{"id":22176,"date":"2026-07-31T10:12:08","date_gmt":"2026-07-31T10:12:08","guid":{"rendered":"https:\/\/cryptoted.net\/index.php\/2026\/07\/31\/swan-treasury-loses-625k-after-signer-key-leak-enables-discounted-sty-purchases\/"},"modified":"2026-07-31T10:12:08","modified_gmt":"2026-07-31T10:12:08","slug":"swan-treasury-loses-625k-after-signer-key-leak-enables-discounted-sty-purchases","status":"publish","type":"post","link":"https:\/\/cryptoted.net\/index.php\/2026\/07\/31\/swan-treasury-loses-625k-after-signer-key-leak-enables-discounted-sty-purchases\/","title":{"rendered":"Swan Treasury loses $625K after signer key leak enables discounted STY purchases"},"content":{"rendered":"<p> <br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/media.crypto.news\/2024\/09\/crypto-news-Crypto-wallet-recovery-without-a-private-key-or-seed-phrase-option04.webp\" \/><\/p>\n<div>\n<p class=\"is-style-lead\">Blockchain asset management protocol Swan Treasury has suffered an estimated $625,000 loss after attackers exploited a leaked off-chain signer key to buy STY tokens at a steep discount before selling them for profit.<\/p>\n<div id=\"cn-block-summary-block_2c369111aa3c814e69d5dad73e267aef\" class=\"cn-block-summary\">\n<p>\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/p>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>Swan Treasury lost about $625,000 after attackers exploited a compromised off chain signer key on BNB Chain.<\/li>\n<li>The attacker bought about 687,000 STY at a 100 times discount using forged signatures and a PancakeSwap flash loan.<\/li>\n<li>Forged claim and transfer signatures allowed the attacker to sell the tokens into the STY USDT pool for profit.<\/li>\n<li>Security analysis found the transactions were signed with the protocol\u2019s compromised signer key rather than exploiting a flaw in signature verification.<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>According to blockchain security firm Defimon Alerts, the exploit took place on BNB Chain after the protocol\u2019s off-chain signer key, hardcoded as the _signer address in the ZhaiquanBuy contract, was compromised.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">\ud83d\udea8 <a rel=\"nofollow\" href=\"https:\/\/x.com\/SwanTreasurpaj?ref_src=twsrc%5Etfw\">@SwanTreasurpaj<\/a> \u2013 Loss ~$625K (2026-07-30)<\/p>\n<p>Token: <a rel=\"nofollow\" href=\"https:\/\/x.com\/search?q=%24STY&amp;src=ctag&amp;ref_src=twsrc%5Etfw\">$STY<\/a> @ $2.87<br \/>Network: BNB Chain<\/p>\n<p>Type: Private Key Compromise (signer key leak)<\/p>\n<p>The protocol&#8217;s off-chain signer key (0xdEb4\u20268284, hardcoded as _signer in ZhaiquanBuy) was compromised. buy() sells STY at a signed discount:\u2026<\/p>\n<p>\u2014 Defimon Alerts (@DefimonAlerts) <a rel=\"nofollow\" href=\"https:\/\/x.com\/DefimonAlerts\/status\/2083039796784410802?ref_src=twsrc%5Etfw\">July 31, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>The attacker used the leaked key to generate valid signatures for their own wallet, allowing them to bypass the protocol\u2019s intended purchase restrictions.<\/p>\n<h2 class=\"wp-block-heading\">Swan Treasury exploit relied on leaked signer key<\/h2>\n<p>Defimon Alerts said the attacker manipulated the buy() function, which calculates the amount of STY a user receives based on a signed discount value. By generating a valid signature with the discount parameter set to one, the attacker purchased STY at roughly one-hundredth of its intended price.<\/p>\n<p>Using a PancakeSwap flash loan worth about 19,700 USDT, the attacker acquired nearly 687,000 STY tokens through the discounted purchase mechanism.<\/p>\n<p>The security firm said the exploit did not stop there. Valid signatures were also forged for the protocol\u2019s claim() and transfer() functions on related contracts, giving the attacker additional access to STY before selling the tokens into the STY\/USDT liquidity pool.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<p>After unwinding the position, the attacker realized about 625,000 USDT in profit, according to Defimon Alerts.<\/p>\n<p>STY traded at approximately $2.87 at the time of the incident, the firm\u2019s alert noted.<\/p>\n<h2 class=\"wp-block-heading\">Transaction analysis points to a compromised private key<\/h2>\n<p>In its technical assessment, Defimon Alerts said every ecrecover operation observed during the exploit resolved to the protocol\u2019s hardcoded signer address rather than any attacker-controlled account.<\/p>\n<p>The firm said this behavior indicates the private signer key itself had been compromised instead of the protocol containing a flaw in its signature verification logic. Because the generated signatures matched the expected signer exactly, the transactions appeared valid to the affected smart contracts.<\/p>\n<p>The finding narrows the likely cause of the exploit to unauthorized access to the protocol\u2019s signing credentials rather than an error in the cryptographic verification process.