CASE STUDY: How our investigation discovered the ZondaCrypto liquidity issues, one of Europe's largest crypto scandals. [Read the case study]

Incident Reports // 23.03.2026 // 3 min read // recoveris-team

Weekly Incident Report: March 16–22, 2026

Over $26.7M drained across 3 incidents in March 16-22: a catastrophic infrastructure breach with unbacked stablecoin minting, a suspected state-sponsored hot wallet drain, and a gasless permit phishing attack.

This week’s Recoveris report covers a devastating infrastructure breach that allowed an attacker to mint tens of millions in unbacked stablecoins and extract roughly $25 million in real value, a hot wallet compromise and data breach at a major crypto payment platform attributed to a suspected North Korean APT group, and a gasless permit phishing attack that drained $1.77 million from a single high-net-worth wallet.


Resolv Protocol (Resolv Labs) – ~$25M | March 21-22 | Infrastructure Breach

A critical infrastructure breach at Resolv Protocol allowed an attacker to use a stolen private key to mint between 50 and 80 million USR stablecoins without backing. The flood of unbacked tokens crashed the USR peg and enabled the attacker to extract approximately $25 million in real value before the exploit was contained.

Private key compromises at the infrastructure level represent one of the most damaging attack classes in DeFi. Unlike smart contract logic exploits, they grant attackers direct minting or administrative privileges, bypassing all protocol-level safeguards. The window for intervention in these cases is extremely narrow: once unbacked tokens are swapped for legitimate assets and moved off-platform, recovery becomes exponentially more difficult.

Early tracing and coordinated exchange freeze requests are critical to intercepting extracted assets before they reach obfuscation services.

Sources: Telegram/X (@officer_cia), ForkLog, BitcoinWorld


Bitrefill – Undisclosed Loss | March 18 | Corporate Systems Breach

Attackers breached Bitrefill’s internal systems using stolen employee credentials, draining hot wallets of varied crypto assets and exfiltrating approximately 18,500 user purchase records. The attack is suspected to be the work of the Lazarus Group, a North Korean state-sponsored APT known for targeting crypto infrastructure.

This incident combines two distinct damage vectors: direct financial theft through hot wallet drainage and a significant data breach exposing customer transaction histories. The involvement of a state-sponsored threat actor signals operational sophistication, including pre-planned credential harvesting, internal lateral movement, and rapid asset extraction.

While recovery operations against state-sponsored actors face well-documented challenges, monitoring laundered fund flows for compliance chokepoints and off-ramp interception remains a viable strategy. Exchanges and service providers in the downstream path of stolen assets can be alerted to flag and freeze tainted funds as they surface.

Sources: Coinpedia, The Record


High-Net-Worth Phishing Victim (0x051bb…b664) – $1,770,000 | March 17 | Permit Phishing

A single wallet holder lost 1,770,000 USDC through a gasless permit phishing signature. Permit-based phishing exploits the EIP-2612 gasless approval mechanism, tricking users into signing off-chain messages that authorize token transfers without requiring an on-chain transaction. Because no gas is consumed and no visible transaction appears in the wallet’s history at the time of signing, victims often have no immediate indication that their funds have been compromised.

Phishing proceeds of this type are frequently routed directly to centralized exchanges for rapid liquidation. The speed of the attacker’s exit path makes immediate on-chain tracing and exchange freeze coordination essential. In cases where the victim is identified quickly, deploying an on-chain message to the compromised address can establish contact and initiate rapid response.

Sources: Telegram/Twitter (@officer_cia)


If your platform or users have been affected by recent exploits, immediate forensic intervention is critical to tracing and freezing assets before they reach obfuscation services.

Schedule a confidential consultation with Recoveris

Read more

Crypto Source of Funds report: evidence checklist
18.09.2026

Crypto Source of Funds report: evidence checklist

What should a crypto Source of Funds report include? An evidence checklist for bank reviews, exchange records, DeFi profits and complex asset histories.

Crypto Asset Recovery Has a Speed Problem: There Is Nobody You Can Call
16.09.2026

Crypto Asset Recovery Has a Speed Problem: There Is Nobody You Can Call

Crypto asset recovery moves at blockchain speed. Marcin Zarakowski and Patrick Prinz explain tracing, freezing and Europe’s intelligence gap.

Why I joined Recoveris
15.09.2026

Why I joined Recoveris

Aleksander Góra explains why he joined Recoveris to scale digital asset compliance, investigations and Source of Funds services for institutions.