T
iTokenly

SwissBorg hack — September 2025

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Target typeCentralised exchange
Loss$41,000,000Published estimates range $41,000,000 to $42,000,000Price at time of incident
MethodSupply chain or frontend compromisestolen GitHub token let attackers inject a payload into staking provider Kiln's Connect API that rewrote Solana stake authority during unstaking
ChainsSolana
OutcomeUsers reimbursed

What happened

SwissBorg, a Swiss crypto wealth-management platform, lost about $41 million worth of Solana from the wallet backing its SOL Earn product around midday CEST on 8 September 2025. More than 192,000 SOL were fraudulently unstaked; independent analyses put the figure at roughly 192,600 SOL.

The compromise was not of SwissBorg's own systems. SwissBorg's later security update says the entry point was a GitHub access token belonging to an infrastructure engineer at Kiln, the third-party staking provider it used. With that token the attackers injected a malicious payload into the Kiln Connect API. The payload targeted organisations holding more than 150,000 SOL through Kiln, and during what appeared to be a routine deactivate transaction it silently appended extra instructions transferring control of SwissBorg's stake accounts to attacker-controlled wallets. QuillAudits counted eight such authorisation instructions and noted the groundwork was laid days before execution. Because the tampering happened inside Kiln's closed infrastructure it was not externally observable, and SwissBorg said no practical way existed at the time to decode a Solana transaction within its sub-two-minute validity window.

SwissBorg detected the fraudulent unstaking within minutes of Kiln raising it, opened a case with SEAL 911 and paused SOL Earn redemptions. Chief executive Cyrus Fazel said the incident touched fewer than one percent of users and about two percent of platform assets, that app balances were unchanged, and that SwissBorg would cover any shortfall from its treasury. Kiln exited its ETH validators, rotated keys on other networks and suspended transaction crafting. In the weeks afterwards most of the stolen SOL remained unmoved in the attackers' wallets.

Sources

  1. SwissBorgPrimary · retrieved 2026-08-01
  2. SwissBorgPrimary · retrieved 2026-08-01
  3. QuillAuditsSecondary · retrieved 2026-08-01
  4. HalbornSecondary · retrieved 2026-08-01

Official post-mortem: https://swissborg.com/blog/swissborg-security-update-kiln-breach

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "SwissBorg hack — September 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/swissborg
https://itokenly.com/hacks/swissborg

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.