The post SwissBorg Hit by $41M Solana Theft in Kiln API Compromise appeared on BitcoinEthereumNews.com. The company clarified that only 1% of users were affected and pledged full reimbursement. Meanwhile, a massive supply chain hack targeting JavaScript libraries downloaded over a billion times, but surprisingly only netted attackers less than $50 in stolen crypto. However, experts warned that the potential risks are still significant. Hackers Steal $41M in SOL from SwissBorg SwissBorg, a Switzerland-based crypto wealth management platform, confirmed that it suffered a security breach involving its staking partner Kiln that resulted in the theft of about 193,000 Solana tokens. The exploit targeted Kiln’s API, and drained funds from SwissBorg’s Solana Earn program which amounted to roughly $41 million at the time of the incident. Despite the scale of the hack, SwissBorg explained that its app and other Earn products were unaffected, with the vulnerability traced back to Kiln’s infrastructure rather than its own systems. API attacks like this one exploit the software bridge that enables communication between different systems. In this case, Kiln’s API was compromised, which allowed hackers to manipulate requests and siphon tokens meant for staking on the Solana network.  SwissBorg stated that the breach only impacted users who deposited Solana into its Earn program, which makes up about 1% of its customer base and 2% of total assets under management. CEO Cyrus Fazel addressed the issue in an X Space, and admitted that the loss was big but it did not threaten the company’s overall financial stability. Cyrus Fazel during an X Space addressing the hack The Solana Earn program, powered by Kiln, was designed to make staking simple for retail investors who might not want to deal with the complexities of running validator nodes or engaging directly with DeFi protocols. While the attack was a setback, SwissBorg reassured its customers that affected users will be reimbursed. The company also pointed… The post SwissBorg Hit by $41M Solana Theft in Kiln API Compromise appeared on BitcoinEthereumNews.com. The company clarified that only 1% of users were affected and pledged full reimbursement. Meanwhile, a massive supply chain hack targeting JavaScript libraries downloaded over a billion times, but surprisingly only netted attackers less than $50 in stolen crypto. However, experts warned that the potential risks are still significant. Hackers Steal $41M in SOL from SwissBorg SwissBorg, a Switzerland-based crypto wealth management platform, confirmed that it suffered a security breach involving its staking partner Kiln that resulted in the theft of about 193,000 Solana tokens. The exploit targeted Kiln’s API, and drained funds from SwissBorg’s Solana Earn program which amounted to roughly $41 million at the time of the incident. Despite the scale of the hack, SwissBorg explained that its app and other Earn products were unaffected, with the vulnerability traced back to Kiln’s infrastructure rather than its own systems. API attacks like this one exploit the software bridge that enables communication between different systems. In this case, Kiln’s API was compromised, which allowed hackers to manipulate requests and siphon tokens meant for staking on the Solana network.  SwissBorg stated that the breach only impacted users who deposited Solana into its Earn program, which makes up about 1% of its customer base and 2% of total assets under management. CEO Cyrus Fazel addressed the issue in an X Space, and admitted that the loss was big but it did not threaten the company’s overall financial stability. Cyrus Fazel during an X Space addressing the hack The Solana Earn program, powered by Kiln, was designed to make staking simple for retail investors who might not want to deal with the complexities of running validator nodes or engaging directly with DeFi protocols. While the attack was a setback, SwissBorg reassured its customers that affected users will be reimbursed. The company also pointed…

SwissBorg Hit by $41M Solana Theft in Kiln API Compromise

The company clarified that only 1% of users were affected and pledged full reimbursement. Meanwhile, a massive supply chain hack targeting JavaScript libraries downloaded over a billion times, but surprisingly only netted attackers less than $50 in stolen crypto. However, experts warned that the potential risks are still significant.

Hackers Steal $41M in SOL from SwissBorg

SwissBorg, a Switzerland-based crypto wealth management platform, confirmed that it suffered a security breach involving its staking partner Kiln that resulted in the theft of about 193,000 Solana tokens. The exploit targeted Kiln’s API, and drained funds from SwissBorg’s Solana Earn program which amounted to roughly $41 million at the time of the incident. Despite the scale of the hack, SwissBorg explained that its app and other Earn products were unaffected, with the vulnerability traced back to Kiln’s infrastructure rather than its own systems.

