← Swan Treasury (STY Token)4 decisions on this page
Audit log
Every state-changing event for Swan Treasury (STY Token): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-20 17:03:03ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 443,509,659
- sig
2xfsKHBRCiQ7…VMARL6nAexplorer ↗- hash
J9moGqUh6v98…iiqEa9Casha256 → base58
verifying row…full verify ↗canonical bytes (10661 B) ▸
{"actor":"system:backfill","investigation_id":"c34f3c80-b857-491a-a7d3-690b042fc2ed","kind":"publish","page_slug":"swan-treasury-sty-token","published_at":"2026-08-20T17:03:03.211Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Swan Treasury (STY Token)","sections":[{"content":"Swan Treasury describes itself as a privacy-focused financial infrastructure built for the 'Black Swan era' on BNB Chain. The platform integrates several modules: Swan ID for anonymous identity establishment, Privacy Swap for confidential transactions, Dark Pool for hidden liquidity access, Shielded Vault for on-chain treasury management, and a Node Network for distributed consensus. The STY token serves as the central ecosystem passkey, connecting user participation, transaction flows, vault rights, node contributions, and governance. According to a KuCoin news flash published June 21, 2026 and attributed to MetaEra, the protocol also integrates a liquidity reserve, automated market making, benefit bond vault, and hashrate contract pool. Planned roadmap items include RWA Treasury, an AI Treasury Agent, DePIN Node services, Swan DEX, and Privacy Vault modules. No team members, founders, or organizational details have been publicly disclosed.","heading":"Protocol Overview","severity":"medium","sources":[{"credibility":2,"name":"Swan Treasury Launches Privacy Financial Infrastructure for the Black Swan Era — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/swan-treasury-launches-privacy-financial-infrastructure-for-black-swan-era"}]},{"content":"On July 30, 2026, Swan Treasury suffered an estimated $625,000 loss in a smart contract exploit on BNB Chain. According to reporting by crypto.news and cryptonews.net, both citing analysis by blockchain security firm Defimon Alerts, the root cause was the compromise of an off-chain signer private key that was hardcoded as the _signer address (identified as 0xdEb4…8284) inside the ZhaiquanBuy contract.\n\nThe attacker used the compromised key to generate valid signatures and manipulate the contract's buy() function. The buy() function calculates how many STY tokens a user receives based on a signed discount parameter; by forging a signature with the discount parameter set to 1, the attacker was able to purchase STY at approximately one-hundredth of its intended market price (approximately $2.87 per token at the time of the incident).\n\nThe attacker funded the attack using a PancakeSwap flash loan of approximately 19,700 USDT, with which they acquired approximately 687,000 STY tokens at the deeply discounted rate. The attacker also forged valid signatures for the protocol's claim() and transfer() functions on related contracts, then sold the accumulated tokens into the STY/USDT liquidity pool, realizing a profit of approximately $625,000 USDT.\n\nDefimon Alerts stated that 'every ecrecover operation observed during the exploit resolved to the protocol's hardcoded signer address,' confirming that the private key itself was compromised rather than any flaw in the signature verification logic. Security researchers characterize hardcoding a privileged signer address in a smart contract as a fundamental operational security failure, as any compromise of the associated private key gives an attacker unrestricted ability to forge protocol-level authorization.","heading":"July 2026 Signer Key Exploit","severity":"critical","sources":[{"credibility":2,"name":"Swan Treasury loses $625K after signer key leak enables discounted STY purchases — crypto.news","type":"news_article","url":"https://crypto.news/swan-treasury-loses-625k-after-signer-key-leak-enables-discounted-sty-purchases/"},{"credibility":2,"name":"Swan Treasury loses $625K after signer key leak enables discounted STY purchases — cryptonews.net","type":"news_article","url":"https://cryptonews.net/news/security/33229560/"}]},{"content":"The core architectural vulnerability enabling the July 30, 2026 exploit was the use of a single, hardcoded off-chain signer address (_signer) in the ZhaiquanBuy contract to authorize discounted token purchases. This design creates a single point of failure: if the private key associated with that address is ever exposed — through server compromise, poor key management, code repository leaks, or insider access — an attacker gains the ability to forge any signature the contract accepts, with no on-chain mechanism to detect or prevent misuse before funds are drained.