{"investigation":{"slug":"swissborg","entity_name":"SwissBorg","trust_score":47,"severity_base":null,"score_modifier":-5,"confidence":1,"status":"published","content_type":"investigation","summary":"SwissBorg is a Swiss-based crypto wealth management and exchange aggregator founded in 2017, holding MiCA authorization from France's AMF and VQF membership in Switzerland. In September 2025, the platform suffered a $41.5 million loss when its staking partner Kiln's API was compromised via a GitHub token theft and Kubernetes pod injection, resulting in the unauthorized transfer of 192,600 SOL from SwissBorg's SOL Earn program; the company subsequently pledged full reimbursement from treasury funds. While SwissBorg maintains legitimate regulatory standing and transparency measures including Proof of Liabilities, the third-party supply chain failure exposes material counterparty risk in its Earn product architecture.","sections":[{"content":"SwissBorg was founded in 2017 by Cyrus Fazel (CEO) and Anthony Lesoismier (CSO), both formerly of traditional wealth management and banking. The company is headquartered in Lausanne, Switzerland. Its primary product is a mobile crypto aggregator — marketed as a 'meta-exchange' — that routes trades across more than 12 centralized and decentralized exchanges via a Smart Engine to obtain best-available prices. As of 2024 the platform reported over one million registered users in 47 countries across 16 fiat currencies. SwissBorg also operates 'Earn' strategies, yield-bearing products that deploy user assets to third-party staking and DeFi infrastructure partners. The platform's native token is BORG (formerly CHSB). Fazel and Lesoismier both hold backgrounds at EDHEC Business School and spent over a decade in European wealth management before founding SwissBorg.","heading":"Background","sources":[{"url":"https://help.swissborg.com/hc/en-gb/articles/360009028418-What-is-SwissBorg","name":"","type":"other","credibility":3},{"url":"https://www.venturelab.swiss/SwissBorg-CEO-Cyrus-Fazel-We-enable-everyone-to-enjoy-the-world-of-decentralized-finance-regardless-of-their-investment-interests","name":"","type":"other","credibility":3},{"url":"https://en.cryptonomist.ch/2024/07/23/swissborg-the-swiss-crypto-exchange-open-to-everyone/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On September 8, 2025, an attacker drained approximately 192,600 SOL (valued at roughly $41.5 million) from an external DeFi wallet used to operate SwissBorg's SOL Earn staking strategy. The root cause was a multi-stage supply chain compromise targeting Kiln, SwissBorg's third-party Solana staking infrastructure partner.\n\nThe attack began on or before August 31, 2025. An attacker obtained a GitHub access token belonging to a Kiln infrastructure engineer — the initial intrusion vector is consistent with a phishing or credential-theft campaign. Using this token, the attacker triggered CI/CD pipeline workflows by creating and rapidly deleting branches designed to avoid automated detection. From those workflows, the attacker harvested cloud credentials spanning AWS, GCP, and bare-metal infrastructure. This access was used to inject a malicious payload directly into a running Kubernetes pod hosting the Kiln Connect API.\n\nThe injected code modified the logic of Kiln's 'deactivate stake' API endpoint so that, in addition to returning the expected unstaking transaction, it also returned a second malicious transaction. This second transaction reassigned the Solana withdrawal authority — the key that controls fund movement — for any stake account holding more than 150,000 SOL. On August 31, SwissBorg used the Kiln Dashboard to unstake approximately 975 SOL. The malicious transaction bundle was forwarded to SwissBorg's custody solution, where a quorum of multi-signature approvers signed both the legitimate and the malicious transactions, apparently without decoding the full transaction payload. Kiln's own post-mortem noted that the customer 'failed to decode the transaction before signing,' which Kiln identified as a best-practice gap.