{
    "id": 48575,
    "date": "2025-09-09T09:55:01",
    "date_gmt": "2025-09-09T02:55:01",
    "guid": {
        "rendered": "https:\/\/hbbgroup.net\/swissborg-hacked-for-41m-sol-after-third-party-api-compromise\/"
    },
    "modified": "2025-09-09T09:55:01",
    "modified_gmt": "2025-09-09T02:55:01",
    "slug": "swissborg-hacked-for-41m-sol-after-third-party-api-compromise",
    "status": "publish",
    "type": "post",
    "link": "https:\/\/hbbgroup.net\/en_us\/swissborg-hacked-for-41m-sol-after-third-party-api-compromise\/",
    "title": {
        "rendered": "SwissBorg hacked for $41M SOL after third-party API compromise"
    },
    "content": {
        "rendered": "<div data-gtm-locator=\"articles\" data-v-43e640e6>\n<article id=\"article-214546\" data-v-43e640e6>\n<p itemprop=\"description\" data-v-43e640e6> Hackers drained 193,000 SOL from SwissBorg\u2019s Solana Earn program after a Kiln API was compromised, affecting 1% of users and 2% of assets. <\/p>\n<div data-v-43e640e6><picture><source media=\"(min-width: 1200px)\" ><source media=\"(min-width: 992px)\" ><source media=\"(min-width: 768px)\" ><source media=\"(min-width: 480px)\" ><img  loading=\"eager\" fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/cdn-cgi\/image\/format=auto,onerror=redirect,quality=90,width=1434\/https:\/\/s3.cointelegraph.com\/uploads\/2024-11\/01937771-ffda-7b37-9bb7-b0048a4b91d0\" alt=\"SwissBorg hacked for $41M SOL after third-party API compromise\"><\/picture><\/div>\n<div data-v-43e640e6>\n<div data-v-43e640e6>\n<p>SwissBorg, a Switzerland-based crypto wealth management platform, said hackers exploited a vulnerability in the API of its staking partner Kiln, draining about 193,000 Solana tokens from its Earn program.\u00a0<\/p>\n<p>The SwissBorg app and other Earn products were not impacted by the hack, the company wrote in a post on <a href=\"https:\/\/x.com\/swissborg\/status\/1965123506477359471\" rel=\"nofollow noopener\" target=\"_blank\" title=\"https:\/\/x.com\/swissborg\/status\/1965123506477359471\">X<\/a>. The stolen SOL (<a href=\"http:\/\/cointelegraph.com\/solana-price-index\">SOL<\/a>) tokens were worth roughly $41 million at time of writing. <\/p>\n<figure><img decoding=\"async\" alt src=\"https:\/\/s3.cointelegraph.com\/uploads\/2025-09\/01992b1f-c5bf-7977-99b3-37134b7b18aa\" title><figcaption><em>Source: <\/em><a href=\"https:\/\/x.com\/swissborg\/status\/1965123506477359471\" rel=\"nofollow noopener\" target=\"_blank\" title=\"https:\/\/x.com\/swissborg\/status\/1965123506477359471\"><em>Swissborg<\/em><\/a><em> <\/em><\/figcaption><\/figure>\n<p>The breach originated with Kiln, a staking infrastructure provider that powers yield products on blockchains such as Solana and Ethereum.<\/p>\n<p>An\u00a0API attack\u00a0targets the software \u201cbridge\u201d that connects two systems. In SwissBorg\u2019s case, its app relied on Kiln\u2019s API to communicate with Solana\u2019s staking network. By compromising the API, hackers were able to manipulate requests and siphon off funds.<\/p>\n<p>SwissBorg said that despite the hack, the company remains in good financial health, daily operations are unaffected and the affected users will be contacted directly by email.<\/p>\n<p><em><strong>Related: <\/strong><\/em><a href=\"https:\/\/cointelegraph.com\/news\/npm-attack-crypto-stealing-malware-into-core-javascript-libraries\" rel target=\"_self\" title=\"https:\/\/cointelegraph.com\/news\/npm-attack-crypto-stealing-malware-into-core-javascript-libraries\"><em><strong>Crypto users urged to take extreme care as NPM attack hits core JavaScript libraries<\/strong><\/em><\/a><a href=\"https:\/\/cointelegraph.com\/news\/npm-attack-crypto-stealing-malware-into-core-javascript-libraries\" rel target=\"_self\" title=\"https:\/\/cointelegraph.com\/news\/npm-attack-crypto-stealing-malware-into-core-javascript-libraries\">\u00a0<\/a><\/p>\n<h2>A \u2018bad day\u2019 but not a fatal blow<\/h2>\n<p>SwissBorg CEO Cyrus Fazel <a href=\"https:\/\/x.com\/i\/broadcasts\/1yoJMPQbOPnGQ\" rel=\"nofollow noopener\" target=\"_blank\" title=\"https:\/\/x.com\/i\/broadcasts\/1yoJMPQbOPnGQ\">hosted<\/a> an X Space on Monday shortly after the company\u2019s statement that it had been hacked. According to Fazel, the breach only impacted users depositing Solana tokens in its Earn program, which accounts for about 1% of its customer base and 2% of total assets. <\/p>\n<p>\u201cIt\u2019s a big amount of money, but it doesn\u2019t put SwissBorg at risk,\u201d the spokesperson said. <\/p>\n<p>SwissBorg\u2019s\u00a0Solana Earn program\u00a0lets users deposit SOL through its app to earn staking rewards, using the infrastructure provided by Kiln. The product was part of SwissBorg\u2019s wider suite of Earn offerings on assets like BTC and ETH, designed to give retail users simple access to staking yields without managing validator nodes or DeFi protocols directly.