Swan Treasury Suffers $625K Loss Due to Leaked Signer Key
Swan Treasury Suffers $625K Loss Due to Leaked Signer Key
The blockchain asset management protocol, Swan Treasury, has incurred a substantial loss estimated at $625,000 after attackers took advantage of a leaked off-chain signer key. This key leak allowed unauthorized purchases of STY tokens at significantly discounted rates.
Details of the Exploit
According to a report from blockchain security firm Defimon Alerts, attackers exploited the compromised signer key on the BNB Chain. Using this key, the attackers bought approximately 687,000 STY tokens at a price around one-hundredth of its intended value. This was achieved through forged signatures combined with a PancakeSwap flash loan.
Mechanics of the Attack
The operation was executed by manipulating the buy() function, which determines the amount of STY received based on a signed discount value. By generating a valid signature parameter set to one, they exploited the system’s vulnerabilities. After purchasing the tokens, they sold them into the STY/USDT liquidity pool for profit.
Technical Assessment Insights
Defimon Alerts noted that all observed ecrecover operations resolved to the protocol’s hardcoded signer address, indicating a direct compromise of the signer key itself. This assessment suggests that the exploit was due to unauthorized access rather than a flaw in the signature verification process.
No Public Statement from Swan Treasury
As of the report’s publication, Swan Treasury had not provided any details on how the signer key was compromised or whether they have undertaken any mitigation measures following the incident.
Broader Implications for Crypto Security
This exploit is part of a larger trend in the crypto industry, where compromised private keys lead to significant financial losses. Previous incidents have shown that security breaches involving private keys accounted for a large percentage of crypto thefts in the past year. Security experts continue to raise concerns about the vulnerabilities associated with private key management and the potential for ongoing attacks against various protocols.
Source: crypto.news