DeFi Hacked to Presidential Ransom: Is Bitcoin the Hacker's First Choice?

CN
8 hours ago

In July 2026, two screens, one on-chain and the other at the presidential palace. On one side, Solv Protocol disclosed on July 13 that its BTC+ product, deployed on the BNB Chain with BTC as the underlying asset, was attacked. The hacker did not "break Bitcoin" but first stole the deployer's private key, then used this "master key" to upgrade the minting proxy contract of BTC+, minting unauthorized BTC+ tokens in bulk. Fortunately, the underlying BTC assets were not directly transferred; on the other side, far away in Africa, the official website of President William Ruto of Kenya was hacked, the page was altered to a ransom announcement, with hackers demanding 5 bitcoins as ransom. The government claimed to have responded quickly, and the website returned to normal on July 21. Both incidents seemed to bear the "color" of Bitcoin: one was an issue with a DeFi protocol using BTC as an underlying asset, while the other was a political ransom demand explicitly asking for BTC. Thus, Bitcoin once again stood in the spotlight of security incidents, as if it had become the natural "scapegoat." However, when examining the timeline and technical details, it becomes clear that the common weak link was not the Bitcoin protocol itself, but rather the compromised off-chain entries like private keys and website access credentials; Bitcoin was merely chosen as the unit of account and settlement vehicle after the incident occurred.

Emergency response to Solv's private key theft within three hours

Focusing on the Solv incident itself, the timeline is quite clear: the BTC+ product running on the BNB Chain first had its deployer's private key stolen by hackers. The real issue was not the contract logic, but the key that controlled the contract's "power of life and death." After obtaining this key, the attacker did not target the underlying custodial BTC but chose to "change the lock on the door" on-chain—directly upgrading the minting proxy contract of BTC+ on BSC, turning the minting gateway, which should have been strictly controlled, into their own ATM. The subsequent attack path was also very straightforward: through this altered proxy contract, the hacker minted a large number of unauthorized BTC+ tokens, instantly diluting the certificates that originally represented real BTC positions into a pool mixed with "fake chips."

The real test of the team's response speed was the next three hours. In its official statement, Solv indicated that they completed emergency measures within about 3 hours of the incident: on one hand, they isolated the maliciously upgraded contract to cut off further illegal minting possibilities, and on the other hand, they froze or destroyed any suspicious assets that had been generated, minimizing the circulation radius of "fake BTC+." Meanwhile, Solv emphasized that all underlying BTC assets remained safe and had not been directly transferred, effectively signaling to users that the problem lay with the encapsulation layer, not the underpinning part of Bitcoin. The cost was that the subscription and redemption functions of BTC+ were immediately suspended, with officials expecting gradual restoration within about two weeks after the incident. For a Bitcoin yield product that builds trust through "redeemability," such a suspension would undoubtedly impact user confidence in the short term; however, under the premise of a compromised private key, controlling the situation first and discussing recovery later was almost the only viable choice.

Single point of private key compromise: An old problem in DeFi contracts resurfaces

Solv's explanation after the fact was that the "deployer's private key was stolen." The key point is not the two words "stolen," but rather how much power that deployer account held—it had the ability to upgrade the minting proxy contract of BTC+ on the BNB Chain. For the attacker, once they obtained this key, there was no need to breach the business logic of the contract itself; simply replacing the contract logic quietly would allow them to mint new derivative tokens without touching any underlying BTC, which was the premise for this unauthorized BTC+ minting to occur.

This hit upon a pain point that DeFi has been unable to avoid: the single point control risk brought about by upgradable contracts. The industry widely adopts a proxy + upgrade model to iterate products and patch vulnerabilities, but who holds the "upgrade" lever determines whether a protocol is "evolvable" or "can be taken over." The mature practice is to use multi-signature wallets to decentralize authority, implement time locks to provide a buffer for significant upgrades, or split minting, parameter adjustments, and emergency responses among different parties, attempting to avoid rewriting the system's fate with just one compromised private key. The Solv incident once again reminds the market that even if the underlying BTC assets are intact, as long as the governance layer’s authority control and private key management have issues, users' long-term trust in the entire protocol will be shaken.

