SwissBorg lost 192,600 $SOL ($41.5M) via a partner API exploit. Funds are covered, but the case highlights major risks of third-party transaction-crafting APIs.SwissBorg lost 192,600 $SOL ($41.5M) via a partner API exploit. Funds are covered, but the case highlights major risks of third-party transaction-crafting APIs.

The SwissBorg Solana Exploit & The Case Against Transaction-Crafting APIs

2025/09/17 20:10
4 min di lettura
Per feedback o dubbi su questo contenuto, contattateci all'indirizzo crypto.news@mexc.com.
solana3 main

In an incident that has rocked parts of the crypto staking ecosystem, SwissBorg recently disclosed a major exploit wherein about 192,600 SOL, worth roughly US$41.5 million, was siphoned from an external wallet tied to its SOL Earn product. The attack did not stem from a breach of SwissBorg itself but from a compromised API belonging to one of its partners. 

What Happened with SwissBorg

  • The attack was traced to a partner’s API which had been compromised. Through that API, malicious actors were able to access the wallet tied to SwissBorg’s SOL Earn offering and withdraw the funds.
  • Though the amount stolen is large, SwissBorg reported that the exploit affected fewer than 1% of its users and represented about 2% of SwissBorg’s total assets under management.
  • SwissBorg emphasized that all other funds and strategies remain secure. They have committed to covering the losses and ensuring that no user is harmed financially.
  • As part of its response, SwissBorg paused SOL Earn redemptions, initiated recovery efforts, and is working with security firms, white-hat hackers, and law enforcement. A full incident report is expected.

This incident raises broader concerns not only about partner / third-party API security, but about architectural choices around transaction creation and who controls what part of the staking and funds flow.

Transaction-Crafting APIs: Why They’re Risky

An analysis by Chorus One throws light on the fundamental vulnerabilities associated with transaction-crafting APIs – a design pattern increasingly used in staking and DeFi services. 

Here are the key points:

  • Security by assumption vs. security by design: Many systems assume third parties (validators, API providers) will behave correctly. But Chorus One argues that architecture should enforce safety in such a way that even if a partner is compromised, funds are not immediately at risk.
  • Transaction crafting explained: On Solana, staking involves creating transactions (e.g. delegate, deactivate, withdraw), which are encoded, signed, and broadcast. These transactions include parameters like which validator to use, how much SOL, etc.
  • Libraries vs. APIs: Using a library (SDK) incorporated into the code of your own system means you can inspect and verify what it does. By contrast, a remote API that crafts a transaction and returns it to you introduces a dependency: you see the result, but you don’t control how it is generated—or whether it was maliciously altered.
  • Even verifying every response from an API is nontrivial; malicious responses may not be obviously wrong and the cost of blindly trusting a third party can be very high in terms of financial exposure.

Chorus One’s position is that while APIs are useful for many purposes (such as broadcasting or querying the chain), transaction‐crafting APIs are an unnecessary risk, especially when alternative patterns (like SDKs or embedding open-source libraries) exist.

What This Means for the Industry

  • Reconsider architectural choices: Platforms offering staking, yield products, or other DeFi services need to critically assess whether parts of their infrastructure should depend on third-party APIs that craft transactions. The SwissBorg incident shows the threat is not hypothetical.
  • Transparency and control: Using open-source libraries or SDKs that allow auditability gives more assurance. Institutions or apps that build features should demand visibility into the code path that handles fund movement or transaction parameters.
  • Risk mitigation and contingency: Even with safe design, compromises can occur. Layered security, such as limiting what an API can do, least privilege, monitoring, verifications, and temporary pauses (as SwissBorg did), is essential.
  • Regulatory scrutiny may increase: As larger losses emerge from API or third-party compromises, regulators and users may demand higher standards and possibly audits of these components of crypto staking / yield providers.

The SwissBorg loss is a stark reminder that the weakest link in a complex system doesn’t have to be the core platform itself – it can be a partner, an API, or any component with permissions over funds or transaction logic. While APIs provide convenience and scalability, their use in crafting transactions entails serious trust assumptions that may not be acceptable for funds at scale.