<\/p>\n<p>The company pledged to reimburse affected users, noting that \u201cwith the current treasury we have, we could already do that,\u201d while stressing it is also working with international agencies, exchanges and white-hat hackers to assist with the investigation, and that some transactions have already been blocked.<\/p>\n<p>Calling it \u201ca bad day for SwissBorg,\u201d Fazel said the incident would ultimately serve as a learning experience for the company.<\/p>\n<figure data-ct-story-hidden=\"undefined\"><img decoding=\"async\" alt src=\"https:\/\/s3.cointelegraph.com\/uploads\/2025-09\/01992b22-7699-791d-9e7c-8a1a87082ddf\" title><figcaption><em>Source: <\/em><a href=\"https:\/\/solscan.io\/account\/TYFWG3hvvxWMs2KXEk8cDuJCsXEyKs65eeqpD9P4mK1\" rel=\"nofollow noopener\" target=\"_blank\" title=\"https:\/\/solscan.io\/account\/TYFWG3hvvxWMs2KXEk8cDuJCsXEyKs65eeqpD9P4mK1\"><em>Solscan<\/em><\/a><em> <\/em><\/figcaption><\/figure>\n<p>Blockchain data shows the stolen funds were routed to a Solana wallet now labeled on Solscan as the \u201cSwissBorg Exploiter,\u201d advising users to exercise caution when interacting with it.<\/p>\n<p data-ct-non-breakable=\"undefined\">Cointelegraph reached out to Swissborg and Kiln for comment, but did not receive an immediate response.<\/p>\n<p><template data-name=\"subscription_form\" data-type=\"markets_outlook\" label=\"Subscription Form: Markets Outlook\"><\/template><\/div>\n<p><img decoding=\"async\" alt src=\"https:\/\/zoa.cointelegraph.com\/pixel?postId=214546&#038;regionId=1\" data-v-43e640e6><\/p>\n<\/div>\n<\/div>",
        "protected": false
    },
    "excerpt": {
        "rendered": "<p>Hackers drained 193,000 SOL from SwissBorg\u2019s Solana Earn program after a Kiln API was compromised, affecting 1% of users and [&hellip;]<\/p>",
        "protected": false
    },
    "author": 1,
    "featured_media": 48576,
    "comment_status": "open",
    "ping_status": "open",
    "sticky": false,
    "template": "",
    "format": "standard",
    "meta": {
        "_acf_changed": false,
        "footnotes": ""
    },
    "categories": [
        220
    ],
    "tags": [],
    "class_list": [
        "post-48575",
        "post",
        "type-post",
        "status-publish",
        "format-standard",
        "has-post-thumbnail",
        "hentry",
        "category-tien-dien-tu"
    ],
    "acf": [],
    "_links": {
        "self": [
            {
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/posts\/48575",
                "targetHints": {
                    "allow": [
                        "GET"
                    ]
                }
            }
        ],
        "collection": [
            {
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/posts"
            }
        ],
        "about": [
            {
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/types\/post"
            }
        ],
        "author": [
            {
                "embeddable": true,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/users\/1"
            }
        ],
        "replies": [
            {
                "embeddable": true,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/comments?post=48575"
            }
        ],
        "version-history": [
            {
                "count": 0,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/posts\/48575\/revisions"
            }
        ],
        "wp:featuredmedia": [
            {
                "embeddable": true,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/media\/48576"
            }
        ],
        "wp:attachment": [
            {
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/media?parent=48575"
            }
        ],
        "wp:term": [
            {
                "taxonomy": "category",
                "embeddable": true,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/categories?post=48575"
            },
            {
                "taxonomy": "post_tag",
                "embeddable": true,
                "href": "https:\/\/hbbgroup.net\/en_us\/wp-json\/wp\/v2\/tags?post=48575"
            }
        ],
        "curies": [
            {
                "name": "wp",
                "href": "https:\/\/api.w.org\/{rel}",
                "templated": true
            }
        ]
    }
}