Blockchain security firm Defimon Alerts confirmed that the incident stemmed from a compromised private key rather than a vulnerability in smart contract code. The attacker manipulated the protocol’s buy() function by using the hardcoded signer address to generate valid, unauthorized signatures. This allowed them to set a discount parameter to one, effectively purchasing approximately 687,000 STY tokens at a fraction of their $2.87 market value.
To facilitate the attack, the perpetrator utilized a PancakeSwap flash loan worth 19,700 USDT. Beyond the initial token purchase, the attacker forged signatures for claim and transfer functions on related contracts, granting them further access to the protocol’s assets. Forensic analysis of ecrecover operations confirmed that every transaction involved was cryptographically valid, as the signatures matched the protocol’s compromised credential exactly. Swan Treasury has yet to disclose how the signer key was exposed or provide a timeline for system recovery.

Comments (0)
No comments yet. Be the first!