Solv Protocol has confirmed a smart contract exploit that drained about $2.7 million from one vault tied to SolvBTC. The attacker took 38.05 SolvBTC, and the platform said fewer than 10 users were affected. Solv added that those users will be fully reimbursed.
The breached vault was linked to SolvBTC, a Bitcoin-pegged token used across several decentralized finance services. Solv said its other vaults and user funds were not affected by the incident. The team also offered the attacker a 10% white-hat bounty if the funds are returned quickly.
Researchers say the flaw was used 22 times
After the attack was detected, Hypernative, SlowMist, and CertiK joined the investigation. Chris Dior, co-founder of CD Security, said the attacker repeatedly abused a smart contract flaw, triggering it 22 times. That allowed the attacker to mint excess tokens inside the protocol and then swap hundreds of millions of those tokens for slightly more than 38 SolvBTC.
Researcher Pyro described the exploit as a re-entrancy attack, a method that interferes with contract logic through repeated calls before a transaction is completed. Solv has not published a full technical breakdown of the vulnerability. The team did share an Ethereum wallet address and asked the attacker to negotiate through on-chain communication, but Etherscan data showed no response at the time of reporting.
Protocol says remaining vaults are safe
Solv told users that their funds are safe and said it is working to strengthen the protocol after the breach. It also disclosed that the platform currently holds more than 24,226 BTC, worth over $1.7 billion. That broader pool, according to the project, was not impacted by the exploit.
Fresh incident joins recent DeFi attack streak
The breach adds to a series of recent DeFi security failures. Earlier this week, markets tied to Curve Finance were hit by a separate issue in sDOLA LlamaLend pools after attackers manipulated the oracle pricing system and reportedly captured about $240,000 with flash loans. In early February, cross-chain liquidity protocol CrossCurve lost nearly $3 million after attackers used spoofed cross-chain messages to bypass gateway validation and unlock funds from the PortalV2 contract.

