incident.

Understanding this requires first grasping the structure of the Fluid protocol itself.

Fluid was launched by the Instadapp team in 2024. Instadapp has been operating as DeFi 'middleware' since 2018, and then the team realized that relying solely on existing protocol combinations had limited room for innovation, so they built their own — creating a protocol that thoroughly integrates lending and trading liquidity: Fluid.

Fluid's core design philosophy is: to integrate the liquidity of lending and trading, allowing the same asset to perform multiple functions simultaneously, achieved through two innovative mechanisms:

  • Smart Collateral: The collateral deposited serves simultaneously as market-making funds for the AMM liquidity pool, waiting for you to repay while helping others match trades and earn fees.

  • Smart Debt: The borrowed money is not idle; it is automatically injected into the AMM liquidity pool to act as liquidity, and the trading fees earned offset the borrowing interest — in extreme cases, it can even achieve 'negative interest borrowing'.

With this design, Fluid achieved an LTV (Loan-to-Value) of 95%, with liquidation penalties as low as 0.1%. This mechanism is advantageous in a normal market, but in the face of extreme decoupling, the margin for error is almost zero — any small fluctuation in collateral value can trigger a chain liquidation.

So, how did the Resolv attack affect Fluid?

The problem lies in Fluid's lending market. Fluid previously accepted wstUSR (Wrapped Staked USR) as collateral. When USR fell, the collateral value of these positions evaporated instantaneously.

Bad debt is an inevitable outcome. In the following Fluid borrowing page, multiple market states are displayed with wstUSR (the staked version of USR from Resolv) as collateral.

Omer Goldberg's statistics show that Fluid's potential bad debt exceeds 11,000,000 USD.

Source: Omer Goldberg

In response, Fluid stated that the team has secured a short-term loan to cover 100% of the current bad debt in the protocol. This portion of funding is jointly contributed by Konstantin Lomashuk from Cyber Fund (one of Fluid's investors), meow, co-founder of Jupiter, and the core team of Fluid. At the same time, several investors have expressed willingness to purchase FLUID tokens from the treasury to provide additional support if needed.

Samyak Jain, founder of Fluid, also publicly stated: 'In the next 2 to 4 weeks, we will focus on two things: enhancing Fluid's security and automating security mechanisms. We want the robots to react within 30 to 60 seconds, instead of waiting for the team to respond — which may take 30 to 60 minutes. Fluid will establish the most complex security infrastructure, allowing specific parts of the protocol to automatically enter a freeze state based on market conditions.'

So does the market buy it or not? DefiLlama data shows that Fluid's TVL has dropped from 1.25 billion USD before the USR attack to the current 870 million USD, a decrease of 380 million USD in one day, a drop of 30%.

In terms of price, Morpho fell 3.64% in 24 hours, while FLUID's 24-hour decline reached 15%.

What other affected protocols and participants are there?

RLP holders: RLP is the 'insurance pool' of the protocol, specifically for USR holders to provide support, but the returns will be higher. @yieldsandmore statistics: before the incident, the total circulation of RLP was 29,999,625, approximately 38.6 million USD, while its largest holder is Stream Finance, which lost 93 million USD due to asset misappropriation by partners in November 2025, holding about 13.6 million RLP on Morpho, with a net risk exposure of about 17 million USD. It is worth noting that Stream Finance's official Twitter has had no updates since November 2025.

Leverage yield strategy product yoUSD: also uses RLP as collateral, with an exposure to RLP of 2.75%, holding 943,248 RLP.

Inverse Finance: Quick Response. The official stated that the risk working group suspended the wstUSR-DOLA FiRM market within 15 minutes after USR was first attacked. The liquidators acted quickly, and the final bad debt was only 340,000 USD.

Summary

Zooming out, the Resolv incident has thrown an extremely sharp and unavoidable question at the entire DeFi industry: the security bottom line of protocols no longer solely relies on code audits.

Audits are preemptive, and monitoring is real-time; both are indispensable. Real protection also requires real-time, continuous monitoring during operation. Once any anomaly is detected (reserve mismatch, operator signature anomaly, etc.), a 'hard circuit breaker' must be triggered at the second or even millisecond level to block the spread of risk.

For any lending, derivatives, or liquidity protocols that accept external stablecoins as collateral, it is crucial to understand: you can control your smart contracts, but you can never control the minting logic, key management, and operational security of the stablecoin you rely on. This type of external risk is the most stubborn and hardest to eradicate structural shortcoming in the 'Lego-style' composable architecture of DeFi.

At the same time, while DeFi pursues extreme efficiency, it is essential to establish stronger risk isolation and external dependency firewalls. Otherwise, every 'Lego block' connection could become the starting point of a domino effect the next second.

Security is never a luxury; it is the lifeline for the long-term survival of DeFi.