지금 프로젝트를 보호하세요
최대 규모의 웹3 보안 제공업체로 프로젝트를 강화하세요.
CertiK 보안 전문가가 귀하의 요청을 검토 후 곧 연락드리겠습니다.

Transit Swap Incident Report

보고서 ·사고 분석 ·
Transit Swap Incident Report

Transit Swap is billed as a "cross-chain swap platform that integrates DEXs to aggregate transactions."

Token Swap's developers paused the contracts after the exploit was noticed, though not before users had seen 49,815 BNB and 5,182 ETH transferred out of their wallets.

Using Skytrace to visualize the attacker's wallet immediately highlights a number of things.

Transit Skytrace1 Visualizing the attacker's wallet using Skytrace

First, the huge amount of individual wallets that the attacker's EOA has interacted with makes it clear that this was not a hack of a single Transit Swap contract. Rather, the attacker likely abused some vulnerability in the Transit Swap&Cross Approve Proxy contract to individually drain hundreds of addresses.

Transit Skytrace Tornado

Second, thanks to Skytrace's address labeling, we can see that the attacker has begun to transfer the stolen funds to Tornado Cash on BNB Chain. So far, they have effectuated 25 deposits of 100 BNB (~$49k) for a total of $1,225,146.86.

The attacker bridged 2,000 of the stolen ETH from Ethereum to BNB Chain using Multichain's cross-chain router.

Their BNB Chain wallet currently holds 1,499 ETH and 49,612 BNB.

Transit Swap released the following announcement in English and Mandarin on their Twitter page.

Transit Tweet

While Transit Swap has paused their contracts, any user who has interacted with the protocol – and particularly anyone who has approved the Transit Swap&Cross Approve Proxy contract – should immediately transfer any funds to an address which has had no contact with the platform.

관련 블로그

Movie Token Incident Analysis
새로운 · 보고서 ·사고 분석

Movie Token Incident Analysis

On 10 March 2026, the Movie Token (MT) contract was exploited for approximately $242,000 due to a critical flaw in its 'sell' logic. The vulnerability stemmed from a double-counting error: when a user sold MT tokens, the contract simultaneously transferred them to the liquidity pair for the swap and added that same balance to a pendingBurnAmount variable. When distributeDailyRewards() subsequently burned those pending tokens, it created an artificial supply shock, inflating the MT price and allowing the attacker to drain value from the pool.

2026 Skynet Prediction Markets Report

2026 Skynet Prediction Markets Report

Prediction markets crossed into the mainstream in 2025, with annual trading volume growing 4x and a small number of dominant platforms emerging. Kalshi, Polymarket, and Opinion now control the vast majority of global volume, each pursuing distinct regulatory and technical strategies.

CertiK, 2025년 Skynet Hack3d 보안 보고서 발표!

CertiK, 2025년 Skynet Hack3d 보안 보고서 발표!

CertiK이 2025 Skynet Hack3D 보안 보고서를 발표했습니다. 본 보고서는 블록체인 및 스마트 컨트랙트 보안을 규정하는 주요 공격 사례, 취약점, 그리고 트렌드를 심층적으로 분석합니다. 또한 개별 사건에 대한 상세 분석과 기술적 인사이트는 물론, Web3 업계 전반의 해킹·사기·취약점 악용 사례에 대한 가장 포괄적인 통계가 담겨 있습니다.