Going forward, the industry might shift more toward security-by-design approaches: encoded, auditable components; more SDK or library-based integration; fewer black-box APIs with high privilege. These design choices may cost more up front, but the alternative – massive losses and reputational damage – is far costlier.

Opportunità di mercato
Logo Solana
Valore Solana (SOL)
$84.06
$84.06$84.06
-5.30%
USD
Grafico dei prezzi in tempo reale di Solana (SOL)
Disclaimer: gli articoli ripubblicati su questo sito provengono da piattaforme pubbliche e sono forniti esclusivamente a scopo informativo. Non riflettono necessariamente le opinioni di MEXC. Tutti i diritti rimangono agli autori originali. Se ritieni che un contenuto violi i diritti di terze parti, contatta crypto.news@mexc.com per la rimozione. MEXC non fornisce alcuna garanzia in merito all'accuratezza, completezza o tempestività del contenuto e non è responsabile per eventuali azioni intraprese sulla base delle informazioni fornite. Il contenuto non costituisce consulenza finanziaria, legale o professionale di altro tipo, né deve essere considerato una raccomandazione o un'approvazione da parte di MEXC.

Potrebbe anche piacerti

OpenClaw API Integration Is Live in the Crypto.com App: Here’s What Traders Need to Know

OpenClaw API Integration Is Live in the Crypto.com App: Here’s What Traders Need to Know

TLDR: OpenClaw API integration is now live in the Crypto.com App via the new Agent Key feature for traders. Users can set weekly trading budgets to cap how much
Condividi
Blockonomi2026/03/03 19:30
The Best Crypto Presale in 2025? Solana and ADA Struggle, but Lyno AI Surges With Growing Momentum

The Best Crypto Presale in 2025? Solana and ADA Struggle, but Lyno AI Surges With Growing Momentum

The post The Best Crypto Presale in 2025? Solana and ADA Struggle, but Lyno AI Surges With Growing Momentum appeared on BitcoinEthereumNews.com. With the development of 2025, certain large cryptocurrencies encounter continuous issues and a new player secures an impressive advantage. Solana is struggling with congestion, and the ADA of Cardano is still at a significantly lower level than its highest price. In the meantime, Lyno AI presale is gaining momentum, attracting a large number of investors. Solana Faces Setbacks Amid Market Pressure However, despite the hype surrounding ETFs, Solana fell by 7% to $ 203, due to the constant congestion problems that hamper its network functionality. This makes adoption slow and aggravates traders who want to get things done quickly. Recent upgrades should combat those issues but the competition is rising, and Solana continues to lag in terms of user adoption and ecosystem development. Cardano Struggles to Regain Momentum ADA, the token of a Cardano, costs 72% less than the 2021 high and is developing more slowly than Ethereum Layer 2 solutions. The adoption of the coin is not making any progress despite the good forecasts. Analysts believe that the road to regain the past heights is long before Cardano can go back, with more technological advancements getting more and more attention. Lyno AI’s Explosive Presale Growth In stark contrast, Lyno AI is currently in its Early Bird presale, in which tokens are sold at 0.05 per unit and have already sold 632,398 tokens and raised 31,462 dollars. The next stage price will be established at $0.055 and the final target will be at $0.10. Audited by Cyberscope , Lyno AI provides a cross-chain AI arbitrage platform that enables retail traders to compete with institutions. Its AI algorithms perform trades in 15+ blockchains in real time, opening profitable arbitrage opportunities to everyone. Those who make purchases above 100 dollars are also offered the possibility of winning in the 100K Lyno AI…
Condividi
BitcoinEthereumNews2025/09/18 18:22
What to Expect From The Fed This Year After First Rate Cut in 2025

What to Expect From The Fed This Year After First Rate Cut in 2025

The United States central bank has just cut rates for the first time this year, and investors are now watching for its next move.
Condividi
CryptoPotato2025/09/18 13:02