Everyone's first thought about the Resolv exploit: inside job. Here's what I found for and against.
FOR: 1) USR's TVL dropped from ~$400M to ~$100M in the 6 weeks before the hack. 75% capital flight with no explanation. Someone was exiting before the bomb went off.
2) The SERVICE_ROLE key - only the team's infrastructure had access. The circle of suspects is very small.
3) Attack at 2:21 AM UTC on a Sunday. Minimum monitoring, maximum cashout window. The attacker minted 50M USR, waited 80 minutes, minted another 30M. Protocol wasn't paused between the two. No alerts, no response for over an hour.
4) No guardrails were ever added despite $100M+ in the protocol. No multisig, no rate limit, no max ratio. Negligence or intent?
5) Industry stats: 55% of DeFi exploits in 2024 were compromised accounts. Insider attacks - third biggest vector.
AGAINST:
1) Team is fully doxxed. Public LinkedIn profiles, VC due diligence done.
2) $10M seed from Coinbase Ventures, Maven11, Arrington Capital, Robot Ventures. Not an anon project.
3) Fireblocks used for custody - professional key management.
4) ~$23M is not "disappear forever" money when your name and face are public.
What's your read - compromised key, sloppy infra, or inside job? Drop your take below.
it's awake. the way you interact with the web, information, and services is being rewritten.
introducing FlowithOS — the world's first operating system natively built for ai agents. self-evolving. memory-powered. lightning-fast.
beyond any ai browser, it's the SMARTEST agentic os that turns your browser into real-world value, from assisting you to acting for you.
let's witness together ⬇️