$625K Stolen as Swan Treasury Falls Victim to Leaked Signer Key Attack
Swan Treasury has fallen victim to a security breach that has resulted in an estimated $625,000 loss. The attack occurred on BNB Chain after attackers exploited a leaked off-chain signer key, allowing them to purchase STY tokens at a significant discount before selling them for profit.
The attacker used the compromised key to generate valid signatures, enabling them to bypass the protocol's intended purchase restrictions. By manipulating the buy() function, which calculates the amount of STY received based on a signed discount value, the attacker purchased nearly 687,000 STY tokens at roughly one-hundredth of their intended price.
The security firm Defimon Alerts noted that the exploit did not stop there, as valid signatures were also forged for the protocol's claim() and transfer() functions on related contracts. This allowed the attacker to access additional STY before selling the tokens into the STY/USDT liquidity pool.