What's Hot

    Mexican inexperienced card holder convicted of illegally voting in US elections: DHS | Invesloan.com

    April 22, 2026

    Lululemon is getting a Nike veteran as its new CEO. An analyst says that could possibly be an issue. | Invesloan.com

    April 22, 2026

    California hospice CEO tells Congress fraud is flourishing statewide | Invesloan.com

    April 22, 2026
    Facebook Twitter Instagram
    Finance Pro
    Facebook Twitter Instagram
    invesloan.cominvesloan.com
    Subscribe for Alerts
    • Home
    • News
    • Politics
    • Money
    • Personal Finance
    • Business
    • Economy
    • Investing
    • Markets
      • Stocks
      • Futures & Commodities
      • Crypto
      • Forex
    • Technology
    invesloan.cominvesloan.com
    Home » Swiss Crypto Platform SwissBorg Hit by $41.5M SOL Hack After Partner API Compromise | Invesloan.com
    Crypto

    Swiss Crypto Platform SwissBorg Hit by $41.5M SOL Hack After Partner API Compromise | Invesloan.com

    September 8, 2025
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swiss crypto platform SwissBorg lost $41.5 million worth of Solana (SOL) tokens after hackers compromised partner API provider Kiln, marking the latest in a devastating series of cyber attacks that struck the crypto ecosystem within hours of each other.

    On-chain investigator ZachXBT reported that approximately 192,600 SOL tokens were stolen from SwissBorg’s SOL Earn program, affecting less than 1% of users.

    The platform immediately allocated its SOL treasury to cover most user losses while engaging white-hat hackers for fund recovery efforts.

    SwissBorg confirmed that its SOL treasury will compensate affected users for the majority of their losses, with final figures to be determined.

    The company emphasized that its strong financial health remains intact, and it will continue day-to-day operations unaffected by the security incident.

    SOL Earn Incident & SwissBorg Recovery Plan

    A partner API was compromised, impacting our SOL Earn Program (~193k SOL, <1% of users).
    Rest assured, the SwissBorg app remains fully secure and all other funds in Earn programs are 100% safe.

    Our recovery plan.
    Immediate Actions…

    — SwissBorg (@swissborg) September 8, 2025

    Quite a Day in Crypto: Cascade of Security Failures

    The SwissBorg incident coincided with multiple high-profile breaches across the crypto ecosystem.

    Earlier today, Nemo Protocol on the Sui blockchain suffered a $2.4 million exploit that crashed its total value locked from $6.3 million to $1.57 million as users fled the platform.

    The attack targeted Nemo’s yield-trading mechanism, which splits staked assets into Principal Tokens and Yield Tokens for speculation purposes.

    PeckShieldAlert detected the breach as hackers swiftly moved stolen USDC via Circle by bridging from Arbitrum to Ethereum.

    Following the exploit, user withdrawals exceeded $3.8 million worth of USDC and SUI tokens. Nemo halted all smart contract operations during scheduled maintenance windows to investigate the vulnerability’s root cause.

    Just today, the Solana project Aqua executed a $4.65 million rug pull involving 21,770 SOL tokens after promotion by teams including Meteora, Quill Audits, Helius, SYMMIO, and Dialect.

    Swiss Crypto Platform SwissBorg Hit by $41.5M SOL Hack After Partner API Compromise
    Source: Telegram

    The funds were split four ways and transferred through intermediary addresses before reaching instant exchanges.

    The team disabled Twitter replies across all posts following the exit scam.

    These attacks contribute to 2025’s $2.37 billion in DeFi losses across 121 security incidents during the first half alone.

    DeFi protocols account for 76% of breach cases, though centralized exchanges recorded higher single losses.

    npm Supply Chain Attack Threatens Entire Ecosystem

    On a massive scale, hackers compromised the npm account of respected developer Josh Goldberg, publishing malicious versions of 18 popular JavaScript packages, including chalk and debug.

    The affected packages receive over 2 billion weekly downloads, potentially exposing the entire JavaScript ecosystem.

    The sophisticated crypto-clipper malware intercepts browser functions to hijack crypto transactions by replacing recipient addresses with attacker-controlled wallets.

    The payload targets foundational packages like strip-ansi, color-convert, and error-ex buried deep within dependency trees.

