Crypto news: Wu Shuo learned that Solv Protocol stated that on July 13, a security incident occurred involving the BTC+ contract on BNB Smart Chain. The attacker upgraded the BTC+ minting proxy contract and minted unauthorized tokens due to a leaked deployer private key. The team isolated the malicious contract within 3 hours and froze, destroyed, or isolated all unauthorized BTC+; the underlying BTC assets were not affected. BTC+ subscriptions and redemptions have been temporarily paused, and redemptions are expected to resume within two weeks. Solv Protocol has rotated the relevant access credentials and signing keys, and has launched an external security audit; it will subsequently release a detailed incident report.

SOLV-0.11%
BNB0.05%
BTC1.59%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 7
  • 1
  • Share
Comment
Add a comment
Add a comment
GreedIndexWatcher
· 14h ago
Losing your private key is really a headache—no matter how good the contract is, it can’t prevent human error. It looks like rotating credentials is necessary.
View OriginalReply0
LongShortBalance
· 19h ago
What I’m most worried about is whether the underlying BTC assets have been affected. Luckily, the announcement says they haven’t been touched, otherwise the entire DeFi space would have to shake three times.
View OriginalReply0
LightningSender
· 07-20 16:44
BTC + subscription and redemption suspended for two weeks; in the short term, liquidity may be affected a bit, but compared with a BTC price crash, this is already a fairly gentle handling.
View OriginalReply0
NeonUmbrella
· 07-20 16:27
Attackers use leaked private keys to upgrade proxy contracts and mint unauthorized tokens. This attack path is quite common, but Solv’s response speed and subsequent actions seem fairly reliable. Hopefully the recap report will be released with details.
View OriginalReply0
BreadthHunter
· 07-20 16:27
As a user, I only care about when I can redeem. The announcement says it’s expected to take two weeks—just hope they don’t miss the timeline, because leaving the funds sitting there doing nothing is pretty anxiety-inducing.
View OriginalReply0
VpvrUser
· 07-20 16:24
I hope the audit can find the root cause; otherwise, when redemptions are resumed in two weeks, everyone will be uneasy, because once trust has cracked, it’s hard to mend.
View OriginalReply0
MobilePay
· 07-20 16:19
This round of actions was still pretty fast—within three hours, the malicious contract was isolated, which is definitely a plus for the project team.
View OriginalReply0
  • Pinned