On July 30, 2026, blockchain asset management protocol Swan Treasury lost approximately $625,000 on BNB Chain. Attackers exploited a compromised off-chain signer key to purchase STY tokens at a 100-fold discount using a PancakeSwap flash loan. Security analysis by Defimon Alerts indicates the incident was caused by unauthorized credential access rather than a smart contract bug, highlighting the ongoing industry risk of private key compromises.
Swan Treasury exploit mechanics
▪The attacker used a PancakeSwap flash loan of approximately 19,700 USDT to purchase nearly 687,000 STY tokens at a 100-fold discount.
▪On July 30, 2026, Swan Treasury suffered an estimated $625,000 loss on BNB Chain after attackers exploited a compromised off-chain signer key.
▪The attacker forged signatures for Swan Treasury's claim() and transfer() functions to sell the acquired STY tokens into the STY/USDT liquidity pool.
Compromised signer key analysis
▪Defimon Alerts determined the exploit resulted from unauthorized access to Swan Treasury's signing credentials rather than a flaw in its signature verification logic.
▪Blockchain security firm Defimon Alerts found that every ecrecover operation during the exploit resolved to Swan Treasury's hardcoded signer address in the ZhaiquanBuy contract.
Private key compromise incidents
▪Zilliqa suspended native ZIL transactions after discovering a flaw in its native Ledger application that allowed attackers to reconstruct private keys from public transaction signatures.
▪A report by blockchain security company Hacken found that access control failures, including private key leaks, accounted for 78% of crypto hack losses in 2024.
▪In June 2025, a compromised private key tied to a Hacken bridge contract enabled an attacker to mint 900 million HAI tokens and realize a $250,000 profit.
Security research on key exposure
▪University of California researchers reported that some third-party AI routing services could access cryptocurrency private keys because they process user requests in plaintext.
▪During controlled testing, University of California researchers demonstrated that an intermediary AI routing service successfully drained Ether from a test wallet after receiving its private key.
Story comments
Loading comments…