{"investigation":{"slug":"chainswap","entity_name":"ChainSwap","trust_score":22,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"ChainSwap was a cross-chain token bridge protocol connecting Ethereum, Binance Smart Chain, and Huobi Eco Chain, which raised $3 million in April 2021 from investors including Alameda Research and NGC Ventures. The platform suffered two separate smart contract exploits in July 2021 — the first on July 2 draining approximately $800,000, and the second on July 10-11 draining approximately $4.4 million (with some sources citing up to $8 million across affected partner token markets) — collectively devastating more than 20 partner projects. Following the exploits, ChainSwap offered partial compensation via token airdrops; the project's native CHAINS/ASAP token collapsed over 96% from its all-time high and the protocol has since become largely inactive under its original identity, with the @ChainSwapERC Twitter handle rebranding to ChainHub in early 2026.","sections":[{"content":"ChainSwap was a multi-chain bridge and application hub that allowed projects to bridge tokens between Ethereum, Binance Smart Chain (BSC), and Huobi Eco Chain. In April 2021, ChainSwap announced a $3 million strategic funding round led by NGC Ventures, with participation from Alameda Research, OKEx's Block Dream Fund, CMS Holdings, Spark Digital Capital, Rarestone Capital, SRC Capital, DAO Ventures, and Metaconstant Ventures. The project issued a native token (ticker: ASAP, later CHAINS/CSWAP) that reached an all-time high of approximately $3.62 in April 2021. ChainSwap distinguished itself by enabling project teams to deploy cross-chain token bridges without building custom infrastructure, positioning itself as a bridge-as-a-service platform. The Alameda Research connection is notable given Alameda's subsequent collapse in November 2022 amid the FTX fraud scandal.","heading":"Project Background and Funding","sources":[{"url":"https://cointelegraph.com/news/chainswap-raises-3m-from-investors-including-alameda-research-and-ngc-ventures","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://insidebitcoins.com/news/3m-investment-round-for-chainswap-led-by-ngc-ventures","name":"insidebitcoins.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On July 2, 2021, ChainSwap's smart contract was exploited for approximately $800,000. The attacker identified a vulnerability that enabled unauthorized token minting across protocols using the ChainSwap bridge. The attacker minted tokens directly to their own address, then sold them on PancakeSwap. ChainSwap's team responded quickly — shutting down all nodes and deploying a fix within approximately 30 minutes — and pledged a 1:1 airdrop of replacement ASAP tokens to affected holders. Despite the rapid response, the underlying contract architecture contained a second, related vulnerability that was not fully remediated before the next attack.","heading":"First Exploit — July 2, 2021 (~$800,000)","sources":[{"url":"https://decrypt.co/75698/chainswap-exploit-leads-to-multi-million-loss-for-defi-tokens","name":"decrypt.co","type":"other","credibility":3},{"url":"https://rekt.news/chainswap-rekt/","name":"rekt.news","type":"other","credibility":3},{"url":"https://cryptopotato.com/chainswap-exploited-projects-using-the-bridge-protocol-crashed-99/","name":"cryptopotato.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Just nine days after the first exploit, on July 10-11, 2021, ChainSwap suffered a second and far more severe attack. A logical flaw in the token cross-chain quota code allowed the attacker to bypass the signature node's whitelist validation: the on-chain swap bridge quota was designed to increase automatically via signature nodes to reduce centralized control, but a code logic error permitted non-whitelisted addresses to increase the quota and drain funds. The attacker's address (0xEda5066780dE29D00dfb54581A707ef6F52D8113) called the receive function on ChainSwap's proxy Factory contracts on both Ethereum and BSC, paying a minimal 0.005 ETH charge fee per transaction, and used each new address to bypass the signature authentication check. Approximately 20 tokens were drained across both chains, with the attacker minting 20 million Wilder World (WILD) tokens alone, which were sold for roughly 650 WBNB (~$200,000) via PancakeSwap. The attacker cashed out approximately 456 ETH (~$935,000) through 1inch using bridged BSC liquidity. Direct losses to the bridge totaled approximately $4.4 million, while market impact from token price collapses across 16+ affected projects pushed estimated total damages to figures cited as high as $8 million. Affected projects included Wilder World (WILD), Antimatter (MATTER), Option Room (ROOM), Umbrella Network (UMB), BlockWallet (BLANK), Nord Finance (NORD), Razor Network (RAZOR), Peri Finance (PERI), Unido (UDO), Oro (ORO), Vortex (VTX), Corra (CORA), ROCKS, Dafi (DAFI), and Unifarm (UFARM).","heading":"Second Exploit — July 10-11, 2021 (~$4.4M–$8M)","sources":[{"url":"https://rekt.news/chainswap-rekt/","name":"rekt.news","type":"other","credibility":3},{"url":"https://chain-swap.medium.com/chainswap-exploit-11-july-2021-post-mortem-6e4e346e5a32","name":"chain-swap.medium.com","type":"other","credibility":3},{"url":"https://halborn.com/explained-the-chainswap-hack-july-2021/","name":"halborn.com","type":"other","credibility":3},{"url":"https://cryptobriefing.com/8-million-lost-major-chainswap-exploit/","name":"cryptobriefing.com","type":"other","credibility":3},{"url":"https://losslessdefi.medium.com/chainswap-post-mortem-deep-dive-into-the-exploit-b5e7d2f58758","name":"losslessdefi.