Protect Your Project Today
Strengthen your project with the largest web3 security provider.
A CertiK security expert will review your request and follow up shortly.

Transit Swap Incident Report

Reports ·Incident Analysis ·
Transit Swap Incident Report

Transit Swap is billed as a "cross-chain swap platform that integrates DEXs to aggregate transactions."

Token Swap's developers paused the contracts after the exploit was noticed, though not before users had seen 49,815 BNB and 5,182 ETH transferred out of their wallets.

Using Skytrace to visualize the attacker's wallet immediately highlights a number of things.

Transit Skytrace1 Visualizing the attacker's wallet using Skytrace

First, the huge amount of individual wallets that the attacker's EOA has interacted with makes it clear that this was not a hack of a single Transit Swap contract. Rather, the attacker likely abused some vulnerability in the Transit Swap&Cross Approve Proxy contract to individually drain hundreds of addresses.

Transit Skytrace Tornado

Second, thanks to Skytrace's address labeling, we can see that the attacker has begun to transfer the stolen funds to Tornado Cash on BNB Chain. So far, they have effectuated 25 deposits of 100 BNB (~$49k) for a total of $1,225,146.86.

The attacker bridged 2,000 of the stolen ETH from Ethereum to BNB Chain using Multichain's cross-chain router.

Their BNB Chain wallet currently holds 1,499 ETH and 49,612 BNB.

Transit Swap released the following announcement in English and Mandarin on their Twitter page.

Transit Tweet

While Transit Swap has paused their contracts, any user who has interacted with the protocol – and particularly anyone who has approved the Transit Swap&Cross Approve Proxy contract – should immediately transfer any funds to an address which has had no contact with the platform.

Related Blogs

Hack3d: The Web3 Security Report 2025

Hack3d: The Web3 Security Report 2025

Welcome to the 2025 Skynet Hack3D Report! This report offers deep dives into the exploits, vulnerabilities, and trends that define blockchain and smart contract security. They’re an invaluable resource for anyone seeking to understand the current landscape of Web3 security. Each report contains detailed incident analyses, technical insights, and the most comprehensive statistics on hacks, scams, and exploits in the entire Web3 industry.

Skynet Stablecoin Spotlight Report: H1 2025

Skynet Stablecoin Spotlight Report: H1 2025

In our 2025 Stablecoin Report, we look at the current stablecoin landscape, vulnerabilities that affect stablecoins, and how CertiK’s Skynet Security Score can help evaluate stablecoin security.

Hack3d: The Web3 Security Quarterly Report - Q2 + H1 2025

Hack3d: The Web3 Security Quarterly Report - Q2 + H1 2025

Welcome to Hack3d: The Web3 Security Report for Q2 + H1 2025. Hack3d is the industry's most comprehensive record of statistics and analysis of on-chain security incidents. It equips stakeholders with the knowledge needed to make informed decisions in an increasingly high-stakes environment.