BTCC / BTCC Square / StellarMiner /
Resolv and IoTeX Take Action to Compensate Users as DeFi Exploits Push 2026 Losses Beyond $137 Million

Resolv and IoTeX Take Action to Compensate Users as DeFi Exploits Push 2026 Losses Beyond $137 Million

Published:
2026-03-23 21:39:01
11
1


The DeFi space is reeling from a brutal first quarter in 2026, with Resolv Labs and IoTeX becoming the latest protocols to implement compensation plans following major security breaches. According to blockchain security firm Halborn, these incidents contribute to a staggering $137+ million in cumulative losses across 15 major DeFi exploits this year - already surpassing Q1 2025's $106.8 million total. What makes this wave particularly concerning? The emergence of AI-assisted attacks and the alarming speed at which exploits are accumulating.

How Did the Resolv and IoTeX Exploits Unfold?

Resolv Labs suffered one of 2026's largest DeFi attacks on March 22 when a compromised private key allowed an attacker to mint 80 million USR tokens. Within 48 hours, the protocol announced it WOULD restore pre-attack redemption values for holders, though a full forensic report remains pending. Meanwhile, IoTeX - whose cross-chain bridge was exploited back on February 21 - opened a claims portal offering 100% compensation to affected users. Security analysts note these incidents represent two of four major February breaches that are now entering their resolution phases.

Which Protocols Were Impacted by the Resolv Fallout?

The Resolv breach created collateral damage across DeFi platforms that accepted USR tokens, forcing them to disclose exposures. Morpho CEO Paul Frambot confirmed about 15 of their 500+ vaults had significant exposure to affected markets, though Core low-risk vaults remained untouched. Risk management firm Gauntlet is negotiating compensation plans with Resolv, while lending protocol Fluid secured short-term loans backed by personal commitments from Cyber Fund's Lom Lomashuk and team members to cover 100% of currently unrecoverable debts. "All other markets continue operating normally with protocol safeguards active," Fluid assured users on X (formerly Twitter).

Is AI Making DeFi Security More Challenging?

The $137 million lost to DeFi exploits in 2026's first quarter - tracked by CipherResearchx - reveals an accelerating threat landscape. February's $1.78 million Moonwell breach marked what observers call the first "AI-coded" DeFi exploit, with security auditor Pashov identifying commits co-written by Claude Opus 4.6. For context, Immunefi reported $1.64 billion and $336.3 million in total crypto losses during Q1 2025 and 2024 respectively. The 2026 DeFi-specific total already exceeds Q1 2025's figures, suggesting attackers are refining their methods at an alarming pace.

What's Next for DeFi Security in 2026?

With Resolv's $25+ million exploit and IoTeX's breach now in resolution phases, the DeFi community faces critical questions about scaling security measures against increasingly sophisticated attacks. Resolv has burned approximately 9 million of the attacker's tokens, while its $141 million guarantee fund limits direct financial damage. However, as Gauntlet and other risk managers work on compensation frameworks, the industry must confront whether traditional security audits can keep pace with AI-assisted exploits. One thing's certain - 2026 is shaping up to be a watershed year for DeFi security protocols.

FAQs About the 2026 DeFi Exploits

How much has been lost to DeFi exploits in 2026?

As of March 24, 2026, DeFi exploits have accumulated over $137 million in losses across 15 major incidents according to CipherResearchx data.

Which protocols were hit hardest in Q1 2026?

The largest individual exploits affected Step Finance ($27.3M), Truebit ($26.2M), Resolv ($25M+), and SwapNet ($13.4M).

Are users getting their funds back?

Both Resolv and IoTeX have announced 100% compensation plans, though Resolv's implementation is still underway as forensic analysis continues.

Was this the first AI-assisted DeFi exploit?

The February Moonwell breach appears to be the first confirmed case, with audit trails showing AI-generated code contributions.

|Square

Get the BTCC app to start your crypto journey

Get started today Scan to join our 100M+ users

All articles reposted on this platform are sourced from public networks and are intended solely for the purpose of disseminating industry information. They do not represent any official stance of BTCC. All intellectual property rights belong to their original authors. If you believe any content infringes upon your rights or is suspected of copyright violation, please contact us at [email protected]. We will address the matter promptly and in accordance with applicable laws.BTCC makes no explicit or implied warranties regarding the accuracy, timeliness, or completeness of the republished information and assumes no direct or indirect liability for any consequences arising from reliance on such content. All materials are provided for industry research reference only and shall not be construed as investment, legal, or business advice. BTCC bears no legal responsibility for any actions taken based on the content provided herein.