May 8, 2026
|

Giddy, BCE Token, and Resolv Exploits: $27M Lost to Signature Validation Gaps, Burn-Based Price Manipulation, and Compromised Signing Keys

A breakdown of three recent exploits across Ethereum and BSC that together resulted in $27M in losses. Giddy was drained for $1.3M through incomplete signature validation in its vault contract, where unsigned fields allowed an attacker to reuse a valid signature with modified swap parameters. BCE Token lost $679K when a burn flaw enabled an attacker to manipulate the PancakeSwap pool price using a flash loan from Venus. Resolv suffered a $25M loss after off-chain signing infrastructure was compromised, allowing unauthorized minting of 80M USR stablecoins without collateral deposits.

In Brief

  • Giddy lost $1.3M due to incomplete signature validation.
  • BCE Token lost $679K due to a burn flaw that allowed price manipulation.
  • Resolv lost $25M due to compromised signing keys enabling unauthorized minting.

Hacks Analysis

Giddy | Amount Lost: $1.3M

On April 23rd, the Giddy exploit on the Ethereum mainnet resulted in a $1.3M loss. The root cause of the exploit was an incomplete signature validation in giddyVaultV3’s struct VaultAuth. The protocol required a valid signature to approve swaps but the signature only covered part of the swap data. Critical fields such as fromToken, toToken, amount, and aggregator were not included in the signed message. This allowed the attacker to reuse a valid signature while changing the unsigned fields. The attacker modified token approvals, swap targets, and amounts, then redirected funds to their own address.

Exploited Contract: 0x5f0ad32c00641d1d2bb628ff341e0d4bb4494318

Transaction: 0x5edb66a4c2ea55bba95d36d27713e3bb1c67c3c4199a8a1759e754c6f25482e5

BCE Token | Amount Lost: $679K

On March 23rd, the BCE Token exploit on BSC resulted in a $679K loss. The root cause was a flaw in BCE’s token contract that allowed an attacker to burn tokens directly from the PancakeSwap liquidity pool, manipulating the token price. The attacker took a flash loan from Venus, bought and sold BCE to trigger a burn that removed nearly all BCE from the pool. Once the BCE token price was artificially increased, the attacker sold the remaining BCE tokens and made a profit.

Exploited Contract (on BSC): 0xcdb189d377ac1cf9d7b1d1a988f2025b99999999

Transaction: 0x85ac5d15f16d49ae08f90ab0e554ebfcb145712342c5b7704e305d602146d452

Resolv | Amount Lost: $25M

On March 22nd, the Resolv exploit on the Ethereum mainnet resulted in a $25M loss. The root cause was a compromise of off-chain signing infrastructure that resulted in authorized minting of $80M USR stablecoins. The attacker gained access to the signing key by compromising infrastructure credentials and modifying access policies. With signing authority, the attacker executed two transactions minting 80M USR tokens without depositing collateral.

Transaction: 0xfe37f25efd67d0a4da4afe48509b258df48757b97810b28ce4c649658dc33743

What’s a Rich Text element?

The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.

A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!

Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.

  1. Follow-up: Conduct a follow-up review to ensure that the remediation steps were effective and that the smart contract is now secure.
  2. Follow-up: Conduct a follow-up review to ensure that the remediation steps were effective and that the smart contract is now secure.

In Brief

  • Remitano suffered a $2.7M loss due to a private key compromise.
  • GAMBL’s recommendation system was exploited.
  • DAppSocial lost $530K due to a logic vulnerability.
  • Rocketswap’s private keys were inadvertently deployed on the server.

Hacks

Hacks Analysis

Huobi  |  Amount Lost: $8M

On September 24th, the Huobi Global exploit on the Ethereum Mainnet resulted in a $8 million loss due to the compromise of private keys. The attacker executed the attack in a single transaction by sending 4,999 ETH to a malicious contract. The attacker then created a second malicious contract and transferred 1,001 ETH to this new contract. Huobi has since confirmed that they have identified the attacker and has extended an offer of a 5% white hat bounty reward if the funds are returned to the exchange.

Exploit Contract: 0x2abc22eb9a09ebbe7b41737ccde147f586efeb6a

Ready to Shift Security Assurance In-House? Talk to Our Security Experts Today.