Solv.finance exploited for $2.7M via double-minting flaw in BitcoinReserveOffering contract's mint function.
Security & Exploits ·
Solv.finance suffered a $2.7M exploit through a double-minting vulnerability in the BitcoinReserveOffering contract's mint() function. The flaw allowed an attacker to mint BRO tokens twice for a single transaction: once via a callback triggered during ERC-3525 NFT transfer, and again within the mint() function itself.
The attacker exploited this by repeating a burn-and-mint cycle 22 times, converting an initial balance of 135 BRO into 567 million BRO tokens. The inflated BRO supply was then exchanged for 38 SolvBTC—worth approximately $2.73M at the time—through Solv's exchange contract, as documented on-chain.
The scope of the damage and whether additional funds remain at risk in other Solv contracts remain unclear. No remediation timeline or formal postmortem has been disclosed yet.