<\/p>\n<p>At the time of publication, Swan Treasury had not publicly explained how the signer key was exposed or whether additional mitigation measures had been implemented.<\/p>\n<h2 class=\"wp-block-heading\">Private key compromises continue to drive crypto losses<\/h2>\n<p>The incident adds to a series of crypto attacks in which compromised privileged keys, rather than smart contract bugs, allowed attackers to access protocol funds.<\/p>\n<p>In June 2025, blockchain security company Hacken <a href=\"https:\/\/crypto.news\/hacken-bridge-exploited-for-250k-hai-token-following-private-key-leak\/\" target=\"_blank\">disclosed<\/a> that a compromised private key tied to a contract with minting privileges enabled an attacker to create 900 million HAI tokens across Ethereum and BNB Chain.\u00a0<\/p>\n<p>Hacken said the key was exposed while the company was making architectural changes to its blockchain bridge infrastructure, allowing the attacker to realize about $250,000 before the affected minting account was revoked and bridge operations were paused.<\/p>\n<p>Separate research has also continued to identify private key exposure as one of the industry\u2019s most persistent security risks. A Hacken report cited by crypto.news previously found that access control failures, including private key leaks, accounted for 78% of crypto hack losses recorded during 2024.<\/p>\n<p>More recently, Zilliqa <a href=\"https:\/\/crypto.news\/zilliqa-ledger-app-flaw-exposes-private-keys-halts-zil-transfers\/\" target=\"_blank\">disclosed<\/a> a flaw in its native Ledger application that could allow attackers to recover private keys from public transaction signatures. The network suspended native ZIL transactions after determining that a weakness in nonce generation made it possible to reconstruct affected keys once enough signatures had been collected.\u00a0<\/p>\n<p>Zilliqa said the issue stemmed from its own Ledger application rather than Ledger hardware itself and instructed affected users to wait for recovery guidance instead of moving funds immediately.<\/p>\n<h2 class=\"wp-block-heading\">Security researchers continue warning about key exposure<\/h2>\n<p>Academic researchers and <a href=\"https:\/\/crypto.news\/binances-changpeng-zhao-urges-caution-after-github-breach\/\" target=\"_blank\">crypto industry players<\/a> have likewise warned that private key security remains vulnerable outside traditional smart contract exploits.<\/p>\n<p>Researchers from the University of California <a href=\"https:\/\/crypto.news\/uc-researchers-warn-third-party-ai-routers-are-stealing-crypto-and-private-keys\/\" target=\"_blank\">reported<\/a> earlier this year that some third-party AI routing services were capable of accessing sensitive credentials, including cryptocurrency private keys and seed phrases, because they process user requests in plaintext.\u00a0<\/p>\n<p>During controlled testing, the researchers observed malicious behavior from several routing services and demonstrated that one intermediary successfully drained Ether from a test wallet after receiving its private key.<\/p>\n<p>While the university study was unrelated to the Swan Treasury incident, the researchers concluded that developers should avoid exposing private keys or seed phrases to intermediary systems and instead rely on stronger cryptographic protections to reduce credential theft risks.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/crypto.news\/swan-treasury-loses-625k-after-signer-key-leak-enables-discounted-sty-purchases\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Blockchain asset management protocol Swan Treasury has suffered an estimated $625,000 loss after attackers exploited a leaked off-chain signer key to buy STY tokens at a steep discount before selling them for profit. Summary Swan Treasury lost about $625,000 after attackers exploited a compromised off chain signer key on BNB Chain. The attacker bought about [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":22177,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"tdm_status":"","tdm_grid_status":"","footnotes":""},"categories":[23],"tags":[],"kronos_expire_date":[],"class_list":["post-22176","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto"],"_links":{"self":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/22176","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/comments?post=22176"}],"version-history":[{"count":0,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/22176\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media\/22177"}],"wp:attachment":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media?parent=22176"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/categories?post=22176"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/tags?post=22176"},{"taxonomy":"kronos_expire_date","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/kronos_expire_date?post=22176"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}