\n\nStandard smart contract security practice calls for multi-signature authorization schemes, hardware security modules for key custody, regular key rotation, and on-chain rate limiting or circuit breakers to cap damage in the event of a key compromise. No public information is available regarding what key management practices Swan Treasury employed, or how the attacker obtained the private key. As of August 20, 2026, Swan Treasury has not published a post-mortem, incident report, or any public explanation of the key exposure.","heading":"Operational Security Failure: Hardcoded Signer","severity":"critical","sources":[{"credibility":2,"name":"Swan Treasury loses $625K after signer key leak enables discounted STY purchases — crypto.news","type":"news_article","url":"https://crypto.news/swan-treasury-loses-625k-after-signer-key-leak-enables-discounted-sty-purchases/"},{"credibility":2,"name":"Swan Treasury loses $625K after signer key leak enables discounted STY purchases — cryptonews.net","type":"news_article","url":"https://cryptonews.net/news/security/33229560/"}]},{"content":"As of August 20, 2026 — approximately three weeks after the exploit — Swan Treasury has not published a post-mortem, security advisory, or any public statement explaining how the signer key was exposed, what remediation steps have been taken, or whether user funds are at further risk. No team members are publicly identified, making it impossible for users or researchers to seek accountability through conventional channels. The absence of post-incident disclosure is a material transparency concern for any users still interacting with the protocol.","heading":"Transparency and Post-Incident Communication","severity":"high","sources":[{"credibility":2,"name":"Swan Treasury loses $625K after signer key leak enables discounted STY purchases — crypto.news","type":"news_article","url":"https://crypto.news/swan-treasury-loses-625k-after-signer-key-leak-enables-discounted-sty-purchases/"}]},{"content":"Swan Treasury does not publicly disclose the identities of its founders, developers, or operators. No team page, LinkedIn profiles, or named individuals appear in available reporting or the KuCoin launch announcement attributed to MetaEra. Anonymous teams in DeFi are not inherently disqualifying, but the combination of anonymous operators, a confirmed $625,000 exploit, and the absence of any post-incident communication substantially increases the risk profile for users considering interaction with the protocol.","heading":"Anonymous Team and Disclosure Risks","severity":"medium","sources":[{"credibility":2,"name":"Swan Treasury Launches Privacy Financial Infrastructure for the Black Swan Era — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/swan-treasury-launches-privacy-financial-infrastructure-for-black-swan-era"}]}],"sources_used":[{"credibility":2,"name":"Swan Treasury loses $625K after signer key leak enables discounted STY purchases — crypto.news","type":"news_article","url":"https://crypto.news/swan-treasury-loses-625k-after-signer-key-leak-enables-discounted-sty-purchases/"},{"credibility":2,"name":"Swan Treasury loses $625K after signer key leak enables discounted STY purchases — cryptonews.net","type":"news_article","url":"https://cryptonews.net/news/security/33229560/"},{"credibility":2,"name":"Swan Treasury loses $625K after signer key leak enables discounted STY purchases — CoinDesk (coindesk.cc)","type":"news_article","url":"https://coindesk.cc/swan-treasury-loses-625k-after-signer-key-leak-enables-discounted-sty-purchases-94385.html"},{"credibility":2,"name":"Swan Treasury Launches Privacy Financial Infrastructure for the Black Swan Era — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/swan-treasury-launches-privacy-financial-infrastructure-for-black-swan-era"}],"summary":"Swan Treasury is a BNB Chain privacy-finance protocol offering anonymous identity, private transactions, dark pool liquidity, on-chain vaults, and a node network, with the STY token serving as its central ecosystem