In section Cryptocurrency

Swan Treasury suffers $625,000 loss after signer key leak

A critical security breach on the BNB Chain has left Swan Treasury short $625,000 after attackers obtained the protocol’s off-chain signer key. By exploiting this leaked credential, bad actors bypassed purchase restrictions to acquire STY tokens at a 100-fold discount before dumping them into liquidity pools for profit.

Swan Treasury suffers $625,000 loss after signer key leak

Blockchain security firm Defimon Alerts confirmed that the incident stemmed from a compromised private key rather than a vulnerability in smart contract code. The attacker manipulated the protocol’s buy() function by using the hardcoded signer address to generate valid, unauthorized signatures. This allowed them to set a discount parameter to one, effectively purchasing approximately 687,000 STY tokens at a fraction of their $2.87 market value.

To facilitate the attack, the perpetrator utilized a PancakeSwap flash loan worth 19,700 USDT. Beyond the initial token purchase, the attacker forged signatures for claim and transfer functions on related contracts, granting them further access to the protocol’s assets. Forensic analysis of ecrecover operations confirmed that every transaction involved was cryptographically valid, as the signatures matched the protocol’s compromised credential exactly. Swan Treasury has yet to disclose how the signer key was exposed or provide a timeline for system recovery.

Share:on TelegramXFacebook

Subscribe to our newsletter

Once a week — the best stories from our editors, no ads or push notifications. Delivered Sunday morning.

Comments (0)

Leave a comment

No comments yet. Be the first!