Swan Treasury lost $625,000 on July 30. The cause traces to one line of code nobody thought to change: a signer address hardcoded as a constant, sitting in a contract called ZhaiquanBuy.
That address controlled how much of a discount a buyer could get on STY, the BNB Chain protocol’s own token. Whoever held the private key behind it could sign a purchase at any price they wanted. On July 30, someone who was not supposed to have that key signed one anyway.

A Discount Set to One
The buy() function priced STY off a signed discount parameter. Set that number low enough and the token is nearly free. The attacker set it to 1, buying roughly 687,000 STY at close to a hundredth of the going rate.
None of it required real capital up front. A PancakeSwap flash loan covered the purchase inside a single transaction, and the forged signature made the discounted buy look completely legitimate to the contract. DarkGrove Labs, an on-chain incident aggregator, cited analysis from Defimon Alerts confirming the transactions carried a genuine signature from the real signer key. That single detail rules out a bug in how the contract checks signatures. The key itself was the failure.
Once the tokens landed, the attacker sold them straight into the STY/USDT pool on PancakeSwap. Cheap supply meeting a thin pool does exactly what you would expect.
The Chart Confirms It, Almost to the Dollar
Pulling the pool’s own daily candles independently, rather than trusting anyone’s summary, tells the same story in numbers. STY opened July 30 at $2.79 and traded as low as $0.987 intraday, a 65 percent wipeout inside one session, before clawing back to close at $2.02. Volume that day hit $1.21 million against roughly $65,000 the day before, nearly 19 times normal.

Ten days on, STY sits at $2.55. Close, but still about 9 percent under where it was trading before the exploit hit. Market cap is back to $25.3 million and pool liquidity to $3.1 million, meaning the loss equaled roughly a fifth of the pool’s entire current depth. Not fatal. Not nothing either.
Five Named Firms, Zero Coverage
DeFiLlama’s hacks database logs the incident with one listed source: itself. A search built just to catch PeckShield, SlowMist, CertiK Alert, Cyvers, or BlockSec naming Swan Treasury or STY came back empty. Every account actually flagging this, DarkGrove Labs, BlockWatchdog, a Telegram monitor called Defendor, general crypto commentators, sits a tier below those five.
That gap is worth sitting with. A $625,000 signer-key compromise on a live protocol went uncovered by the industry’s most-cited alert accounts. Smaller, less-followed trackers did the work instead.
What the Project Actually Said
Swan Treasury’s own account never went quiet. Between August 6 and 8 it posted about a community node network, an AI-labeled RiskController announcement, and a summit tour opening in Vietnam. Ordinary marketing, running on schedule.
One post, on August 7, came close to the topic without ever landing on it: “Recent wallet security concerns remind the industry of one thing: Self-custody needs stronger protection,” quoting a CoinDesk piece about an unrelated hardware-wallet hack days earlier. No dollar figure. No mention of STY, ZhaiquanBuy, or July 30. No dedicated statement exists anywhere on the account.

Swan Treasury launched in March 2026 and has no other DeFiLlama incidents on record, so this is not a pattern, at least not yet. A hardcoded key was the whole vulnerability, a flash loan and a forged signature did the rest, and five months into the project’s life, the team that built it has still not said what happened in its own words.