    Security experts warned users to verify every hardware wallet transaction and avoid web-based on-chain activity until patches are deployed.

    I would strongly recommend not signing any crypto transactions right now.

    There is a huge supply chain attack on popular NPM packages that may have compromised various crypto websites (frontend, not the actual contracts).

    It changes the destination address of transactions and…

    — cygaar (@0xCygaar) September 8, 2025

    The malware uses Levenshtein distance algorithms to execute the large-scale hack.

    When crypto addresses are detected, the system replaces them with attacker addresses across Bitcoin, Ethereum, Solana, Tron, Litecoin, and Bitcoin Cash.

    Additionally, npm swiftly removed compromised packages, but transitive dependencies in tools like Babel and ESLint create persistent risks.

    Developers are advised to use npm ci in build pipelines and pin affected packages to the last known safe versions.

    Industry Grapples with Escalating Security Crisis

    The crypto ecosystem has been massively disrupted today, which could be regarded as one of the worst days for crypto security this year.

    So far this year, access control vulnerabilities, including misconfigured wallets and compromised legacy keys, represent 59% of industry losses according to Hacken’s mid-year assessment.

    The Sui blockchain faces particular scrutiny following the Nemo breach and May’s $223 million Cetus Protocol exploit.

    The earlier attack leveraged arithmetic overflow flaws in third-party code libraries, draining funds within 15 minutes.

    Similarly, Venus Protocol lost $13.5 million earlier this month, while Bunni Protocol suffered $8.4 million in theft. This latest hack marks the fourth major DeFi hack this month alone.

    The frequency of attacks has accelerated despite increased security awareness and audit practices.

    CertiK warns that security risks arise from multiple sources, including coding errors, blockchain network vulnerabilities, and programming language limitations.

    The npm attack is particularly disturbing as it represents large-scale supply chain compromises, potentially affecting millions of unaware users across thousands of websites and applications.

    The post Swiss Crypto Platform SwissBorg Hit by $41.5M SOL Hack After Partner API Compromise appeared first on Cryptonews.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Keep Reading

    Bitcoin Price Prediction: Major Miner Just Expanded in Texas: Is a Massive BTC Production Surge Coming? | Invesloan.com

    Crypto Price Prediction Today 25 February: XRP, Solana, Bitcoin | Invesloan.com

    Hong Kong to Link New Digital Bond Platform With Regional Crypto Tokenization Hubs | Invesloan.com

    An AI Crypto Agent Sent a ‘Beggar’ Six Figures, Then He Lost It All This Way | Invesloan.com

    Ethereum Locks In FOCIL for 2026 as Foundation Moves $6.8M ETH to Staking | Invesloan.com

    Bitcoin Price Prediction: $400 Million Suddenly Pulled From ETFs — Is Smart Money Quietly Exiting BTC? | Invesloan.com

    Crypto Price Prediction Today 24 February – XRP, Bitcoin, Ethereum | Invesloan.com

    XRP Price Prediction: Arizona Just Named XRP in a State Crypto Reserve Bill — Is Government Adoption Beginning? | Invesloan.com

    Bitpanda Offers €15 in Silver to New Users Trading €50 in Metals | Invesloan.com

    LATEST NEWS

    Mexican inexperienced card holder convicted of illegally voting in US elections: DHS | Invesloan.com

    April 22, 2026

    Lululemon is getting a Nike veteran as its new CEO. An analyst says that could possibly be an issue. | Invesloan.com

    April 22, 2026

    California hospice CEO tells Congress fraud is flourishing statewide | Invesloan.com

    April 22, 2026

    SpaceX and Cursor: What Smart People Are Saying About the $60B Deal | Invesloan.com

    April 22, 2026
    POPULAR

    China’s first passenger jet completes maiden commercial flight

    May 28, 2023

    Numbers taking US accountancy exams drop to lowest level in 17 years

    May 29, 2023

    Toyota chair faces removal vote over governance issues

    May 29, 2023
    Advertisement
    Load WordPress Sites in as fast as 37ms!
    Facebook Twitter Pinterest WhatsApp Instagram
    © 2007-2023 Invesloan.com All Rights Reserved.
    • Privacy
    • Terms
    • Press Release
    • Advertise
    • Contact

    Type above and press Enter to search. Press Esc to cancel.

    invesloan.com
    Manage Cookie Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}