Security analysis tied the exploit to a compromised off-chain signer key, with forged buy, claim and transfer signatures used to extract and dump discounted STY tokens.
Swan Treasury, a decentralized asset management protocol on BNB Chain, lost about $625,000 after a compromised off-chain signer key let an attacker generate valid signatures and bypass purchase restrictions. Defimon Alerts said the attacker used the hardcoded signer address in the ZhaiquanBuy contract to buy roughly 687,000 STY at about a 100x discount, funding the trade with a PancakeSwap flash loan of about 19,700 USDT before selling the tokens into the STY/USDT pool. The security firm said forged signatures were also used on related claim() and transfer() functions, and its transaction analysis indicated the exploit stemmed from unauthorized access to the protocol’s signing credentials rather than a flaw in signature verification logic. STY was trading at about $2.87 at the time of the incident, according to the alert.