\n\nEight days later, on September 8 at approximately 12:02 UTC, the attacker executed the theft across eight separate transactions in under three minutes, draining all stake accounts whose withdrawal authority had been silently reassigned. Approximately 189,524 SOL was parked in a single attacker-controlled wallet, with roughly 3,000 SOL routed through exchanges including Bitget in a apparent liquidity test. As of the most recent available reporting, the primary wallet remains unspent.\n\nSwissBorg confirmed the breach on September 9, 2025. CEO Cyrus Fazel characterized the incident as an attack on a counterparty, stating 'this was not a breach of the SwissBorg platform.' SwissBorg temporarily suspended SOL Earn redemptions. The company engaged blockchain analytics firm Chainalysis, independent researcher ZachXBT, the SEAL security organization, and Fireblocks, in addition to notifying law enforcement. Kiln publicly disclosed the incident on October 7, 2025, after completing initial forensics with Sygnia, and announced six remediation measures: zero-trust access controls, hardened CI/CD pipelines, blast-radius isolation, container hardening, 24/7 monitoring, and enhanced validator key protection.","heading":"The Kiln Supply Chain Hack ($41M)","sources":[{"url":"https://www.kiln.fi/post/re-enablement-of-kiln-services-and-security-incident-information","name":"","type":"other","credibility":3},{"url":"https://harrydonnelly.substack.com/p/swissborgkiln-exploit-breakdown","name":"","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/?id=swissborg-exploit","name":"","type":"other","credibility":3},{"url":"https://protos.com/swissborg-ceo-blames-41m-loss-on-staking-partner-kiln/","name":"","type":"other","credibility":3},{"url":"https://swissborg.com/blog/sol-earn-incident-swissborg-recovery","name":"","type":"other","credibility":3},{"url":"https://therecord.media/swissborg-platform-solana-cryptocurrency-stolen","name":"","type":"other","credibility":3},{"url":"https://thecryptobasic.com/2025/09/09/swissborg-to-compensate-users-after-41m-solana-staking-hack/","name":"","type":"other","credibility":3},{"url":"https://www.fireblocks.com/blog/case-for-native-staking-kiln-incident","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"SwissBorg operates through multiple legal entities across jurisdictions. The primary operating entity, SwissBorg Solutions OÜ, holds a Virtual Currency Service License (FVT000326) issued by the Financial Intelligence Unit (FIU) of Estonia, and was registered with France's Autorité des Marchés Financiers (AMF) under number E2022-034 as a Digital Asset Service Provider (DASP).\n\nSwissBorg is also a member of VQF (Verein zur Qualitätssicherung der Finanzdienstleister), a self-regulatory organization (SRO) recognized and supervised by the Swiss Financial Market Supervisory Authority (FINMA). This SRO membership subjects SwissBorg to Swiss AML compliance requirements, though it does not constitute a full FINMA banking or securities dealer license.\n\nIn March 2026, SwissBorg's French entity Blocknodes SAS received full MiCA (Markets in Crypto-Assets Regulation) authorization from the AMF — one of Europe's most demanding financial regulators. This MiCA authorization serves as a European passport enabling SwissBorg to provide regulated crypto services across all 27 EU member states. Under the authorization, Blocknodes SAS is permitted to offer crypto custody, order execution, asset transfers, portfolio management, and investment advice. SwissBorg has announced a phased migration of European users from SwissBorg Solutions OÜ to Blocknodes SAS following the approval. The MiCA framework mandates 1:1 stablecoin reserves, quarterly audits, and AML/KYC compliance.","heading":"Regulatory