Fact-check findings
What an automated fact-checker found when it re-read Swan Treasury (STY Token) against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
disputed
1 claimThe reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.
- #25[disputed][awaiting moderator]in the cited sources
“https://coindesk.cc/swan-treasury-loses-625k-after-signer-key-leak-enables-discounted-sty-purchases-94385.html”
reviewerA source titled 'Swan Treasury loses $625K after signer key leak enables discounted STY purchases — CoinDesk (coindesk.cc)' is included in sources_used as a CoinDesk report.This source is listed with the same credibility rating (2) as legitimate tier-2 outlets and labeled 'CoinDesk,' but coindesk.cc has no verified affiliation with the real CoinDesk (coindesk.com); it is not cited in any section body. Its inclusion under the CoinDesk name risks conferring unearned credibility.
unverifiable
1 claimNo source the reviewer could reach confirms or contradicts the claim.
- #14[unverifiable][awaiting moderator]in section: July 2026 Signer Key Exploit
“Security researchers characterize hardcoding a privileged signer address in a smart contract as a fundamental operational security failure, as any compromise of the associated private key gives an attacker unrestricted ability to forge protocol-level authorization.”
reviewerSecurity researchers characterize hardcoding a privileged signer address as a fundamental operational security failure.The underlying security-design point is plausible and widely accepted in the industry, but the specific attribution to unnamed 'security researchers' is not traceable to either cited source and could not be independently verified as a sourced quote versus the page's own analysis.
confirmed
23 claimsThe cited evidence supports the claim as written.
- #1[confirmed][no action needed]in the summary
“Swan Treasury is a BNB Chain privacy-finance protocol offering anonymous identity, private transactions, dark pool liquidity, on-chain vaults, and a node network, with the STY token serving as its central ecosystem passkey.”
reviewerSwan Treasury is a BNB Chain privacy-finance protocol with anonymous identity, private transactions, dark pool liquidity, vaults, and a node network, with STY as its ecosystem passkey.Description matches the source's characterization of Swan Treasury and STY's function, allowing for reasonable paraphrase. - #2[confirmed][no action needed]in the summary
“On July 30, 2026, the protocol suffered an estimated $625,000 loss after an attacker exploited a compromised off-chain signer private key that was hardcoded as the _signer address in the ZhaiquanBuy smart contract.”
reviewerOn July 30, 2026, Swan Treasury suffered an estimated $625,000 loss after a compromised off-chain signer key hardcoded as _signer in the ZhaiquanBuy contract was exploited.Date, dollar figure, contract name and mechanism are all corroborated by both cited outlets, which attribute the technical finding to Defimon Alerts. - #3[confirmed][no action needed]in the summary
“As of August 20, 2026, Swan Treasury has not published a post-mortem or explained how the signer key was exposed, leaving users without clarity on the protocol's current security posture.”
reviewerAs of August 20, 2026, Swan Treasury had not published a post-mortem or explained how the signer key was exposed.The page's own source_url attribution ('verified via web search') is a weak citation format, but independent search corroborates the underlying fact that no disclosure has been published. - #4[confirmed][no action needed]in section: Protocol Overview
“Swan Treasury describes itself as a privacy-focused financial infrastructure built for the 'Black Swan era' on BNB Chain.”
reviewerSwan Treasury describes itself as privacy-focused financial infrastructure for the 'Black Swan era' on BNB Chain.Direct match to source framing. - #5[confirmed][no action needed]in section: Protocol Overview
“The platform integrates several modules: Swan ID for anonymous identity establishment, Privacy Swap for confidential transactions, Dark Pool for hidden liquidity access, Shielded Vault for on-chain treasury management, and a Node Network for distributed consensus.”
reviewerThe platform integrates Swan ID, Privacy Swap, Dark Pool, Shielded Vault, and a Node Network modules.Module list and descriptions are a faithful summary of the source. - #6[confirmed][no action needed]in section: Protocol Overview
“According to a KuCoin news flash published June 21, 2026 and attributed to MetaEra, the protocol also integrates a liquidity reserve, automated market making, benefit bond vault, and hashrate contract pool.”
