SwissBorg, the Swiss-based crypto wealth management platform, was hit by a $41 million hack on September 8 after attackers exploited a vulnerability in a partner’s API connection.
What Happened?
The breach was tied to staking provider Kiln, which SwissBorg uses for its Solana Earn program. Hackers managed to manipulate the API integration, draining around 192,600 SOL tokens into a wallet now flagged as the “SwissBorg Exploiter” on Solscan.
The stolen tokens—valued between $41M and $41.5M represent nearly half of SwissBorg’s Solana reserves (about $72.6M). Still, the company stressed that the impact was limited: only 1% of users were directly affected, while its app and other Earn products remained secure.
SwissBorg confirmed the incident in a same-day post on X, assuring users that core systems were not compromised.
SwissBorg’s Response and Recovery Plan
To ease user concerns, SwissBorg quickly pledged to cover losses with funds from its own Solana treasury. CEO Cyrus Fazel acknowledged the severity of the situation, calling it “a bad day, but not a fatal one,” while highlighting the company’s overall financial strength.
Ongoing efforts include:
- Compensation: Assets from SwissBorg’s treasury will reimburse most affected users.
- Investigation: The company is working with blockchain investigators, white-hat hackers, and partners like Fireblocks and the Solana Foundation.
- Damage Control: Several exchanges have already frozen transactions linked to the stolen funds.
- Future Safeguards: SwissBorg promised to strengthen its third-party risk oversight and enhance security protocols.
Bigger Picture: API Risks in Crypto
The incident highlights one of DeFi’s growing pain points: vulnerabilities in third-party APIs. As platforms rely more on external integrations for staking and trading services, attackers are increasingly targeting these weak links.
The SwissBorg hack follows a string of September exploits, including a $2.4M attack on Nemo Protocol on the Sui blockchain.
While SwissBorg has earned some praise for its transparency and quick promise to reimburse users, the event underscores the ongoing security risks facing staking programs and DeFi platforms.
For recovery updates and official statements, SwissBorg has directed its community to its X account.


























































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































