This week’s Recoveris report covers the continued fallout from Resolv Labs’ private key compromise resulting in $23–25M in unbacked USR token minting, a supply chain attack on API development platform Apifox injecting malicious JavaScript to steal credentials, and a $679K exploit of the Bitcorse (BCE) liquidity pool on PancakeSwap via a token burn mechanism.
Resolv Labs – ~$24M | March 22–29 | Infrastructure Breach
A compromised private key allowed an attacker to mint between 23 and 25 million dollars worth of unbacked USR stablecoins through the Resolv protocol. The minting event crashed the USR peg by approximately 70%, and the attacker extracted real value before the protocol team paused operations. On-chain activity related to the exploit continued through March 29 as the team and external investigators worked to trace fund movements.
Private key compromises remain the most destructive attack vector in DeFi. They bypass all smart contract safeguards and grant direct administrative control over minting, transfers, or governance functions. The damage ceiling is effectively unlimited, bounded only by the liquidity available on downstream markets at the time of exploitation.
The protocol team is active, the attacker’s on-chain trail is documented, and operations have been paused. These conditions create a viable window for forensic tracing and coordinated exchange-freeze engagement before extracted assets reach obfuscation layers.
Sources: CoinDesk, Telegram reports
Apifox Supply Chain Attack – Undisclosed | March 25 | Supply Chain
Attackers compromised the Apifox software supply chain by injecting malicious JavaScript into the platform’s distribution pipeline. The payload was designed to harvest user credentials and execute remote commands on affected machines, giving attackers persistent access to developer environments and potentially to downstream systems those developers interact with.
Supply chain attacks are particularly dangerous because they exploit trust relationships. Users running a legitimate tool have no reason to inspect its code on every update, and traditional endpoint security may not flag a trusted application’s outbound network behavior. When the compromised tool is used by developers who hold access to exchanges, protocols, or institutional wallets, the blast radius extends far beyond the initial target.
This type of breach represents a corporate security and incident response engagement rather than a direct asset recovery case, but the credential theft vector means affected organizations should audit all systems accessed by compromised developer machines and rotate all credentials immediately.
Sources: PANews
Bitcorse (BCE) Pool Exploit – $679,000 | March 23 | Smart Contract
An attacker exploited the BCE/USDT liquidity pool on PancakeSwap, draining approximately $679,000 through manipulation of the BCE token’s burn mechanism. The exploit leveraged the token’s deflationary logic to artificially inflate the token’s value within the pool before extracting USDT at the manipulated rate.
Deflationary token mechanics, particularly custom burn functions that execute on transfers, remain a recurring source of exploits in DeFi. The interaction between non-standard token behavior and AMM pool logic creates pricing inconsistencies that can be exploited in a single transaction. These attacks are typically executed via flash loans and leave minimal time for intervention.
Recovery potential in cases like this is limited. The attacker likely routed proceeds through decentralized exchanges and cross-chain bridges within minutes of execution, making centralized exchange freezes less effective. The primary value of tracking these incidents lies in pattern recognition and protocol-level preventive measures.
Sources: Phemex
If your platform or users have been affected by recent exploits, immediate forensic intervention is critical to tracing and freezing assets before they reach obfuscation services.