reviewerPer the KuCoin/MetaEra flash (June 21, 2026), the protocol also integrates a liquidity reserve, automated market making, benefit bond vault, and hashrate contract pool.Page substitutes descriptive terms for the source's proper-noun feature names; substance is unchanged and traceable to the source. - #7[confirmed][no action needed]in section: Protocol Overview
“Planned roadmap items include RWA Treasury, an AI Treasury Agent, DePIN Node services, Swan DEX, and Privacy Vault modules.”
reviewerPlanned roadmap items include RWA Treasury, an AI Treasury Agent, DePIN Node services, Swan DEX, and Privacy Vault modules.Direct match. - #8[confirmed][no action needed]in section: Protocol Overview
“No team members, founders, or organizational details have been publicly disclosed.”
reviewerNo team members, founders, or organizational details have been publicly disclosed.Negative claim corroborated by absence of any named individuals across all sources reviewed. - #9[confirmed][no action needed]in section: July 2026 Signer Key Exploit
“According to reporting by crypto.news and cryptonews.net, both citing analysis by blockchain security firm Defimon Alerts, the root cause was the compromise of an off-chain signer private key that was hardcoded as the _signer address (identified as 0xdEb4…8284) inside the ZhaiquanBuy contract.”
reviewerOn July 30, 2026, Swan Treasury suffered an estimated $625,000 loss in a smart contract exploit on BNB Chain, root-caused to a hardcoded off-chain signer key (0xdEb4…8284) in the ZhaiquanBuy contract.Partial address 0xdEb4…8284 is directly sourced to cryptonews.net. - #10[confirmed][no action needed]in section: July 2026 Signer Key Exploit
“The buy() function calculates how many STY tokens a user receives based on a signed discount parameter; by forging a signature with the discount parameter set to 1, the attacker was able to purchase STY at approximately one-hundredth of its intended market price (approximately $2.87 per token at the time of the incident).”
reviewerBy forging a signature with the discount parameter set to 1, the attacker purchased STY at roughly 1/100th of its intended price (~$2.87/token).Both outlets independently report the same discount-parameter mechanism and price. - #11[confirmed][no action needed]in section: July 2026 Signer Key Exploit
“The attacker funded the attack using a PancakeSwap flash loan of approximately 19,700 USDT, with which they acquired approximately 687,000 STY tokens at the deeply discounted rate.”
reviewerThe attacker funded the attack with a PancakeSwap flash loan of ~19,700 USDT and acquired ~687,000 STY tokens.Consistent across both sources. - #12[confirmed][no action needed]in section: July 2026 Signer Key Exploit
“The attacker also forged valid signatures for the protocol's claim() and transfer() functions on related contracts, then sold the accumulated tokens into the STY/USDT liquidity pool, realizing a profit of approximately $625,000 USDT.”
reviewerThe attacker forged signatures for claim() and transfer() and sold tokens into the STY/USDT pool for a ~$625,000 profit.Matches both cited reports. - #13[confirmed][no action needed]in section: July 2026 Signer Key Exploit
“Defimon Alerts stated that 'every ecrecover operation observed during the exploit resolved to the protocol's hardcoded signer address,' confirming that the private key itself was compromised rather than any flaw in the signature verification logic.”
reviewerDefimon Alerts stated that every ecrecover operation observed during the exploit resolved to the protocol's hardcoded signer address.The quoted fragment is verbatim from the Defimon Alerts finding as reported by crypto.news. - #15[confirmed][no action needed]in section: Operational Security Failure: Hardcoded Signer
“No public information is available regarding what key management practices Swan Treasury employed, or how the attacker obtained the private key.”
