Tools Crypto Exploit Tracker exploit-0063
Exploit record
Solv Protocol
- Loss
- $3M
- Attack vector
- Other
- Chain
- Ethereum
- Sector
- Vault
What happened
On March 5, 2026, Solv's BRO vault was exploited through a double-mint flaw that let the attacker turn a tiny BRO position into a cartoonishly large one and swap it for real SolvBTC.
The vulnerable BRO contract effectively paid twice in the same mint path. When the ERC-3525 NFT transfer callback fired, tokens were minted once, and then the outer mint routine minted them again. The attacker just looped burn/mint repeatedly until 135 BRO had been inflated into hundreds of millions. Once the fake balance existed, it was exchanged for real SolvBTC. Solv said the impact was confined to the affected vault and committed to covering losses.
On-chain references
- Vulnerable Contract
0x014e6F6ba7a9f4C9a51a0Aa3189B5c0a21006869 - Exploit txetherscan.io/tx/0x44e637c7d85190d376a52d89ca75f2d208089bb02b…
- Exploiter
0x08259F9D1De695329b5a0FDF4703F72c7C2326A9
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026
