The team said an attacker used a compromised deployer private key to upgrade a mint proxy contract and create unauthorized BTC+ tokens, while underlying BTC assets remain safe.
Solv Protocol said it detected a security incident on July 13 involving the BTC+ contract on BNB Smart Chain. The attacker compromised the deployer private key, upgraded the BTC+ mint proxy contract, and minted unauthorized BTC+ tokens. The team said it responded within three hours, isolated the malicious contract, and froze, burned, or quarantined all unauthorized BTC+. It added that the underlying BTC assets remain safe. BTC+ subscriptions and redemptions have been paused for an expected two weeks while the protocol handles the aftermath of the breach. The incident highlights a common crypto security risk around private key management and upgradeable smart contracts (self-executing blockchain code), where control of admin credentials can allow unauthorized contract changes and token issuance.