Swan Treasury Security Breach
Swan Treasury, a blockchain protocol focused on asset management, has fallen victim to a significant security breach, leading to an estimated loss of $625,000. The incident is linked to the exposure of an off-chain signer key, which was exploited by attackers to acquire STY tokens at a fraction of their market value.
Details of the Breach
According to the blockchain security firm Defimon Alerts, the breach occurred on the BNB Chain. Attackers accessed a hardcoded signer address within the protocol’s ZhaiquanBuy contract, effectively compromising the mechanism that governs token purchases. This allowed them to generate valid signatures, bypassing the established purchase limitations. They managed to purchase STY tokens at approximately 1% of the retail price, leveraging a manipulated discount during the buying process.
Using a flash loan worth approximately 19,700 USDT from PancakeSwap, the attacker effectively obtained about 687,000 STY tokens. The method employed a forged signature with a discount parameter set to the maximum allowable limit. Following this, the attackers additionally forged signatures for other functions within the protocol, allowing them to claim and transfer more STY before liquidating their holdings into the STY/USDT liquidity pool.
Impact of the Attack
The trading price for STY floored at around $2.87 at the time of the exploit, indicating the severity of profit the attackers derived — close to $625,000 in total. The security firm stated that the exploited signatures resolved to the protocol’s hallowed signer address, indicating that the attacker gained unauthorized access to the private key rather than exploiting a flaw in the system’s signature verification processes.
Response and Industry Trends
Despite this serious breach, Swan Treasury has yet to provide detailed information concerning how the signer key was compromised or whether any steps have been taken to prevent future incidents. The event underscores a troubling trend in the crypto world where numerous breaches arise from compromised private keys rather than inherent vulnerabilities in smart contracts.
In a previous incident in June 2025, Hacken, a blockchain security firm, highlighted a similar instance where a compromised private key associated with minting rights allowed attackers to generate 900 million HAI tokens on both Ethereum and BNB Chain, resulting in a financial loss of about $250,000.
Furthermore, research has continually identified the risk of private key exposure as a leading vulnerability in the cryptocurrency ecosystem, with a report from Hacken indicating that such security failures were responsible for 78% of crypto hack losses in 2024. Other networks like Zilliqa recently reported their own private key vulnerabilities, stemming from weaknesses in their Ledger applications, leading to the suspension of native transactions.
Need for Enhanced Security
The ongoing issues reveal a pressing need for heightened security measures around private key management in the cryptocurrency sector. Recently, University of California researchers also found that some AI routing services could inadvertently expose sensitive credentials including private keys, as user data was processed in plaintext, prompting further concern over these vulnerabilities.
As the frequency of breaches like the one at Swan Treasury rises, it is clear that strong cryptographic protections and best practices for private key security are essential to safeguard protocols in the evolving blockchain landscape.