API attacks like this one exploit the software bridge that enables communication between different systems. In this case, Kiln’s API was compromised, which allowed hackers to manipulate requests and siphon tokens meant for staking on the Solana network. 

SwissBorg stated that the breach only impacted users who deposited Solana into its Earn program, which makes up about 1% of its customer base and 2% of total assets under management. CEO Cyrus Fazel addressed the issue in an X Space, and admitted that the loss was big but it did not threaten the company’s overall financial stability.

Cyrus Fazel during an X Space addressing the hack

The Solana Earn program, powered by Kiln, was designed to make staking simple for retail investors who might not want to deal with the complexities of running validator nodes or engaging directly with DeFi protocols. While the attack was a setback, SwissBorg reassured its customers that affected users will be reimbursed. The company also pointed out that its treasury reserves were strong enough to cover losses immediately and pledged to move forward with reimbursements while continuing to work with international agencies, exchanges, and white-hat hackers to trace and block stolen funds.

Blockchain data shows that the stolen assets were routed to a Solana wallet now flagged on Solscan as belonging to the “SwissBorg Exploiter.” The company advised users to avoid interacting with this address during their investigations. 

Fazel described the incident as “a bad day for SwissBorg,” but one that will ultimately serve as a learning experience. Despite the disruption, SwissBorg said daily operations remain unaffected, and its broader suite of crypto yield products is still intact.

$50 Lost in Supply Chain Hack

Meanwhile, hackers have managed to steal less than $50 worth of crypto in what researchers are calling a massive supply chain attack targeting JavaScript software libraries. According to security intelligence platform Security Alliance, attackers broke into the node package manager (NPM) account of a well-known developer and inserted malware into popular libraries downloaded more than a billion times. The breach specifically targeted Ethereum and Solana wallets, but so far the actual damage has been minimal.

Security Alliance revealed that the only malicious address it has identified, an Ethereum wallet labeled “0xFc4a48,” received just a handful of tokens including ETH and several meme coins like Brett, Andy, Dork Lord, Ethervista, and Gondola. Initially, the value of the compromised funds was reported at just five cents, before climbing to around $50 as more small transfers were detected. The relatively tiny haul prompted Security Alliance to say that hackers squandered what could have been one of the most damaging supply chain exploits in the industry’s history.

The attack involved packages like chalk, strip-ansi, and color-convert, which are deeply embedded in the dependency chains of countless projects. This means even developers who never installed the compromised packages directly may still be exposed if their projects depend on them indirectly. The malware that was planted appears to be a crypto-clipper, which is designed to silently swap out wallet addresses during transactions to siphon funds.

Despite the low dollar impact so far, experts are urging caution. Ledger’s chief technology officer Charles Guillemet advised users to carefully verify on-chain transactions, but Ledger confirmed its hardware devices were not directly affected. 

Meanwhile, 0xngmi, founder of DeFiLlama, mentioned that only crypto projects that updated after the malicious NPM code was pushed are at risk, and even then, users would need to approve the compromised transactions for funds to be taken. Still, he thinks that users may want to avoid interacting with crypto websites until developers confirm that their platforms are no longer relying on infected libraries.

Although the outcome so far seems like a missed opportunity for attackers, the sheer scale of the breach shed some light on the fragility of supply chain security in open-source software and how deeply even small libraries are integrated into critical crypto infrastructure.

