Attack likely linked to smart contract bug that allowed unauthorized token minting
Bitcoin-focused DeFi platform Solv Protocol has confirmed that one of its token vaults was exploited, resulting in roughly $2.7 million in losses. The team is now offering the attacker a 10% bounty in exchange for returning the stolen funds.
In a post on X, Solv said the incident affected fewer than 10 users. The protocol also stated it will reimburse the lost 38.05 SolvBTC — a Bitcoin-pegged token used within its ecosystem — while the investigation continues.
Earlier coverage: Bitcoin slides as US-Israel strikes on Iran trigger $128B crypto sell-off
Solv Protocol allows users to deposit Bitcoin and receive SolvBTC in return. That token can then be used across DeFi applications for lending, borrowing, or staking on multiple blockchains. The project claims to manage more than 24,000 BTC in total reserves, worth over $1.7 billion.
Source: Solv Protocol
Security researchers point to minting vulnerability
While Solv has not yet released a full technical explanation, blockchain security researchers believe the attacker exploited a flaw in one of the protocol’s smart contracts.
According to CD Security co-founder Chris Dior, the attacker repeatedly triggered the vulnerability to mint large amounts of tokens. The exploit was reportedly executed 22 times before the attacker swapped the minted tokens for just over 38 SolvBTC.
Another researcher, known online as Pyro, suggested the exploit resembles a re-entrancy attack — a common vulnerability in DeFi systems where a smart contract can be repeatedly called before its internal state updates.
These types of attacks have appeared in multiple DeFi hacks over the past few years, often targeting complex contracts that manage liquidity or token minting.
Protocol moves quickly to limit damage
Solv says it has already introduced additional safeguards to prevent similar exploits. The team is currently working with security firms including Hypernative Labs, SlowMist and CertiK to analyze what went wrong.
The project also published an Ethereum wallet address and invited the attacker to return the funds in exchange for a 10% reward. Such “white-hat” bounty offers are a common strategy in crypto when projects try to recover stolen assets without escalating the situation further.
So far, the attacker has not responded or left any on-chain message, according to data from Etherscan.
