HostDeFi › Is SwissBorg safe
Is SwissBorg safe? The venue that watched its staking middleware get robbed
SwissBorg owns the freshest documented incident in this family — and the cleanest version of the modern supply-chain shape. In September 2025 an attacker didn't touch SwissBorg at all: they compromised a GitHub token at Kiln, the third-party staking provider, slipped eight hidden authorization instructions into a routine unstaking transaction, and walked away with 192,600 SOL (~$42M) that SwissBorg had delegated. The venue's own infrastructure was never breached. The lesson costs exactly what third-party risk always costs — you just rarely get to watch it this clearly.
What SwissBorg is
SwissBorg is a Swiss crypto wealth platform — founded 2017, Lausanne — offering a custodial app with yield 'Earn' strategies, its own BORG token, and an EU user base under MiCA-era licensing. Its model is curating third-party yield/staking strategies behind a clean retail interface — which is exactly the architecture this incident tests: the user experience is SwissBorg's; parts of the execution stack are not.
Custody splits by product — app balances custodial with the platform, Earn strategies delegated to whichever infrastructure runs the strategy. No documented breach of SwissBorg's own wallet infrastructure is on record; the September 2025 event is about where a platform's perimeter actually ends when it sells a managed yield product.
September 8, 2025: the payload inside the routine transaction
The mechanics, per the joint SwissBorg–Kiln disclosures and independent analyses: a GitHub access token belonging to a Kiln infrastructure engineer was compromised; the attacker used it to inject a malicious payload into the Kiln Connect API — the middleware SwissBorg's SOL Earn strategy delegated staking to. The code targeted organizations holding over 150,000 SOL via Kiln's API or dashboard — a supply-chain exploit aimed at the biggest delegators, not retail endpoints.
The elegance of the attack is the nasty part: during what looked like a routine 'deactivate' (unstaking) transaction, the injected code smuggled eight additional authorization instructions that silently reassigned control of the staking accounts to attacker wallets — planted days before the drain. When the trap sprang, 192,600+ SOL (roughly $41–42 million) moved out; the attacker even test-sent ~100 SOL toward Bitget to probe whether the funds would be flagged.
SwissBorg's detection was genuinely fast: Kiln's team flagged an unusual unstake, SwissBorg's analysis caught the fraudulent transaction within minutes, it opened a Seal 911 case, and forensics concluded within hours that SwissBorg's own infrastructure was untouched — the tampering lived entirely inside Kiln's. Solana staking was paused platform-wide the same day, and a joint statement with Kiln went public within hours — disclosure speed that ranks near the top of this family's incident files.
Who pays: the treasury answer, staged
SwissBorg committed to covering the loss from its own treasury — the instinct this family now prices as table stakes — but the honest shape is 'structured recovery,' not 'instant make-whole.' The affected SOL strategy was marked at a 97.7675% loss (the residual 2.2325% auto-redeemed to users), and the recovery vehicle is a 'Solana Support Grant': proportional payouts to impacted users, first tranche ~$4M distributed December 17, 2025 in USDG or SOL, accept-or-decline terms inside the app.
That staging is the difference worth naming against Bybit's playbook — reserves re-bridged within days, users whole immediately. SwissBorg's approach makes users whole over time and on terms; the commitment is documented, the treasury is real, and the payout mechanics are slower than the headline promise implied. Both sentences belong on the record.
What the incident actually demonstrates
Three lessons, in order of usefulness. First, supply-chain custody risk is compositional: your yield product's security equals the least-audited vendor in the delegation chain — SwissBorg's infra, Kiln's API, a GitHub token, an engineer's credentials; the chain broke at its weakest link, which wasn't the brand on the app. Second, transaction-level review fails against crafted payloads: a human or machine approving 'a routine unstake' authorized eight invisible extra instructions — the same class of attack as the Safe{Wallet} UI compromise at Bybit, executed at middleware scale — and, like that one, invisible to the signer because the payload hid inside an operation whose visible intent stayed routine. Third, response quality is separable from prevention quality: detection-in-minutes and a treasury commitment didn't prevent the loss; they changed its distribution.
For the user-side checklist this corpus maintains: 'Earn' and 'staking' products carry vendor-chain risk the platform's own security page doesn't describe — the honest question is always 'who else can move this, and what guards their keys' — a question whose answer, in a managed product, is a vendor list the marketing page never shows you. The platforms that survive this class are the ones that price the delegation chain before the incident, not after.
Where SwissBorg stands
In the mid-tier custodian set SwissBorg is the current-affairs entry: a documented, well-disclosed supply-chain incident with a fast detection record and a real-but-staged treasury recovery — more honest post-mortem than most venues publish, priced against a thinner overall track record than the Kraken/bitFlyer end of the tier. The verdict shape: custodial platform unbreached at its own layer, yield architecture demonstrably breachable at the vendor layer — which is the risk class every 'Earn' product in this corpus shares and SwissBorg's file now illustrates best.
Frequently asked questions
Was SwissBorg hacked?
Not directly — and that distinction is the story. In September 2025 attackers compromised a GitHub token at Kiln, SwissBorg's third-party Solana staking provider, and injected a malicious payload into the Kiln Connect API. SwissBorg's own infrastructure was never breached; ~192,600 SOL (~$42M) delegated through the SOL Earn strategy was drained anyway. Your risk in a managed product includes vendors you never chose.
How did the attacker drain the SOL?
By poisoning the middleware, not the front door. Inside a routine 'deactivate' staking transaction — the kind ops teams approve daily — the injected code smuggled eight extra authorization instructions that silently reassigned account control to attacker wallets. The trap sat days before the drain, targeting any Kiln API customer holding >150,000 SOL. Same attack class as Bybit's Safe{Wallet} incident: the thing being approved wasn't the thing it appeared to be.
Did SwissBorg reimburse affected users?
Committed treasury coverage, staged rather than instant: the affected strategy was marked at a 97.7675% loss (residual ~2.23% auto-redeemed immediately), and a Solana Support Grant distributes proportional payouts — first tranche ~$4M on December 17, 2025 in USDG or SOL — to users who accept the grant terms. Real commitment with mechanics slower than the 'make whole' headline; the honest record keeps both halves.
Is SwissBorg's own custody safe?
No documented breach of SwissBorg's own wallet infrastructure is on record — the September 2025 forensics explicitly concluded the compromise lived entirely inside Kiln's stack. The residual exposure is the product architecture: any 'Earn' strategy delegates assets to whatever vendor chain executes it, and that chain's weakest link (here, an engineer's leaked GitHub token) becomes your risk regardless of the platform's internal controls.
What is Kiln and why does it matter?
Kiln is institutional staking infrastructure — the middleware that runs validator operations for platforms offering yield products. SwissBorg delegated its SOL Earn staking through Kiln's API. When you buy a managed yield product you inherit its vendor chain; Kiln's compromised token became SwissBorg users' $42M problem without SwissBorg's perimeter ever being crossed. That's the third-party risk model in one sentence.
Is SwissBorg regulated?
Swiss-headquartered (Lausanne, founded 2017), operating under Swiss AML registration and EU-facing MiCA-era compliance structures — a real licensing posture, thinner than the statutory segregation regimes Japan or New York impose. Post-incident, the SOL Earn event is the regulatory-grade fact about the platform: not how it's licensed, but how it handled a $42M vendor failure — detection in minutes, disclosure in days, coverage in stages.