Source: https://coinpaper.com/10940/swiss-borg-hit-by-41-m-solana-theft-in-kiln-api-compromise

Market Opportunity
Solana Logo
Solana Price(SOL)
$142.93
$142.93$142.93
-0.39%
USD
Solana (SOL) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Taiko Makes Chainlink Data Streams Its Official Oracle

Taiko Makes Chainlink Data Streams Its Official Oracle

The post Taiko Makes Chainlink Data Streams Its Official Oracle appeared on BitcoinEthereumNews.com. Key Notes Taiko has officially integrated Chainlink Data Streams for its Layer 2 network. The integration provides developers with high-speed market data to build advanced DeFi applications. The move aims to improve security and attract institutional adoption by using Chainlink’s established infrastructure. Taiko, an Ethereum-based ETH $4 514 24h volatility: 0.4% Market cap: $545.57 B Vol. 24h: $28.23 B Layer 2 rollup, has announced the integration of Chainlink LINK $23.26 24h volatility: 1.7% Market cap: $15.75 B Vol. 24h: $787.15 M Data Streams. The development comes as the underlying Ethereum network continues to see significant on-chain activity, including large sales from ETH whales. The partnership establishes Chainlink as the official oracle infrastructure for the network. It is designed to provide developers on the Taiko platform with reliable and high-speed market data, essential for building a wide range of decentralized finance (DeFi) applications, from complex derivatives platforms to more niche projects involving unique token governance models. According to the project’s official announcement on Sept. 17, the integration enables the creation of more advanced on-chain products that require high-quality, tamper-proof data to function securely. Taiko operates as a “based rollup,” which means it leverages Ethereum validators for transaction sequencing for strong decentralization. Boosting DeFi and Institutional Interest Oracles are fundamental services in the blockchain industry. They act as secure bridges that feed external, off-chain information to on-chain smart contracts. DeFi protocols, in particular, rely on oracles for accurate, real-time price feeds. Taiko leadership stated that using Chainlink’s infrastructure aligns with its goals. The team hopes the partnership will help attract institutional crypto investment and support the development of real-world applications, a goal that aligns with Chainlink’s broader mission to bring global data on-chain. Integrating real-world economic information is part of a broader industry trend. Just last week, Chainlink partnered with the Sei…
Share
BitcoinEthereumNews2025/09/18 03:34
Kalshi Prediction Markets Are Pulling In $1 Billion Monthly as State Regulators Loom

Kalshi Prediction Markets Are Pulling In $1 Billion Monthly as State Regulators Loom

The post Kalshi Prediction Markets Are Pulling In $1 Billion Monthly as State Regulators Loom appeared on BitcoinEthereumNews.com. In brief Kalshi reached $1 billion in monthly volume and now dominates 62% of the global prediction market industry, surpassing Polymarket’s 37% share. Four states including Massachusetts have filed lawsuits claiming Kalshi operates as an unlicensed sportsbook, with Massachusetts seeking to permanently bar the platform. Kalshi operates under federal CFTC regulation as a designated contract market, arguing this preempts state gambling laws that require separate licensing. Prediction market Kalshi just topped $1 billion in monthly volume as state regulators nip at its heels with lawsuits alleging that it’s an unregistered sports betting platform. “Despite being limited to only American customers, Kalshi has now risen to dominate the global prediction market industry,” the company said in a press release. “New data scraped from publicly available activity metrics details this rise.” The publicly available data appears on a Dune Analytics dashboard that’s been tracking prediction market notional volume. The data show that Kalshi now accounts for roughly 62% of global prediction market volume, Polymarket for 37%, and the rest split between Limitless and Myriad, the prediction market owned by Decrypt parent company Dastan. Trading volume on Kalshi skyrocketed in August, not coincidentally at the start of the NFL season and as the prediction market pushes further into sports.  But regulators in Maryland, Nevada, and New Jersey have all issued cease-and-desist orders, arguing Kalshi’s event contracts amount to unlicensed sports betting. Each case has spilled into federal court, with judges issuing preliminary rulings but no final decisions yet. Last week, Massachusetts went further, filing a lawsuit that calls Kalshi’s sports contracts “illegal and unsafe sports wagering.” The 43-page Massachusetts lawsuit seeks to stop the company from allowing state residents on its platform—much the way Coinbase has had to do with its staking offerings in parts of the United States. Massachusetts Attorney General…
Share
BitcoinEthereumNews2025/09/19 09:21
[Pastilan] End the confidential fund madness

[Pastilan] End the confidential fund madness

UPDATE RULES. Former Commission on Audit commissioner Heidi Mendoza speaks during a public forum.
Share
Rappler2026/01/16 14:02