Key Highlights

  • An attacker exploited a flaw in a Bitcoin Reserve Offering (BRO) vault, stealing 38.0474 SolvBTC (about $2.7M), Solv said

  • Fewer than 10 users were affected, and Solv will fully compensate for losses. Other vaults were not impacted. 

  • The protocol offered a 10% “white hat” bounty to the attacker to return funds and shared a return address publicly.

Solv Protocol, a Bitcoin-focused DeFi platform, disclosed a “limited exploit” affecting a single BRO vault, resulting in the theft of 38.0474 SolvBTC, valued at roughly $2.7 million at the time of disclosure. The team said fewer than 10 users were impacted and that it will cover the losses.

Attack Mechanics

Independent security monitoring accounts reported the attacker repeatedly looped contract actions to inflate BRO balances and then swapped the inflated amount out for SolvBTC, with on-chain summaries pointing to 22 repetitions and an inflation from roughly 135 BRO to 567 million BRO-equivalent units before extraction.

Separately, the researcher's commentary shared in coverage described the incident as a reentrancy-style accounting exploit.

Protocol Response

Solv said the exploit was limited to one BRO vault, that all other vaults and user funds remain secure, and that it is working with external security partners while remediation is underway. The team also offered the attacker a 10% bounty to return the funds and provided a designated address for repayment.