Transit Swap Incident Report

리서치 사고 분석
Transit Swap Incident Report

Transit Swap is billed as a "cross-chain swap platform that integrates DEXs to aggregate transactions."

Token Swap's developers paused the contracts after the exploit was noticed, though not before users had seen 49,815 BNB and 5,182 ETH transferred out of their wallets.

Using Skytrace to visualize the attacker's wallet immediately highlights a number of things.

Transit Skytrace1 Visualizing the attacker's wallet using Skytrace

First, the huge amount of individual wallets that the attacker's EOA has interacted with makes it clear that this was not a hack of a single Transit Swap contract. Rather, the attacker likely abused some vulnerability in the Transit Swap&Cross Approve Proxy contract to individually drain hundreds of addresses.

Transit Skytrace Tornado

Second, thanks to Skytrace's address labeling, we can see that the attacker has begun to transfer the stolen funds to Tornado Cash on BNB Chain. So far, they have effectuated 25 deposits of 100 BNB (~$49k) for a total of $1,225,146.86.

The attacker bridged 2,000 of the stolen ETH from Ethereum to BNB Chain using Multichain's cross-chain router.

Their BNB Chain wallet currently holds 1,499 ETH and 49,612 BNB.

Transit Swap released the following announcement in English and Mandarin on their Twitter page.

Transit Tweet

While Transit Swap has paused their contracts, any user who has interacted with the protocol – and particularly anyone who has approved the Transit Swap&Cross Approve Proxy contract – should immediately transfer any funds to an address which has had no contact with the platform.

관련 블로그

Skynet DPRK Crypto Threats Report

Skynet DPRK Crypto Threats Report

Our Skynet DPRK Crypto Threats Report discusses key North Korean hacker trends, including amounts stolen, number of incidents, and the most substantial hacks over the past 10 years.

2026 Wrench Attacks Overview

2026 Wrench Attacks Overview

After the publication of our February 2026 Wrench Attacks Report, we now look at the continued escalation of wrench attacks, which have become a structural threat for cryptocurrency holders.

Movie Token Incident Analysis

Movie Token Incident Analysis

On 10 March 2026, the Movie Token (MT) contract was exploited for approximately $242,000 due to a critical flaw in its 'sell' logic. The vulnerability stemmed from a double-counting error: when a user sold MT tokens, the contract simultaneously transferred them to the liquidity pair for the swap and added that same balance to a pendingBurnAmount variable. When distributeDailyRewards() subsequently burned those pending tokens, it created an artificial supply shock, inflating the MT price and allowing the attacker to drain value from the pool.