The Solv Protocol exploit resulted in approximately $2.5M in losses after an attacker exploited a logic flaw in the BitcoinReserveOffering contract. The vulnerabilityThe Solv Protocol exploit resulted in approximately $2.5M in losses after an attacker exploited a logic flaw in the BitcoinReserveOffering contract. The vulnerability

Solv Protocol $2.5M Exploit: Double Mint Bug

2026/03/09 17:05
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

The Solv Protocol exploit resulted in approximately $2.5M in losses after an attacker exploited a logic flaw in the BitcoinReserveOffering contract. The vulnerability allowed the attacker to mint BRO tokens twice during a single mint flow, leading to massive token inflation.

The issue stemmed from an interaction between the NFT transfer process and the onERC721Received callback. By triggering token minting inside the callback and then receiving another mint when execution returned to the main mint() function, the attacker was able to create unbacked BRO tokens.

How the Exploit Happened?

The attacker began with 135 BRO tokens, which were burned through the reserve contract. In return, the protocol issued a small amount of GOEFS tokens based on the current exchange rate.

Using these tokens, the attacker initiated a mint transaction, sending GOEFS tokens along with a specific NFT. When the NFT was transferred, the contract triggered the onERC721Received callback, which internally executed the _mint function and issued BRO tokens to the attacker.

However, after the callback finished, the contract returned to the original mint() function and minted tokens again for the same action. This unintended behavior resulted in double minting.

Token Inflation in a Single Transaction

The attacker repeatedly triggered this mint flow 22 times within a single transaction. Because the entire exploit occurred in one transaction, the exchange rate remained constant, allowing the attacker to repeatedly double the minted tokens.

Through this process, the attacker inflated their holdings from 135 BRO tokens to approximately 567 million BRO tokens.

Converting the Exploit Into Profit

Once the tokens were minted, the attacker converted part of the inflated supply into real assets. Around 165M BRO tokens were swapped through the BRO–SolvBTC exchange, and then routed through Uniswap V3, eventually converting the assets into 1211 ETH.

The remaining tokens remained in the attacker’s wallet.

Following the swaps, the extracted ETH was transferred to multiple attacker-controlled wallets and eventually deposited into RailGun, a privacy protocol used to obscure transaction trails.

Root Cause

The exploit was caused by a logic flaw in the minting flow.

During NFT transfers, the contract triggered a callback (onERC721Received) that already executed a mint. When execution returned to the mint() function, the contract minted tokens again without validating whether minting had already occurred.

This lack of validation allowed the attacker to repeatedly mint tokens and inflate supply within a single transaction.

Why This Matters?

The Solv Protocol exploit highlights how small logic flaws in smart contract flows can lead to catastrophic token inflation. Improper handling of external calls, callbacks, and state updates can introduce subtle vulnerabilities that attackers can exploit at scale.


Solv Protocol $2.5M Exploit: Double Mint Bug was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

Market Opportunity
Solv Protocol Logo
Solv Protocol Price(SOLV)
$0.003795
$0.003795$0.003795
+1.60%
USD
Solv Protocol (SOLV) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Bitcoin Money Laundering Penalties Surge, Brokers Must Comply in Brazil

Bitcoin Money Laundering Penalties Surge, Brokers Must Comply in Brazil

The post Bitcoin Money Laundering Penalties Surge, Brokers Must Comply in Brazil appeared on BitcoinEthereumNews.com. Brazil increases penalties against Bitcoin laundering, requiring the cooperation of crypto brokers in the fight against digital crime by 2025. Brazil has made strong efforts in disabling money laundering using Bitcoin. Penalties are enhanced by the new law. Crypto brokers and tech firms also have to collaborate with it. In September 2025, the bill was presented by Deputy Domingos Neto. It amends the current legislation to combat digital crime more effectively.  This is indicative of the fast development of cryptocurrency-based crimes. The legislation aims at criminal gangs that use technological devices and cryptocurrencies to conceal criminal proceeds New Penalties Shake Digital Crime Organizations that engage in crimes through cyber means, such as Bitcoin laundering, are currently facing tougher penalties.  According to the law, a digital criminal organization refers to three or more individuals who commit crimes whose penalties last more than four years.  Criminals may get 4-8 years of incarceration and the punishments increase by a third or half in case more sophisticated equipment is used to avoid detection. Cryptocurrencies: Money laundering is expressly illegal. In case laundering is carried out through such digital groups, the penalty is raised by 33 to 66 percent.  These actions represent the realization of Brazil that cryptocurrency is a significant path to illegal money. Crypto Brokers Are Subjected to Tight Cooperation According to the new law, the cooperation of crypto brokers, internet providers, banks, and technology companies with the police and the judiciary is compulsory. They have to assist in suspect identification. The consequences of failure to help are fines, which will indicate the interest of the Brazilian in being transparent and accountable in crypto operations. The situation with cryptocurrency in Brazil is that it is not illegal but tightly regulated. The brokers are required to conduct know-your-customer (KYC) and anti-money laundering (AML).  Suspicious…
Share
BitcoinEthereumNews2025/09/21 17:08
Patos (PATOS) Price Alert: 108% Gains Guaranteed from Solana Token?

Patos (PATOS) Price Alert: 108% Gains Guaranteed from Solana Token?

Following the strategic addition of crypto icon Mark Zuckerfart as Lead Marketing Executive, presale activities spiked a staggering 500%. This […] The post Patos
Share
Coindoo2026/03/09 20:49
Safe-Haven Status Faces Unprecedented Pressure As DBS Flags Critical Shifts

Safe-Haven Status Faces Unprecedented Pressure As DBS Flags Critical Shifts

The post Safe-Haven Status Faces Unprecedented Pressure As DBS Flags Critical Shifts appeared on BitcoinEthereumNews.com. US Dollar: Safe-Haven Status Faces Unprecedented
Share
BitcoinEthereumNews2026/03/09 20:55