On July 30, 2026, blockchain asset management protocol Swan Treasury lost approximately $625,000 on BNB Chain. Attackers exploited a compromised off-chain signer key to purchase STY tokens at a 100-fold discount using a PancakeSwap flash loan. Security analysis by Defimon Alerts indicates the incident was caused by unauthorized credential access rather than a smart contract bug, highlighting the ongoing industry risk of private key compromises.
Swan Treasury exploit mechanics
- ▪The attacker used a PancakeSwap flash loan of approximately 19,700 USDT to purchase nearly 687,000 STY tokens at a 100-fold discount.
- ▪On July 30, 2026, Swan Treasury suffered an estimated $625,000 loss on BNB Chain after attackers exploited a compromised off-chain signer key.
- ▪The attacker forged signatures for Swan Treasury's claim() and transfer() functions to sell the acquired STY tokens into the STY/USDT liquidity pool.
Compromised signer key analysis
- ▪Defimon Alerts determined the exploit resulted from unauthorized access to Swan Treasury's signing credentials rather than a flaw in its signature verification logic.
- ▪Blockchain security firm Defimon Alerts found that every ecrecover operation during the exploit resolved to Swan Treasury's hardcoded signer address in the ZhaiquanBuy contract.
Private key compromise incidents
- ▪Zilliqa suspended native ZIL transactions after discovering a flaw in its native Ledger application that allowed attackers to reconstruct private keys from public transaction signatures.
- ▪A report by blockchain security company Hacken found that access control failures, including private key leaks, accounted for 78% of crypto hack losses in 2024.
- ▪In June 2025, a compromised private key tied to a Hacken bridge contract enabled an attacker to mint 900 million HAI tokens and realize a $250,000 profit.
Security research on key exposure
- ▪University of California researchers reported that some third-party AI routing services could access cryptocurrency private keys because they process user requests in plaintext.
- ▪During controlled testing, University of California researchers demonstrated that an intermediary AI routing service successfully drained Ether from a test wallet after receiving its private key.
Story comments
Loading comments…