Dominion is shutting down its Solana-based tokenized silver project less than a month after a security breach compromised its treasury infrastructure, collapsed SILV liquidity and left the company without enough capital to rebuild the market.
The project said most of its remaining liquid resources will instead be directed toward refunds. Eligible investors who held SILV before the September 11 attack will be able to exit at $63 per token, according to Dominion’s shutdown announcement.
SILV was designed as a tokenized representation of physical silver, with each token backed one-to-one by one troy ounce of allocated silver held in US vault custody. Dominion marketed the structure as a way to combine physical precious-metal backing with 24-hour Solana trading, DeFi liquidity and cash redemption.
The security incident broke that model at its most vulnerable point: not the physical silver itself, but the digital infrastructure governing the tokens representing it.
On September 11, an attacker gained control of three of the five keys required to authorize transactions from Dominion’s multisignature treasury. The attacker ultimately sold approximately 46,909 SILV into decentralized exchange pools that did not have enough liquidity to absorb the supply.
Those tokens had a nominal value of roughly $3 million before the attack. Yet the attacker realized only about $238,000 as repeated selling drove SILV dramatically below the value of the silver it was supposed to represent.
A $238,000 Attack Destroyed a Much Larger Market
The gap between the value of the compromised tokens and what the attacker actually extracted is one of the most revealing parts of the incident.
SILV had traded around $63 before the exploit. According to an on-chain reconstruction by Bitquery, the attacker controlled enough keys to satisfy Dominion’s 3-of-5 treasury multisig, emptied treasury positions and pulled additional SILV from loans before selling the tokens into thin Solana liquidity.
Approximately half of SILV’s existing supply was ultimately dumped. As available buyers disappeared, the token’s market price ceased to resemble the value of the physical silver backing it.
Dominion initially attempted a recovery. The company removed liquidity, replaced compromised signing devices, froze tokens acquired during the incident window and said restoring the SILV peg was a priority.
The project also designed a recovery framework intended to protect holders who owned SILV before the exploit while separately addressing investors who bought tokens during the price collapse.
That effort has now ended with a more definitive conclusion: rebuilding liquidity and repairing SILV’s market structure would require more capital than Dominion has left.
The situation resembles a broader problem seen across digital-asset infrastructure, where compromising control systems can be enough to destroy a product even when the underlying asset remains intact. Dave Finances recently examined another variation of that risk after a third-party module was used against real multisig wallets, illustrating how security ultimately depends on the entire authorization path rather than the headline wallet architecture alone.
Eligible Holders Can Exit at $63 per SILV
The refund plan gives qualifying pre-attack holders a defined exit price of $63 per SILV.
That price is significant because silver itself was trading around $60 to $61 per troy ounce on October 7. The refund therefore sits modestly above current spot silver rather than marking holders down to SILV’s distressed secondary-market value.
Eligibility is designed around ownership before the exploit, preventing traders who purchased deeply discounted SILV after the attack from automatically receiving the same treatment as investors who held the token beforehand.
Dominion had already faced that problem during its initial recovery effort. When the peg collapsed, arbitrage buyers could purchase SILV at steep discounts despite the project’s claim that each token remained backed by an ounce of physical silver. Fully honoring every distressed token at net asset value would have transferred a potentially large part of the recovery pool toward investors who deliberately bought after the exploit.
The shutdown simplifies the objective. Instead of spending scarce capital rebuilding DEX liquidity and trying to restore normal trading, Dominion is prioritizing the remaining resources for eligible refunds.
The Silver Was Backed, but the Token Still Failed
This is where Dominion becomes more interesting than an ordinary crypto hack.
Its core proposition was that SILV represented a real-world asset. Dominion said every token was backed by allocated physical silver, with reserves held in professional vault custody and independently auditable. The project was not relying purely on an algorithm or speculative token economics to maintain its value.
Yet asset backing alone did not keep SILV trading near silver.
Once a large volume of unauthorized tokens reached decentralized exchanges, the effective market price was determined by available liquidity rather than the theoretical value of metal in a vault.
That distinction is central to real-world asset tokenization. A token can have sound underlying collateral and still suffer a catastrophic market failure if its custody, issuance, redemption or liquidity infrastructure breaks.
