Swan Treasury lost roughly $625,000 after an off‑chain signer key was leaked, letting an attacker buy STY tokens at a steep discount and cash out on BNB Chain, blockchain security firm Defimon Alerts reported. What happened - Date & exposure: Defimon Alerts flagged the incident on July 30, 2026. The protocol’s off‑chain signer key—hardcoded as _signer (0xdEb4…8284) in the ZhaiquanBuy contract—was compromised. - How the exploit worked: The attacker used the stolen private key to generate valid signatures for their own wallet. Those signatures fooled the contract’s buy() function, which calculates how much STY a purchaser receives based on a signed “discount” parameter. - Discount abuse: By signing a discount value of 1, the attacker effectively bought STY for about one‑hundredth of the intended price. - Funding and scale: The attacker took a PancakeSwap flash loan of roughly 19,700 USDT, obtained nearly 687,000 STY via the discounted purchase path, then forged valid signatures for related claim() and transfer() functions to access more tokens. - Exit and proceeds: After dumping into the STY/USDT liquidity pool, the attacker realized about 625,000 USDT in profit. STY was trading near $2.87 at the time. Why this points to a key leak, not a contract bug Defimon Alerts’ technical analysis showed that every ecrecover call during the exploit resolved to the protocol’s hardcoded signer address rather than an attacker account. That indicates the attacker possessed the actual private signer key, not that the signature verification logic was flawed. Because generated signatures matched the expected signer exactly, contracts treated the transactions as legitimate. Swan Treasury response At the time of the report, Swan Treasury had not publicly detailed how the signer key was exposed or what mitigation steps (if any) were implemented. Broader context: key exposure is a recurring danger This incident is part of a string of attacks where compromised privileged keys—not smart contract bugs—enabled theft: - June 2025: Hacken disclosed a compromised private key tied to a minting account that allowed creation of 900 million HAI across Ethereum and BNB Chain; the attacker realized about $250,000 before the account was revoked and bridge operations paused. - Industry data: A Hacken analysis cited by crypto.news found access control failures, including private key leaks, accounted for roughly 78% of recorded crypto hack losses in 2024. - Zilliqa: The network recently suspended native ZIL transactions after finding a flaw in its Ledger app’s nonce generation that could let attackers reconstruct private keys from public signatures; the issue was in the app, not Ledger hardware. - Academic findings: University of California researchers showed that some third‑party AI routing services can access plaintext credentials—including private keys and seed phrases—during request processing. In controlled tests one intermediary drained Ether from a test wallet after receiving its private key. Takeaway Security incidents driven by credential exposure remain a major systemic risk for crypto projects. Researchers and security firms repeatedly advise developers to avoid exposing private keys or seed phrases to intermediaries, hardcode minimal privileges, and employ stronger cryptographic and operational safeguards (e.g., hardware security modules, multisig, rotating keys) to reduce the risk of credential theft.
Swan Treasury Loses $625K After Off-Chain Signer Key Leak
ChainGPTShare
Swan Treasury lost $625,000 after an off-chain signer key was leaked, per on-chain news from ChainGPT. The attacker used the stolen key to generate valid signatures and exploit the buy() function. Nearly 687,000 STY tokens were obtained via a flash loan and later sold on BNB Chain. Defimon Alerts confirmed the signatures matched the protocol’s hardcoded signer, pointing to a key leak. A protocol update has not yet been announced, and Swan Treasury has not revealed how the key was exposed.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.