Swan Treasury Loses $625K After Leaked Signer Key Lets Attacker Buy STY at 99% Discount

iconChainGPT
Share
AI summary iconSummary
Swan Treasury suffered a $625K loss after a leaked off-chain signer key allowed an attacker to exploit the BNB Chain. Using a flash loan of 19,700 USDT, the hacker bought 687,000 STY tokens at a 99% discount and cashed out. This on-chain news incident, reported by Defimon Alerts, shows how a valid signature can be forged when keys are exposed. Hacken noted that 78% of 2024 crypto losses came from similar security breaches. Hardcoded keys and weak access controls remain major risks.

Swan Treasury suffered an estimated $625,000 loss after attackers used a leaked off‑chain signer private key to buy STY tokens at a massive discount on BNB Chain and immediately cash out, blockchain security firm Defimon Alerts reported. What happened Defimon’s investigation shows the protocol’s off‑chain signer address (0xdEb4…8284), hardcoded as _signer in the ZhaiquanBuy contract, was compromised. The attacker generated valid signatures with the stolen key to manipulate the contract’s buy() function, which uses a signed “discount” parameter to calculate how many STY tokens a buyer receives. By signing a discount value of 1, the attacker purchased STY at roughly one‑hundredth of the intended price. How the exploit played out Using a PancakeSwap flash loan of about 19,700 USDT, the attacker acquired nearly 687,000 STY through the discounted purchase mechanism. Defimon found the attacker also forged valid signatures for related claim() and transfer() functions to pull additional STY, then sold those tokens into the STY/USDT liquidity pool. After unwinding the position, the attacker realized roughly 625,000 USDT in profit. STY was trading near $2.87 at the time, according to the alert. Why this points to a key leak, not a contract bug Defimon’s technical analysis noted that every ecrecover call during the exploit resolved to the protocol’s hardcoded signer address rather than any attacker‑controlled account. That indicates the private signing key itself was exposed, not that the contracts’ signature verification logic was flawed—because the forged signatures matched the expected signer exactly. Response and wider context Swan Treasury had not publicly explained how the signer key was exposed or disclosed any mitigation steps at the time of publication. The incident is the latest in a string of attacks where leaked privileged credentials—rather than on‑chain bugs—enabled large losses. In June 2025, Hacken disclosed that a compromised private key allowed an attacker to mint 900 million HAI across Ethereum and BNB Chain, netting about $250,000 before the account was revoked. A Hacken analysis cited by crypto.news found access control failures, including private key leaks, accounted for 78% of recorded crypto hack losses in 2024. Emerging attack surfaces Private keys are increasingly targeted not only through poor storage practices but also via third‑party systems. Zilliqa recently paused native ZIL transactions after a flaw in its Ledger app’s nonce generation made key recovery possible from collected signatures. Academic researchers at the University of California also showed some third‑party AI routing services can access plaintext credentials—including private keys—during request processing, and in tests an intermediary was able to drain a test wallet. Takeaway This breach underscores a simple but persistent truth: private signing keys are a single point of failure. Projects should avoid hardcoding or exposing keys to intermediary services, enforce strict access controls, rotate and vault credentials, and adopt stronger cryptographic custody solutions to reduce the risk of credential theft. Read more: Defimon Alerts’ technical summary and follow‑ups from Swan Treasury (if released) for mitigation details and recovery status.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.