The same separation between asset value and financial infrastructure appears in other tokenized products. A recently disclosed Heliobond vault accounting issue, for example, showed how a tokenized investment structure could potentially accumulate withdrawal claims exceeding the assets reflected by its accounting logic even without the underlying investments themselves failing.
Tokenization Adds Liquidity, but It Also Adds New Failure Points
Tokenized commodities are usually sold on a compelling idea: take something traditionally slow and difficult to move, put its economic representation on a blockchain and make it transferable around the clock.
Dominion was built around exactly that proposition. Physical silver could remain securely stored in a vault while SILV circulated through Solana, traded against stablecoins and interacted with lending and liquidity protocols.
That improves composability, but every additional layer introduces dependencies that owning a silver bar does not have.
The investor is no longer exposed only to the price of silver. There is also issuer risk, custody risk, key-management risk, smart-contract risk, blockchain risk, market-maker risk, redemption risk and liquidity risk.
In Dominion’s case, the silver did not need to disappear for the product to become unsustainable. Control of enough signing keys allowed an attacker to release a quantity of SILV that the market could not absorb. The resulting depeg then damaged liquidity and working capital badly enough that the project eventually concluded it could not recover.
That is a useful counterpoint to the growing institutional enthusiasm around tokenization. Major financial institutions are exploring blockchain representations of conventional assets and money, including the recent effort by Canada’s six largest banks to explore tokenized deposits. The technology can make settlement faster and assets more programmable, but the Dominion failure demonstrates why governance and operational controls have to develop alongside that efficiency.
Thin Liquidity Turned the Multisig Breach Into a Death Spiral
The biggest lesson may ultimately be about liquidity rather than silver.
The attacker controlled tokens notionally worth around $3 million but extracted only about $238,000. That sounds like a poor outcome for the attacker, yet it was disastrous for everyone else.
Every successive sale pushed the token further from its intended value. Once the market no longer trusted the peg, liquidity providers had little reason to keep capital exposed without clarity over how much unauthorized or compromised supply could still appear.
That creates a self-reinforcing problem. Falling liquidity makes subsequent sales more damaging, greater slippage widens the gap from net asset value, and a wider depeg makes market makers even less willing to restore liquidity.
A sufficiently large issuer can inject capital, repurchase tokens or provide redemption capacity until arbitrage pulls the market back toward its underlying value. A small project may not have that luxury.
Dominion’s closure shows how an exploit that generated less than a quarter-million dollars for an attacker can destroy a project representing several million dollars of nominal assets.
Multisig Security Is Only as Strong as the Independence of Its Keys
The 3-of-5 structure also deserves scrutiny.
Multisignature wallets are intended to eliminate the danger of a single compromised key. Requiring three signatures should mean that stealing one device or credential is not enough to move treasury assets.
That protection weakens dramatically if multiple keys share the same operational environment, personnel, devices or attack surface.
The relevant question for investors is therefore not simply whether an RWA issuer uses multisig custody. It is how genuinely independent those signers are.
A similar distinction emerged after the much larger Bitget breach, where Dave Finances reported that the exchange’s backend wallet system was compromised even though Bitget said its private keys themselves were not stolen. Both cases point toward the same security principle: a sophisticated custody design on paper does little good if attackers can compromise enough of the systems or credentials surrounding it.
Dominion Is a Warning for the Tokenized Commodity Market
SILV’s closure does not undermine the basic concept of tokenized precious metals. Larger products can have deeper liquidity, stronger operational controls, more diversified custody structures and enough capital to survive temporary market dislocations.
But Dominion exposes an uncomfortable assumption behind the real-world asset narrative.
Investors often hear that tokenization brings the stability of traditional assets onto blockchain rails. In practice, the blockchain wrapper introduces a second risk stack on top of the underlying asset.
A token backed by silver is not simply silver in digital form. Its value also depends on whether the issuer can securely control supply, preserve redemption, maintain sufficient liquidity and survive an operational shock.
Dominion had physical metal behind SILV. That was not enough.
The project is now using what remains of its capital to return money to qualifying holders rather than rebuild the token. For investors evaluating the next generation of tokenized commodities, that may be the more important lesson: verifying the collateral is only the beginning of due diligence.
You also need to know whether the infrastructure surrounding that collateral can survive when something goes wrong.
Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.
His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.
Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