President's official website hacked: demanding 5 bitcoins

If the DeFi protocol being attacked is a battle among insiders, then the hacking of the official website of Kenyan President William Ruto pushes Bitcoin onto a more mainstream stage. At an undisclosed and precisely unspecified time, this official window meant for releasing presidential schedules and policy information was altered into a ransom notice board: the hackers left blatant conditions on the homepage—pay 5 bitcoins, and the website will "return to normal"; otherwise, the presidential website will remain hijacked. Here, Bitcoin is no longer the underlying asset of a specific on-chain product but is directly used as a cross-border payment tool, creating a ransom channel almost completely disconnected from Kenya's local financial system.

The Kenyan government subsequently stated it had responded quickly to the attack, but did not disclose how the hackers breached the official website, which specific system permissions were affected, or whether the ransom demand was addressed. By July 21, 2026, the presidential website had resumed normal access, indicating that relevant departments had at least completed preliminary handling, but the identity of the hacker, the attack path, and whether those 5 bitcoins circulated remained blanks outside of the public narrative. What’s more troubling is that this is not an isolated case: in recent years, government and public institution websites in many countries have frequently encountered similar cryptocurrency ransoms, with hackers displaying wallet demands, officials hurriedly "closing for repairs," and technical details along with the destination of the funds disappearing collectively, forming a repetitive script that exposes structural shortcomings in public infrastructure regarding cybersecurity and emergency transparency.

From DeFi to government: a shared weak link in crypto credentials

When viewed on the same timeline, the attacks on Solv's BTC+ and the hacking of the Kenyan presidential website resemble two repetitions of the same type of incident in different scenarios: what was truly breached was the credentials that held the "power of life and death," not the underlying cryptographic algorithm itself. The incident with Solv's BTC+ contract on the BNB Chain had an entry point of the deployer's private key being stolen, allowing hackers to upgrade the minting proxy contract and gain minting rights that did not belong to them, thereby minting unauthorized BTC+ tokens; in the presidential website incident, the attack entry point was likely the website's backend account, server permissions, or related certificates, though officials did not disclose specific methods. The former's "key" controls the contract logic and asset mapping, while the latter's "key" controls the public interface through which the president, as the highest symbol, communicates externally. Essentially, both scenarios highlight that once the few identity credentials controlling critical systems are compromised, the entire trust structure collapses accordingly.

The role of Bitcoin in both incidents has also been misinterpreted. In the Solv incident, it was merely the underlying asset of BTC+; current information shows it was not directly stolen by hackers. In the Kenyan presidential website incident, it was the designated payment target specified in the ransom note. Hackers prefer to demand ransoms in Bitcoin more because of its global availability, cross-border settlement convenience, and difficulty in being forcibly frozen by a single entity, rather than indicating that the Bitcoin network or cryptographic algorithms are inherently more "dangerous." Currently, there is no evidence in publicly available data indicating security flaws in these areas. However, in public narratives, the situation is often simplified to "Bitcoin being involved in a security incident," with technical and operational details smoothed over, while real responsibilities—from the management of the deployer's private key in the DeFi protocol to the security of account and certificates on government websites—are slightly bypassed. This is precisely the key variable that will determine whether all similar systems can maintain security boundaries in the future.

Bitcoin is not the culprit; the real security battle lies off-chain

Contrasting the attack on Solv's BTC+ with the ransom of the Kenyan presidential website reveals that both incidents are truly vulnerable at the off-chain level: the underlying BTC assets of Solv are reported to be intact, but once the deployer’s private key is compromised, the governance layer is effectively "taken over" by hackers, triggering fluctuations in trust and business operations; the presidential website ransom was not about "breaking Bitcoin" but concluded when access was restored. Bitcoin was simply chosen as the valuation item for the 5 bitcoins in ransom, exposing the security shortcomings of public sector websites and information systems. For DeFi protocols, this means that the next security watershed will not rest on new gameplay but will focus on moving contract upgrades, authority management, and private key custody away from personal custody to multi-party cooperation, rule transparency, and auditability, aiming to minimize single points of failure. On one hand, Solv expects to restore subscription/redemption functions approximately two weeks after the attack, and the market will continue to question how it will reconstruct its governance and security architecture; on the other hand, while the Kenyan government emphasizes a "swift response" to the website attack and does not blame the Bitcoin network itself, whether Kenya and other countries will synchronously increase security investments at the policy and technical levels will determine whether, in future similar news, people first think of "which chain" or "which defense line had issues."

Join our community, let's discuss and become stronger together!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink