Solv Protocol Security Incident: BTC+ Contract Compromised via Private Key Leak

Solv Protocol has confirmed that its BTC+ contract on BNB Chain was targeted in a security attack on July 13. The investigation traced the breach to the compromise of a deployer's private key.

Attack Vector and Immediate Response

After obtaining the private key, the attacker upgraded the BTC+ minting proxy contract on BNB Chain, minting a significant number of unauthorized BTC+ tokens. The protocol's team activated emergency procedures within three hours of detection.

  • Rapid isolation of the malicious contract
  • Freezing, burning, or quarantining all unauthorized BTC+ tokens
  • Verification that all underlying custodial assets remained secure and untouched

These actions successfully contained further potential damage.

Service Impact and Recovery Timeline

As a precaution, subscription and redemption functions for BTC+ have been temporarily suspended. The team estimates that these services will be restored gradually within the next two weeks. User assets backing the tokens were not affected during the incident.

Security Enhancements and Next Steps

Following the breach, the project has strengthened deployer security protocols, rotating all potentially compromised access credentials and signing keys. A full external re-audit of the contract has been initiated. A detailed post-mortem report will be released to the community upon completion.

This event underscores the critical importance of private key management and upgrade authority controls in decentralized finance.