reviewerNo public information is available regarding what key management practices Swan Treasury employed, or how the attacker obtained the private key.Directly supported. - #16[confirmed][no action needed]in section: Operational Security Failure: Hardcoded Signer
“As of August 20, 2026, Swan Treasury has not published a post-mortem, incident report, or any public explanation of the key exposure.”
reviewerAs of August 20, 2026, Swan Treasury has not published a post-mortem, incident report, or any public explanation of the key exposure.Corroborated by independent search performed at time of review. - #17[confirmed][no action needed]in section: Transparency and Post-Incident Communication
“As of August 20, 2026 — approximately three weeks after the exploit — Swan Treasury has not published a post-mortem, security advisory, or any public statement explaining how the signer key was exposed, what remediation steps have been taken, or whether user funds are at further risk.”
reviewerAs of August 20, 2026 — approximately three weeks after the exploit — Swan Treasury has not published a post-mortem, security advisory, or public statement on remediation or further risk.Three-week gap between July 30 exploit and August 20 checkpoint is arithmetically correct. - #18[confirmed][no action needed]in section: Transparency and Post-Incident Communication
“No team members are publicly identified, making it impossible for users or researchers to seek accountability through conventional channels.”
reviewerNo team members are publicly identified, making it impossible for users or researchers to seek accountability through conventional channels.Consistent with anonymous-team finding elsewhere on the page. - #19[confirmed][no action needed]in section: Anonymous Team and Disclosure Risks
“Swan Treasury does not publicly disclose the identities of its founders, developers, or operators.”
reviewerSwan Treasury does not publicly disclose the identities of its founders, developers, or operators.Confirmed via absence of any named individuals in the only substantive source about the project's origins. - #20[confirmed][no action needed]in section: Anonymous Team and Disclosure Risks
“No team page, LinkedIn profiles, or named individuals appear in available reporting or the KuCoin launch announcement attributed to MetaEra.”
reviewerNo team page, LinkedIn profiles, or named individuals appear in available reporting or the KuCoin launch announcement attributed to MetaEra.Consistent with independent search. - #21[confirmed][no action needed]in the timeline
“Swan Treasury publishes a launch announcement for its privacy-finance infrastructure on BNB Chain, with the STY token described as the central ecosystem passkey. No team members are identified.”
reviewerSwan Treasury publishes a launch announcement on June 21, 2026 describing STY as the central ecosystem passkey, with no team members identified.Timeline date matches article publication date. - #22[confirmed][no action needed]in the timeline
“Attacker exploits a compromised off-chain signer private key hardcoded in the ZhaiquanBuy contract. Using a PancakeSwap flash loan of approximately 19,700 USDT, the attacker forges discount signatures and purchases approximately 687,000 STY tokens at roughly 1/100th of intended price, then sells them into the STY/USDT pool for approximately $625,000 USDT profit.”
reviewerOn July 30, 2026 the attacker exploited the compromised signer key, used a ~19,700 USDT PancakeSwap flash loan, acquired ~687,000 STY at ~1/100th price, and sold for ~$625,000 profit.Timeline date (2026-07-30) matches cryptonews.net's explicit exploit date. - #23[confirmed][no action needed]in the timeline
“Blockchain security firm Defimon Alerts publicly reports the exploit. crypto.news and cryptonews.net cover the incident. Swan Treasury has made no public statement.”
reviewerDefimon Alerts publicly reports the exploit on July 31, 2026; crypto.news and cryptonews.net cover it; Swan Treasury made no public statement.Both outlets' publication timestamps fall on July 31, 2026, matching the timeline date. - #24[confirmed][no action needed]in the timeline
“As of this date, Swan Treasury has not published a post-mortem, explanation of how the signer key was exposed, or any remediation disclosure. The protocol's security posture remains unverified.”
reviewerAs of August 20, 2026, Swan Treasury has not published a post-mortem, explanation of the signer key exposure, or remediation disclosure.Corroborated by archive timestamp and independent search.