passkey. On July 30, 2026, the protocol suffered an estimated $625,000 loss after an attacker exploited a compromised off-chain signer private key that was hardcoded as the _signer address in the ZhaiquanBuy smart contract. As of August 20, 2026, Swan Treasury has not published a post-mortem or explained how the signer key was exposed, leaving users without clarity on the protocol's current security posture.","timeline":[{"date":"2026-06-21","event":"Swan Treasury publishes a launch announcement for its privacy-finance infrastructure on BNB Chain, with the STY token described as the central ecosystem passkey. No team members are identified.","source":"KuCoin (MetaEra attribution)","source_url":"https://www.kucoin.com/news/flash/swan-treasury-launches-privacy-financial-infrastructure-for-black-swan-era"},{"date":"2026-07-30","event":"Attacker exploits a compromised off-chain signer private key hardcoded in the ZhaiquanBuy contract. Using a PancakeSwap flash loan of approximately 19,700 USDT, the attacker forges discount signatures and purchases approximately 687,000 STY tokens at roughly 1/100th of intended price, then sells them into the STY/USDT pool for approximately $625,000 USDT profit.","source":"crypto.news, cryptonews.net (citing Defimon Alerts)","source_url":"https://crypto.news/swan-treasury-loses-625k-after-signer-key-leak-enables-discounted-sty-purchases/"},{"date":"2026-07-31","event":"Blockchain security firm Defimon Alerts publicly reports the exploit. crypto.news and cryptonews.net cover the incident. Swan Treasury has made no public statement.","source":"crypto.news","source_url":"https://crypto.news/swan-treasury-loses-625k-after-signer-key-leak-enables-discounted-sty-purchases/"},{"date":"2026-08-20","event":"As of this date, Swan Treasury has not published a post-mortem, explanation of how the signer key was exposed, or any remediation disclosure. The protocol's security posture remains unverified.","source":"Absence of public disclosure — verified via web search","source_url":"https://cryptonews.net/news/security/33229560/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 9e426c2e-c7b8-45d8-945e-881d9e254ea5 - #2reviewby reviewerreviewer2026-08-25 07:20:29ZScore: 18 → 18 (no score change)The page's core factual claims about the July 30, 2026 Swan Treasury exploit (mechanism, dollar amounts, flash-loan size, token counts, and the Defimon Alerts quote) are well-supported by two independently reviewed, mutually consistent articles and corroborated by additional web search; the direct quotation is accurate and correctly attributed. Minor issues found: one paraphrase drift ('vault rights' vs. the source's 'treasury rights'), one unattributed editorial generalization presented as sourced ('security researchers characterize...'), and a citation-freshness mismatch in two sections where 'as of August 20' claims are footnoted to July 31-dated articles rather than to the page's own later verification (only the timeline entry discloses that methodology transparently).anchoranchored
- chain
- ●mainnet-betaslot 443,512,216
- sig
4sLdD6QRtLkX…2n9ffDnQexplorer ↗- hash
7WRzPjPsxCGt…JwMxw5ZKsha256 → base58
verifying row…full verify ↗canonical bytes (1142 B) ▸
{"actor":"reviewer","decided_at":"2026-08-25T07:20:29.693Z","decision":"review","investigation_id":"c34f3c80-b857-491a-a7d3-690b042fc2ed","new_score":18,"page_slug":"swan-treasury-sty-token","prev_score":18,"reason":"The page's core factual claims about the July 30, 2026 Swan Treasury exploit (mechanism, dollar amounts, flash-loan size, token counts, and the Defimon Alerts quote) are well-supported by two independently reviewed, mutually consistent articles and corroborated by additional web search; the direct quotation is accurate and correctly attributed. Minor issues found: one paraphrase drift ('vault rights' vs. the source's 'treasury rights'), one unattributed editorial generalization presented as sourced ('security researchers characterize...'), and a citation-freshness mismatch in two sections where 'as of August 20' claims are footnoted to July 31-dated articles rather than to the page's own later verification (only the timeline entry discloses that methodology transparently).","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision 6f4f381f-3bce-4cc1-940c-fb84c50ef656 - #3review reviseby judgejudge2026-08-25 07:20:30ZScore: 18 → 10 (-8)No claim on this page was found to be disputed — the