Transit Swap Incident Report

Research Incident Analysis
Transit Swap Incident Report

Transit Swap is billed as a "cross-chain swap platform that integrates DEXs to aggregate transactions."

Token Swap's developers paused the contracts after the exploit was noticed, though not before users had seen 49,815 BNB and 5,182 ETH transferred out of their wallets.

Using Skytrace to visualize the attacker's wallet immediately highlights a number of things.

Transit Skytrace1 Visualizing the attacker's wallet using Skytrace

First, the huge amount of individual wallets that the attacker's EOA has interacted with makes it clear that this was not a hack of a single Transit Swap contract. Rather, the attacker likely abused some vulnerability in the Transit Swap&Cross Approve Proxy contract to individually drain hundreds of addresses.

Transit Skytrace Tornado

Second, thanks to Skytrace's address labeling, we can see that the attacker has begun to transfer the stolen funds to Tornado Cash on BNB Chain. So far, they have effectuated 25 deposits of 100 BNB (~$49k) for a total of $1,225,146.86.

The attacker bridged 2,000 of the stolen ETH from Ethereum to BNB Chain using Multichain's cross-chain router.

Their BNB Chain wallet currently holds 1,499 ETH and 49,612 BNB.

Transit Swap released the following announcement in English and Mandarin on their Twitter page.

Transit Tweet

While Transit Swap has paused their contracts, any user who has interacted with the protocol – and particularly anyone who has approved the Transit Swap&Cross Approve Proxy contract – should immediately transfer any funds to an address which has had no contact with the platform.

Related Blogs

CertiK Intel3D H1 2026 Wrench Attacks

CertiK Intel3D H1 2026 Wrench Attacks

52 verified wrench attacks and $124.1 million in recorded exposure in H1 2026: a 33.3% rise in incidents, an 11.8-fold rise in losses, and a threat that has narrowed into a Western European crisis.

DefiTuna Incident Analysis

DefiTuna Incident Analysis

On 16 July 2026, DeFiTuna was exploited for approximately $569,601 USDC on Solana. The attackers created a highly illiquid TUNA/USDC pool and used it as the destination for borrowed USDC routed through Jupiter. Because the swap returned only a negligible amount of TUNA, DeFiTuna’s value calculation rounded the position’s total assets down to zero. The protocol then incorrectly treated the position as healthy, allowing the attackers to bypass the solvency check and withdraw the USDC through attacker-controlled liquidity positions.

CertiK Hack3D: H1 2026 Report

CertiK Hack3D: H1 2026 Report

Web3 security losses exceeded $1.31 billion in H1 2026 across 344 incidents, with wallet compromise emerging as the most financially destructive attack vector and phishing shifting toward fewer, higher-value social engineering attacks.