CASE STUDY: How our investigation discovered the ZondaCrypto liquidity issues, one of Europe's largest crypto scandals. [Read the case study]

Incident Reports // 30.03.2026 // 3 min read // recoveris-team

Weekly Incident Report: March 23–30, 2026

Over $24M drained across 3 incidents in March 23–30: unbacked stablecoin minting via key compromise, a supply chain credential theft, and a DeFi pool exploit. Weekly breakdown by Recoveris.

This week’s Recoveris report covers the continued fallout from Resolv Labs’ private key compromise resulting in $23–25M in unbacked USR token minting, a supply chain attack on API development platform Apifox injecting malicious JavaScript to steal credentials, and a $679K exploit of the Bitcorse (BCE) liquidity pool on PancakeSwap via a token burn mechanism.

Resolv Labs – ~$24M | March 22–29 | Infrastructure Breach

A compromised private key allowed an attacker to mint between 23 and 25 million dollars worth of unbacked USR stablecoins through the Resolv protocol. The minting event crashed the USR peg by approximately 70%, and the attacker extracted real value before the protocol team paused operations. On-chain activity related to the exploit continued through March 29 as the team and external investigators worked to trace fund movements.

Private key compromises remain the most destructive attack vector in DeFi. They bypass all smart contract safeguards and grant direct administrative control over minting, transfers, or governance functions. The damage ceiling is effectively unlimited, bounded only by the liquidity available on downstream markets at the time of exploitation.

The protocol team is active, the attacker’s on-chain trail is documented, and operations have been paused. These conditions create a viable window for forensic tracing and coordinated exchange-freeze engagement before extracted assets reach obfuscation layers.

Sources: CoinDesk, Telegram reports

Apifox Supply Chain Attack – Undisclosed | March 25 | Supply Chain

Attackers compromised the Apifox software supply chain by injecting malicious JavaScript into the platform’s distribution pipeline. The payload was designed to harvest user credentials and execute remote commands on affected machines, giving attackers persistent access to developer environments and potentially to downstream systems those developers interact with.

Supply chain attacks are particularly dangerous because they exploit trust relationships. Users running a legitimate tool have no reason to inspect its code on every update, and traditional endpoint security may not flag a trusted application’s outbound network behavior. When the compromised tool is used by developers who hold access to exchanges, protocols, or institutional wallets, the blast radius extends far beyond the initial target.

This type of breach represents a corporate security and incident response engagement rather than a direct asset recovery case, but the credential theft vector means affected organizations should audit all systems accessed by compromised developer machines and rotate all credentials immediately.

Sources: PANews

Bitcorse (BCE) Pool Exploit – $679,000 | March 23 | Smart Contract

An attacker exploited the BCE/USDT liquidity pool on PancakeSwap, draining approximately $679,000 through manipulation of the BCE token’s burn mechanism. The exploit leveraged the token’s deflationary logic to artificially inflate the token’s value within the pool before extracting USDT at the manipulated rate.

Deflationary token mechanics, particularly custom burn functions that execute on transfers, remain a recurring source of exploits in DeFi. The interaction between non-standard token behavior and AMM pool logic creates pricing inconsistencies that can be exploited in a single transaction. These attacks are typically executed via flash loans and leave minimal time for intervention.

Recovery potential in cases like this is limited. The attacker likely routed proceeds through decentralized exchanges and cross-chain bridges within minutes of execution, making centralized exchange freezes less effective. The primary value of tracking these incidents lies in pattern recognition and protocol-level preventive measures.

Sources: Phemex


If your platform or users have been affected by recent exploits, immediate forensic intervention is critical to tracing and freezing assets before they reach obfuscation services.

Schedule a confidential consultation with Recoveris

Read more

Crypto Source of Funds report: evidence checklist
18.09.2026

Crypto Source of Funds report: evidence checklist

What should a crypto Source of Funds report include? An evidence checklist for bank reviews, exchange records, DeFi profits and complex asset histories.

Crypto Asset Recovery Has a Speed Problem: There Is Nobody You Can Call
16.09.2026

Crypto Asset Recovery Has a Speed Problem: There Is Nobody You Can Call

Crypto asset recovery moves at blockchain speed. Marcin Zarakowski and Patrick Prinz explain tracing, freezing and Europe’s intelligence gap.

Why I joined Recoveris
15.09.2026

Why I joined Recoveris

Aleksander Góra explains why he joined Recoveris to scale digital asset compliance, investigations and Source of Funds services for institutions.