Status","sources":[{"url":"https://help.swissborg.com/hc/en-gb/articles/360015167634-SwissBorg-Legal-structure-jurisdiction-and-licenses","name":"","type":"other","credibility":3},{"url":"https://swissborg.com/blog/swissborg-secures-mica-approval-from-french-amf","name":"","type":"other","credibility":3},{"url":"https://news.bitcoin.com/swissborg-secures-mica-license-from-frances-amf-expanding-regulated-crypto-services-across-eu/","name":"","type":"other","credibility":3},{"url":"https://www.coindesk.com/press-release/2026/03/12/swissborg-secures-mica-approval-from-france-s-financial-markets-authority","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"SwissBorg describes its core security architecture as relying on multi-party computation (MPC) keyless technology, which eliminates single points of key failure for user wallets. The platform also supports Passkeys for authentication and states that it conducts regular third-party security audits, though specific audit firm names and reports are not comprehensively published as of the time of this investigation.\n\nThe September 2025 exploit exposed material weaknesses in SwissBorg's third-party risk management framework. The attack did not breach SwissBorg's core platform or user wallet infrastructure directly; however, SwissBorg's multi-signature custody process failed to detect and reject the malicious Kiln transaction before approving it. Kiln's own post-mortem explicitly identified failure to decode the full transaction prior to signing as a best-practice gap on the part of its enterprise customer — implicating SwissBorg's internal custody review procedures.\n\nThe incident demonstrates that SwissBorg's Earn product introduced unhedged counterparty exposure to Kiln's infrastructure, with no apparent real-time transaction decoding gate in the approval workflow. This represents a systemic gap between SwissBorg's stated security posture and the actual controls applied to Earn strategy deployments. Following the incident, Kiln implemented zero-trust access, CI/CD hardening, blast-radius isolation, container hardening, and continuous monitoring. SwissBorg has not published a comprehensive independent post-mortem disclosing its own control failures. The stolen funds — approximately 189,524 SOL — remained in the attacker's wallet as of the most recent available reporting, with no confirmed recovery.","heading":"Security Posture","sources":[{"url":"https://academy.swissborg.com/en/learn/mpc-keyless-technology-keeping-your-crypto-secure","name":"","type":"other","credibility":3},{"url":"https://www.kiln.fi/post/re-enablement-of-kiln-services-and-security-incident-information","name":"","type":"other","credibility":3},{"url":"https://harrydonnelly.substack.com/p/swissborgkiln-exploit-breakdown","name":"","type":"other","credibility":3},{"url":"https://www.fireblocks.com/blog/case-for-native-staking-kiln-incident","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"SwissBorg publishes a Proof of Liabilities portal using a Merkle-tree cryptographic mechanism, allowing any user to verify that their balance is included in the platform's total reported liabilities. The open-source implementation is available on GitHub. The company states that customer funds are fully segregated from corporate treasury assets, and that as a regulated Virtual Asset Service Provider it is legally required to maintain 100% user fund coverage. SwissBorg claims that even in a bankruptcy scenario, user funds would remain redeemable on a 1:1 basis.\n\nIn response to the September 2025 hack, SwissBorg pledged full reimbursement of all affected users using its SOL treasury, with CEO Cyrus Fazel publicly stating 'SwissBorg community will not take a loss. Any gap in recovered funds will be covered.' The hack affected fewer than 1% of users and approximately 2% of total platform assets. SOL Earn redemptions were temporarily suspended during the investigation. All other Earn strategies and core user deposits remained unaffected and accessible throughout.