Swan Treasury attack results in $625,000 loss due to private key leak

iconKuCoinFlash
Share
AI summary iconSummary
Swan Treasury on BNBChain lost $625,000 following a private key compromise. Attackers forged valid signatures to purchase STY at a 100x discount. Using PancakeSwap flash loans, they acquired 687,000 STY with 19,700 USDT, then dumped the tokens into the STY/USDT pool, profiting 625,000 USDT. The ecrecover function confirmed the private key was directly exposed, not due to a flaw in signature logic. The incident underscores the risks of private key exposure in blockchain systems.

Odaily Planet Daily reports that Swan Treasury, a decentralized asset management protocol on BNBChain, suffered a loss of approximately $625,000 due to a private key compromise. The attacker forged valid signatures to their self-held address, purchasing STY at a 100x discount, then used a flash loan on PancakeSwap with approximately 19,700 USDT to acquire around 687,000 STY. Subsequently, they forged claim() and transfer signatures on a sibling contract, dumping all STY into the STY/USDT liquidity pool, profiting approximately 625,000 USDT. Each ecrecover call in the transaction resolved to a specific hardcoded signer, confirming that the private key itself was compromised, not a flaw in the signature logic.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.