ResupplyFi Exploit Leads to $9.6M Loss in wstUSR Market Amid Price Manipulation Bug

Decentralized finance (DeFi) protocol Resupply confirmed a security breach in its wstUSR market, which led to about $9.6 million in crypto losses.
Blockchain security firm Cyvers said on Thursday that the exploit was triggered by a price manipulation attack involving the protocol’s integration with a synthetic stablecoin called cvcrvUSD.
Meir Dolev, Cyvers’ co-founder and chief technology officer, told Cointelegraph that the attacker exploited a price manipulation bug in the ResupplyPair contract. “By inflating the share price, they borrowed $10 million reUSD using minimal collateral,” Dolev said.
Cyvers said in the post that the attacker was funded through Tornado Cash, and the stolen funds were swapped to Ether (ETH) and split across two addresses.
Resupply pauses affected contracts in response to the attack
The incident highlights ongoing security concerns in DeFi protocols, particularly those involving synthetic assets and oracle-dependent mechanisms.
Dolev told Cointelegraph that several security measures might have prevented the attack, including proper input validation, oracle checks and edge-case testing.
When asked how protocols can avoid similar hacks, the security expert said that adding sanity checks in the lending logic and monitoring real-time anomalies could help.
In response to the exploit, Resupply issued a statement acknowledging the incident. The company confirmed that only its wstUSR market was affected. The DeFi protocol said the impacted contracts had already been paused to prevent further damage.
“A full post-mortem will be shared as soon as a complete analysis of the situation has been conducted,” the team wrote.
Related: Crypto ATM sting uncovers elderly widow who lost $282K in scam
Crypto hack losses reached $2.1 billion in 2025
The price manipulation exploit on Resupply comes as hack losses reached billions this year.
On June 4, crypto security firm CertiK said over $2.1 billion had already been stolen through hacks and exploits in 2025. CertiK also said hackers have started to shift tactics to social engineering.
Meanwhile, smart contract platform Fuzzland recently revealed that a former employee was responsible for a $2 million Bedrock UniBTC exploit in 2024.
The platform said the insider used social engineering tactics, supply chain attacks and advanced persistent threat techniques to steal sensitive data used in the exploit.
Magazine: New York’s PubKey Bitcoin bar will orange-pill Washington DC next
Bitcoin (BTC) $ 116,214.00
Ethereum (ETH) $ 3,717.17
XRP (XRP) $ 3.03
Tether (USDT) $ 0.999864
BNB (BNB) $ 790.95
Solana (SOL) $ 173.36
USDC (USDC) $ 0.999805
Lido Staked Ether (STETH) $ 3,711.05
Dogecoin (DOGE) $ 0.211187
TRON (TRX) $ 0.326012
Cardano (ADA) $ 0.742521
Wrapped Bitcoin (WBTC) $ 116,236.00
Wrapped stETH (WSTETH) $ 4,494.55
Hyperliquid (HYPE) $ 41.28
Sui (SUI) $ 3.66
Stellar (XLM) $ 0.404279
Wrapped Beacon ETH (WBETH) $ 3,989.46
Chainlink (LINK) $ 17.00
Bitcoin Cash (BCH) $ 569.41
Hedera (HBAR) $ 0.255658
Wrapped eETH (WEETH) $ 3,980.78
Avalanche (AVAX) $ 22.58
Toncoin (TON) $ 3.55
Ethena USDe (USDE) $ 1.00
WETH (WETH) $ 3,715.78
LEO Token (LEO) $ 8.96
Litecoin (LTC) $ 107.49
USDS (USDS) $ 0.999575
Shiba Inu (SHIB) $ 0.000013
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
Coinbase Wrapped BTC (CBBTC) $ 116,153.00
WhiteBIT Coin (WBT) $ 43.41
Uniswap (UNI) $ 9.41
Polkadot (DOT) $ 3.70
Monero (XMR) $ 305.31
Bitget Token (BGB) $ 4.44
Ethena Staked USDe (SUSDE) $ 1.18
Pepe (PEPE) $ 0.000011
Cronos (CRO) $ 0.140136
Aave (AAVE) $ 264.20
Dai (DAI) $ 0.999893
Ethena (ENA) $ 0.566074
Bittensor (TAO) $ 356.28
NEAR Protocol (NEAR) $ 2.56
Ethereum Classic (ETC) $ 20.86
Pi Network (PI) $ 0.408120
Ondo (ONDO) $ 0.932584
Aptos (APT) $ 4.37
Internet Computer (ICP) $ 5.28
OKB (OKB) $ 47.21
Jito Staked SOL (JITOSOL) $ 211.35
Mantle (MNT) $ 0.743578
BlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
Kaspa (KAS) $ 0.088967
Binance-Peg WETH (WETH) $ 3,716.68
Pudgy Penguins (PENGU) $ 0.034568
USD1 (USD1) $ 0.999068
Algorand (ALGO) $ 0.247985
Arbitrum (ARB) $ 0.402307
Bonk (BONK) $ 0.000027
Gate (GT) $ 17.09
VeChain (VET) $ 0.023234
Fasttoken (FTN) $ 4.59
Render (RENDER) $ 3.77
Cosmos Hub (ATOM) $ 4.24
POL (ex-MATIC) (POL) $ 0.206310
Worldcoin (WLD) $ 1.02
Binance Staked SOL (BNSOL) $ 184.64
Official Trump (TRUMP) $ 9.01
sUSDS (SUSDS) $ 1.06
Story (IP) $ 6.01
Sky (SKY) $ 0.082560
Rocket Pool ETH (RETH) $ 4,224.21
Artificial Superintelligence Alliance (FET) $ 0.669781
Sei (SEI) $ 0.295745
Quant (QNT) $ 117.03
Filecoin (FIL) $ 2.41
Kelp DAO Restaked ETH (RSETH) $ 3,895.90
Jupiter Perpetuals Liquidity Provider Token (JLP) $ 4.98
Flare (FLR) $ 0.023247
Lombard Staked BTC (LBTC) $ 116,129.00
XDC Network (XDC) $ 0.098559
SPX6900 (SPX) $ 1.68
Jupiter (JUP) $ 0.491884
KuCoin (KCS) $ 11.29
USDtb (USDTB) $ 0.999870
StakeWise Staked ETH (OSETH) $ 3,905.25
USDT0 (USDT0) $ 1.00
Liquid Staked ETH (LSETH) $ 4,011.99
Mantle Staked Ether (METH) $ 3,977.92
Injective (INJ) $ 13.42
Curve DAO (CRV) $ 0.954427
NEXO (NEXO) $ 1.31
First Digital USD (FDUSD) $ 0.997020
Stacks (STX) $ 0.717640
Celestia (TIA) $ 1.71
Renzo Restaked ETH (EZETH) $ 3,911.90
Polygon Bridged USDT (Polygon) (USDT) $ 0.999763
Optimism (OP) $ 0.674816
Falcon USD (USDF) $ 0.999479