\n\nThere is no publicly disclosed third-party insurance policy for digital assets stored in hot or warm infrastructure. The company references cold wallet insurance in marketing materials, but specific coverage amounts and underwriters are not disclosed. The MiCA authorization (March 2026) imposes additional ongoing obligations including regular audits and capital requirements, which may strengthen user protection over time.","heading":"User Protections","sources":[{"url":"https://swissborg.com/proof-of-liabilities/audits","name":"","type":"other","credibility":3},{"url":"https://swissborg.com/blog/proof-of-liabilities","name":"","type":"other","credibility":3},{"url":"https://github.com/SwissBorg/proof-of-liabilities","name":"","type":"other","credibility":3},{"url":"https://swissborg.com/blog/sol-earn-incident-swissborg-recovery","name":"","type":"other","credibility":3},{"url":"https://swissborg.com/blog/swissborg-security-and-trust","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"SwissBorg is a legitimate, regulated entity with verifiable licensing across Switzerland (VQF/FINMA SRO), Estonia (FIU Virtual Currency License), and now France (MiCA authorization via AMF). It is not a scam or rug-pull. However, the September 2025 Kiln supply chain incident materially affects its risk profile in several ways.\n\nCounterparty risk: The SOL Earn product introduced opaque third-party infrastructure dependency on Kiln. The attack was technically sophisticated — requiring a GitHub credential compromise, CI/CD exploitation, cloud credential harvesting, Kubernetes pod injection, and targeted Solana authority manipulation — but the loss was ultimately enabled by a failure in SwissBorg's own custody signing procedures. Multi-signature approvers signed a malicious transaction bundle without decoding its full content.\n\nRecovery uncertainty: As of the most recent available reporting, 189,524 SOL remains in the attacker's wallet with no confirmed recovery. The stolen amount ($41.5 million) is material relative to the platform's disclosed treasury.\n\nTransparency gaps: SwissBorg has not published a comprehensive independent post-mortem addressing its own control failures. Kiln published its post-mortem on October 7, 2025; SwissBorg's public communications have emphasized the counterparty framing without fully addressing its signing-process failure.\n\nMitigating factors: SwissBorg honored its reimbursement pledge, keeping users financially whole. Core platform infrastructure was not compromised. The platform holds genuine regulatory licenses and operates Proof of Liabilities. The MiCA authorization brings ongoing audit obligations. The incident affected 1% of users and 2% of total assets, suggesting reasonable asset segregation between Earn strategies and core holdings.\n\nThe primary residual risk for users is the platform's Earn product: yield-bearing products depend on third-party infrastructure whose security posture SwissBorg cannot fully control or audit in real time. Users who hold assets in Earn strategies face counterparty risk that extends beyond SwissBorg's own security perimeter.","heading":"Risk Assessment","sources":[{"url":"https://protos.com/swissborg-ceo-blames-41m-loss-on-staking-partner-kiln/","name":"","type":"other","credibility":3},{"url":"https://therecord.media/swissborg-platform-solana-cryptocurrency-stolen","name":"","type":"other","credibility":3},{"url":"https://www.bankinfosecurity.com/cryptohack-roundup-swissborgs-41m-exploit-a-29417","name":"","type":"other","credibility":3},{"url":"https://www.ainvest.com/news/swissborg-41m-loss-exposes-defi-partner-risk-2509/","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2017","event":"SwissBorg founded in Lausanne, Switzerland by Cyrus Fazel and Anthony Lesoismier.","source":"","date_original":"2017-01-01"},{"date":"2022","event":"SwissBorg Solutions OÜ registered with France's AMF as a Digital Asset Service Provider (DASP) under number E2022-034.","source":"","date_original":"2022-01-01"},{"date":"2024-06","event":"SwissBorg publishes Proof of Liabilities audit portal using Merkle-tree cryptographic verification.","source":"","date_original":"2024-06-01"},{"date":"2025-08-31","event":"SwissBorg