reviewer independently fetched all cited articles, found them mutually consistent, and confirmed the page's direct quotation is verbatim and correctly attributed. The revision is triggered by two high-priority coverage gaps rather than by any factual error: the page never cites on-chain transaction hashes or wallet addresses that would let readers independently verify the exploit (coverage_gaps[0]), and it does not say whether Swan Treasury is still operating or whether liquidity has been pulled since the exploit, which matters for assessing whether the risk is ongoing (coverage_gaps[2]). Four claims were only partially supported: a minor paraphrase where the page says 'vault rights' but the source says 'treasury rights' (claim_findings[6]), an editorializing line attributed to unnamed 'security researchers' with no matching source quote (claim_findings[16]), and two 'as of August 20' statements footnoted only to July 31-dated articles, a citation-freshness mismatch the reviewer independently corroborated by search (claim_findings[19], claim_findings[20]). Separately, the source list includes coindesk.cc, an aggregator/imitation domain distinct from coindesk.com, which is not cited by any claim but its mere presence in a fact-check source list on a platform built around crypto risk and impersonation is worth flagging and removing.anchoranchored
- chain
- ●mainnet-betaslot 443,512,219
- sig
2yBqFhuEWEe9…VFRAEBiyexplorer ↗- hash
BRpLvgbhrSt2…qxhKNmLXsha256 → base58
verifying row…full verify ↗canonical bytes (1769 B) ▸
{"actor":"judge","decided_at":"2026-08-25T07:20:29.693Z","decision":"review_revise","investigation_id":"c34f3c80-b857-491a-a7d3-690b042fc2ed","new_score":10,"page_slug":"swan-treasury-sty-token","prev_score":18,"reason":"No claim on this page was found to be disputed — the reviewer independently fetched all cited articles, found them mutually consistent, and confirmed the page's direct quotation is verbatim and correctly attributed. The revision is triggered by two high-priority coverage gaps rather than by any factual error: the page never cites on-chain transaction hashes or wallet addresses that would let readers independently verify the exploit (coverage_gaps[0]), and it does not say whether Swan Treasury is still operating or whether liquidity has been pulled since the exploit, which matters for assessing whether the risk is ongoing (coverage_gaps[2]). Four claims were only partially supported: a minor paraphrase where the page says 'vault rights' but the source says 'treasury rights' (claim_findings[6]), an editorializing line attributed to unnamed 'security researchers' with no matching source quote (claim_findings[16]), and two 'as of August 20' statements footnoted only to July 31-dated articles, a citation-freshness mismatch the reviewer independently corroborated by search (claim_findings[19], claim_findings[20]). Separately, the source list includes coindesk.cc, an aggregator/imitation domain distinct from coindesk.com, which is not cited by any claim but its mere presence in a fact-check source list on a platform built around crypto risk and impersonation is worth flagging and removing.","score_delta":-8,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision 7f45fdd3-6ff2-4810-9c67-b373e92ad8c2 - #4reviewby reviewerreviewer2026-09-09 03:05:21ZScore: 10 → 10 (no score change)Findings-only fact-check (retroactive anchor of stored findings)anchoranchored
- chain
- ●mainnet-betaslot 445,507,214
- sig
5k5eQgdiHxGu…JPu2LndAexplorer ↗- hash
69zqvaNeM7sU…TyQqR2Sisha256 → base58
verifying row…full verify ↗canonical bytes (715 B) ▸
{"actor":"reviewer","artifact_identity":"a36e09e81af1420a8681a9e151d70cd9","decided_at":"2026-09-07T12:29:00.32985+00:00","decision":"review","findings_count":25,"findings_rows_hash":"dc1d9404ed778b3c33c968ee889c6af172fa1a0558a6e919f190e2f379fe40e6","investigation_id":"c34f3c80-b857-491a-a7d3-690b042fc2ed","mode":"findings_only_retroactive","new_score":10,"page_content_hash":"20f38110ad350b799628d28a15e9196f634c683d5385e61fc2fb0c5383b34138","page_slug":"swan-treasury-sty-token","prev_score":10,"reason":"Findings-only fact-check (retroactive anchor of stored findings)","score_delta":0,"sequence_num":4,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}Verify offline (run on your own machine)python -m src.verify_decision e83c4cba-ae47-4e5b-b5fc-216580e06346
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.