Hacker Stole $41M in SOL from Kiln's API, Staking Partner of SwissBorg on September 8, 2025.

SwissBorg is a Switzerland-based crypto wealth management platform was hit by $41M theft due to security breach in its staking partner Kiln that result in theft of 192,623.39 of Solana tokens. Despite the scale of the exploit, CEO Cyrus Fazel confirmed that the incident only affected roughly 1% of its users base and the core application along with smart contracts remain secure and promised compromised users with full reimbursement.

SwissBorg CEO Calls Hack a “Bad Day, Not a Fatal Blow”

Hack Analysis

Kiln provides staking infrastructure for Ethereum and Solana to make staking simple for retail investors who might not want to deal with the complexities of running validator nodes or engaging directly with DeFi protocols. Hacker targeted it's API that bridge SwissBorg's application to Solana's staking network which allowed the hacker to manipulate requests and siphon tokens meant for staking on the Solana network.

Account `TYFWG3hvvxWMs2KXEk8cDuJCsXEyKs65eeqpD9P4mK1`:
Account `2dmoNLgfP1UjqM9ZxtTqWY1YJMHJdXnUkwTrcLhL7Xoq`:
Account `6bnSQH4UtGKgo4hUXRj8MeMz2bqPP6hxSaRrBjL96QaT`:
Amount Deposited in Bitget Exchange:
Account `3XL3qRRsw8BmEne53anKuFZztKU5uftXYurdEsE9r1S1`:

Post Hack mitigation

All Hacker Accounts are being tracked and labeled to warn all Solana users:

  1. Account TYFWG3hvvxWMs2KXEk8cDuJCsXEyKs65eeqpD9P4mK1: was labeled as Exploit 1.
  2. Account 6bnSQH4UtGKgo4hUXRj8MeMz2bqPP6hxSaRrBjL96QaT: was labeled as Exploit 2.
  3. Account 3XL3qRRsw8BmEne53anKuFZztKU5uftXYurdEsE9r1S1: was labeled as Exploit 3.
  4. Account 2dmoNLgfP1UjqM9ZxtTqWY1YJMHJdXnUkwTrcLhL7Xoq: hasn't been labeled yet but tracked.

Kiln began the orderly exit of all of its Ethereum (ETH) validators. The exit process is a precautionary measure designed to ensure the continued integrity of the staked assets.

Kiln disabled its dashboard, widgets, and APIs during the investigation, initiating precautionary steps to safeguard validator operations and mitigate further risk.

Kiln Announcement Postmortem

Security Takeaways

The SwissBorg breach highlights how decentralized finance risks extend well beyond smart-contract code. Third-party APIs and staking partners introduce their own attack surface and must be vetted and monitored continuously. In this case, an attacker spent days setting up on-chain indicators and then drained millions in minutes once the gap was clear. Robust defense means layering safeguards—live authority alerts, transaction simulation, and recurring penetration tests on every external integration. SwissBorg’s rapid incident response shows strong operational discipline, but the episode is a reminder that frequent independent audits are critical to stopping the next large-scale exploit.

Protect Your Protocol and All Your Partners with Cyfrin CodeHawks Audit

A completely redesigned competitive smart contract security audit platform with new features and functionality, improved processes, and industry-leading usability.

Request an Audit