uses Kiln Dashboard to unstake 975 SOL. Undetected by SwissBorg's custody signers, a malicious transaction embedded in the Kiln API response reassigns withdrawal authority for multiple high-value Solana stake accounts to an attacker-controlled address.","source":""},{"date":"2025-09-08","event":"Attacker executes the drain: 192,600 SOL (~$41.5 million) stolen across eight transactions in under three minutes. Kiln detects unauthorized activity on its platform.","source":""},{"date":"2025-09-09","event":"SwissBorg publicly confirms the breach. CEO Cyrus Fazel pledges full user reimbursement from treasury. SOL Earn redemptions suspended. Chainalysis, ZachXBT, SEAL, and Fireblocks engaged.","source":""},{"date":"2025-10-07","event":"Kiln publishes formal incident post-mortem identifying GitHub access token compromise as initial entry point, with Sygnia forensics findings. Services re-enabled with six security enhancements.","source":""},{"date":"2026-03-11","event":"SwissBorg's French entity Blocknodes SAS receives full MiCA authorization from France's AMF, enabling EU-wide regulated crypto services.","source":""}],"sources_used":[{"url":"https://help.swissborg.com/hc/en-gb/articles/360009028418-What-is-SwissBorg","name":"","type":"other","archive_url":"http://web.archive.org/web/20250910074955/https://help.swissborg.com/hc/en-gb/articles/360009028418-What-is-SwissBorg","credibility":3,"archive_timestamp":"2025-09-10T07:49:55+00:00"},{"url":"https://www.venturelab.swiss/SwissBorg-CEO-Cyrus-Fazel-We-enable-everyone-to-enjoy-the-world-of-decentralized-finance-regardless-of-their-investment-interests","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829232021/https://www.venturelab.swiss/SwissBorg-CEO-Cyrus-Fazel-We-enable-everyone-to-enjoy-the-world-of-decentralized-finance-regardless-of-their-investment-interests","credibility":3,"archive_timestamp":"2026-08-29T23:20:21+00:00"},{"url":"https://en.cryptonomist.ch/2024/07/23/swissborg-the-swiss-crypto-exchange-open-to-everyone/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829225526/https://en.cryptonomist.ch/2024/07/23/swissborg-the-swiss-crypto-exchange-open-to-everyone/","credibility":3,"archive_timestamp":"2026-08-29T22:55:26+00:00"},{"url":"https://www.kiln.fi/post/re-enablement-of-kiln-services-and-security-incident-information","name":"","type":"other","archive_url":"http://web.archive.org/web/20260311154929/https://www.kiln.fi/post/re-enablement-of-kiln-services-and-security-incident-information","credibility":3,"archive_timestamp":"2026-03-11T15:49:29+00:00"},{"url":"https://harrydonnelly.substack.com/p/swissborgkiln-exploit-breakdown","name":"","type":"other","archive_url":"http://web.archive.org/web/20250915145012/https://harrydonnelly.substack.com/p/swissborgkiln-exploit-breakdown","credibility":3,"archive_timestamp":"2025-09-15T14:50:12+00:00"},{"url":"https://www.web3isgoinggreat.com/?id=swissborg-exploit","name":"","type":"other","archive_url":"http://web.archive.org/web/20260308010452/https://www.web3isgoinggreat.com/?id=swissborg-exploit","credibility":3,"archive_timestamp":"2026-03-08T01:04:52+00:00"},{"url":"https://protos.com/swissborg-ceo-blames-41m-loss-on-staking-partner-kiln/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260526035926/https://protos.com/swissborg-ceo-blames-41m-loss-on-staking-partner-kiln/","credibility":3,"archive_timestamp":"2026-05-26T03:59:26+00:00"},{"url":"https://swissborg.com/blog/sol-earn-incident-swissborg-recovery","name":"","type":"other","archive_url":"http://web.archive.org/web/20260511055038/https://swissborg.com/blog/sol-earn-incident-swissborg-recovery","credibility":3,"archive_timestamp":"2026-05-11T05:50:38+00:00"},{"url":"https://therecord.media/swissborg-platform-solana-cryptocurrency-stolen","name":"","type":"other","archive_url":"http://web.archive.org/web/20260520194341/https://therecord.media/swissborg-platform-solana-cryptocurrency-stolen","credibility":3,"archive_timestamp":"2026-