Swan Treasury Suffers $625K Loss After Signer Key Leak
Swan Treasury has suffered an estimated $625,000 loss after attackers exploited a leaked off-chain signer key to buy STY tokens at a steep discount. The attacker used forged signatures and a PancakeSwap flash loan to purchase approximately 687,000 STY at a 100 times discount.
The protocol's compromised signer key was hardcoded in the ZhaiquanBuy contract on BNB Chain, allowing the attacker to bypass intended purchase restrictions. Defimon Alerts analyzed the transactions and found that every ecrecover operation resolved to the protocol's hardcoded signer address, indicating private key compromise rather than a flaw in signature verification logic.
After acquiring the tokens at a discounted price, the attacker sold them into the STY/USDT liquidity pool for a profit of approximately $625,000. This incident adds to a series of crypto attacks involving compromised privileged keys, rather than smart contract bugs.