05-20T19:43:41+00:00"},{"url":"https://thecryptobasic.com/2025/09/09/swissborg-to-compensate-users-after-41m-solana-staking-hack/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260516055102/https://thecryptobasic.com/2025/09/09/swissborg-to-compensate-users-after-41m-solana-staking-hack/","credibility":3,"archive_timestamp":"2026-05-16T05:51:02+00:00"},{"url":"https://www.fireblocks.com/blog/case-for-native-staking-kiln-incident","name":"","type":"other","archive_url":"http://web.archive.org/web/20260509133138/https://www.fireblocks.com/blog/case-for-native-staking-kiln-incident","credibility":3,"archive_timestamp":"2026-05-09T13:31:38+00:00"},{"url":"https://help.swissborg.com/hc/en-gb/articles/360015167634-SwissBorg-Legal-structure-jurisdiction-and-licenses","name":"","type":"other","archive_url":"http://web.archive.org/web/20250714030609/https://help.swissborg.com/hc/en-gb/articles/360015167634-SwissBorg-Legal-structure-jurisdiction-and-licenses","credibility":3,"archive_timestamp":"2025-07-14T03:06:09+00:00"},{"url":"https://swissborg.com/blog/swissborg-secures-mica-approval-from-french-amf","name":"","type":"other","archive_url":"http://web.archive.org/web/20260626101418/https://swissborg.com/blog/swissborg-secures-mica-approval-from-french-amf","credibility":3,"archive_timestamp":"2026-06-26T10:14:18+00:00"},{"url":"https://news.bitcoin.com/swissborg-secures-mica-license-from-frances-amf-expanding-regulated-crypto-services-across-eu/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260315211145/https://news.bitcoin.com/swissborg-secures-mica-license-from-frances-amf-expanding-regulated-crypto-services-across-eu/","credibility":3,"archive_timestamp":"2026-03-15T21:11:45+00:00"},{"url":"https://www.coindesk.com/press-release/2026/03/12/swissborg-secures-mica-approval-from-france-s-financial-markets-authority","name":"","type":"other","archive_url":"http://web.archive.org/web/20260316225328/https://www.coindesk.com/press-release/2026/03/12/swissborg-secures-mica-approval-from-france-s-financial-markets-authority","credibility":3,"archive_timestamp":"2026-03-16T22:53:28+00:00"},{"url":"https://academy.swissborg.com/en/learn/mpc-keyless-technology-keeping-your-crypto-secure","name":"","type":"other","archive_url":"http://web.archive.org/web/20260411211143/https://academy.swissborg.com/en/learn/mpc-keyless-technology-keeping-your-crypto-secure","credibility":3,"archive_timestamp":"2026-04-11T21:11:43+00:00"},{"url":"https://swissborg.com/proof-of-liabilities/audits","name":"","type":"other","archive_url":"http://web.archive.org/web/20260511053734/https://swissborg.com/proof-of-liabilities/audits","credibility":3,"archive_timestamp":"2026-05-11T05:37:34+00:00"},{"url":"https://swissborg.com/blog/proof-of-liabilities","name":"","type":"other","archive_url":"http://web.archive.org/web/20260613060504/https://swissborg.com/blog/proof-of-liabilities","credibility":3,"archive_timestamp":"2026-06-13T06:05:04+00:00"},{"url":"https://github.com/SwissBorg/proof-of-liabilities","name":"","type":"other","archive_url":"http://web.archive.org/web/20250910194942/https://github.com/SwissBorg/proof-of-liabilities","credibility":3,"archive_timestamp":"2025-09-10T19:49:42+00:00"},{"url":"https://swissborg.com/blog/swissborg-security-and-trust","name":"","type":"other","archive_url":"http://web.archive.org/web/20260511054448/https://swissborg.com/blog/swissborg-security-and-trust","credibility":3,"archive_timestamp":"2026-05-11T05:44:48+00:00"},{"url":"https://www.bankinfosecurity.com/cryptohack-roundup-swissborgs-41m-exploit-a-29417","name":"","type":"other","archive_url":"http://web.archive.org/web/20250911220505/https://www.bankinfosecurity.com/cryptohack-roundup-swissborgs-41m-exploit-a-29417","credibility":3,"archive_timestamp":"2025-09-11T22:05:05+00:00"},{"url":"https://www.ainvest.com/news/swissborg-41m-loss-exposes-defi-partner-risk-2509/","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:21.35917+00:00","updated_at":"2026-08-29T23:26:12.056272+00:00"}}