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Security researchers and on-chain analysts raised questions about whether the July 11 exploit may have involved insider knowledge or willful negligence. The vulnerable contract configuration was set approximately nine days before the second exploit — coinciding with the period immediately following the first hack — suggesting the team may have introduced the flaw during the patching process or failed to audit the update. Rekt.news noted that the attacker funded their wallet via Tornado Cash (a privacy mixer) but then converted stolen proceeds to centralized stablecoins such as USDT, which are subject to issuer freezing — an unusual choice for an external hacker seeking to avoid identification. An alleged email from the attacker to ChainSwap was also referenced, though its authenticity was not confirmed. Independent investigator 0xWeb3 noted that ChainSwap never published the vulnerable code on GitHub, preventing public audit prior to deployment. These factors are alleged indicators of possible insider involvement or at minimum gross negligence, though no formal findings of insider fraud have been published by law enforcement or regulators as of the investigation date.","heading":"Suspicious Circumstances and Insider-Job Allegations","sources":[{"url":"https://rekt.news/chainswap-rekt/","name":"rekt.news","type":"other","credibility":3},{"url":"https://0xweb3.medium.com/chainswap-hack-investigation-scam-or-not-29dccd4937f2","name":"0xweb3.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the July 11 exploit, ChainSwap announced a compensation plan that included: (1) a 1:1 airdrop of new ASAP tokens to pre-hack ASAP holders, including those holding on exchanges; (2) liquidation of approximately 717,200 ASAP (worth roughly $150,000 at the time) from the team treasury to compensate partner projects; and (3) stablecoins from the team fund. The total compensation offered — approximately $215,000 in stablecoins plus devalued native tokens — was widely criticized as inadequate relative to losses exceeding $4 million in bridge funds alone. Independent analyst 0xWeb3 observed that the proposed compensation for Wilder World involved minting 2 million WILD from the project treasury (tokens originally purchased by investors), rather than providing genuine restitution. ChainSwap also announced it would submit contracts to two audit firms and mandated major audits before reopening the bridge. The bridge was taken offline, and the degree to which affected investors were made whole remains disputed.","heading":"Compensation Response and Shortfalls","sources":[{"url":"https://www.cryptovibes.com/blog/2021/07/14/chainswap-to-compensate-and-deep-audit-plan-after-8m-exploit/","name":"cryptovibes.com","type":"other","credibility":3},{"url":"https://x.com/chain_swap/status/1413985428336693251","name":"x.com","type":"other","credibility":3},{"url":"https://0xweb3.medium.com/chainswap-hack-investigation-scam-or-not-29dccd4937f2","name":"0xweb3.medium.com","type":"other","credibility":3},{"url":"https://coinquora.com/chainswap-to-airdrop-compensation-tokens-after-8m-hack/","name":"coinquora.com","type":"other","credibility":3}],"severity":"medium"},{"content":"ChainSwap's native ASAP/CHAINS token reached an all-time high of approximately $3.62 in April 2021 following the funding announcement. After the July 2 exploit, the token declined sharply from roughly $0.28 to $0.22 within minutes. By July 10, at the time of the second exploit, it had fallen to an all-time low of approximately $0.002 — a decline of over 99% from peak. Tokens of partner projects bridged through ChainSwap crashed 85-99% following the second exploit. Etherscan data shows the CHAINS (contract: 0xa1f830aa68b53fd3ee3bb86d7f8254e604740c8b) token currently trades at approximately $0.00 with approximately 919 holders remaining, indicating the token is functionally defunct.","heading":"Token Collapse and Investor Impact","sources":[{"url":"https://coinrivet.com/chainswap-hackers-steal-8m-and-crash-token-prices/","name":"coinrivet.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/chainswap-exploited-projects-using-the-bridge-protocol-crashed-99/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://etherscan.io/token/0xa1f830aa68b53fd3ee3bb86d7f8254e604740c8b","name":"etherscan.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the 2021 exploits, ChainSwap's original bridge protocol became largely inactive. The @chain_swap Twitter account (the original project handle) went quiet. A separate account, @ChainSwapERC, which had been associated with a CSWAP token on Ethereum (contract: 0xae41b275aaaf484b541a5881a2dded9515184cca), announced a rebranding to ChainHub in January 2026, pivoting to an on-chain trading platform offering Telegram trading bots for Solana and EVM networks. Whether ChainHub is operationally related to the original ChainSwap team or is a separate entity using a legacy account is not clearly established in public sources. The chainswap.com domain continues to display a basic site, and chainswap.io operates as an unrelated instant exchange service. No regulatory actions, court filings, or law enforcement charges related to either exploit have been publicly reported as of May 2026.","heading":"Current Status and Rebranding","sources":[{"url":"https://x.com/chainswaperc","name":"x.com","type":"other","credibility":3},{"url":"https://etherscan.io/token/0xae41b275aaaf484b541a5881a2dded9515184cca","name":"etherscan.io","type":"other","credibility":3},{"url":"https://www.chainswap.com/","name":"chainswap.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Security firm Halborn analyzed the July 2021 exploit and identified the root cause as insufficient consideration of cross-contract interactions. Standard smart contract audits evaluate individual project code but do not necessarily model how that contract interacts with other protocols — a gap the ChainSwap attacker exploited. Lossless DeFi's independent post-mortem confirmed the logical flaw in the quota management code: the signature node's automatic quota increase mechanism lacked proper address validation, allowing arbitrary external addresses to trigger fund transfers without being on the authorized whitelist. The exploit affected 20 tokens across both Ethereum and BSC simultaneously, demonstrating the systemic risk posed by shared bridge infrastructure. The fact that ChainSwap did not publish its updated contract code to GitHub before redeployment — as noted by independent researchers — represents a significant departure from standard open-source DeFi security practices.","heading":"Security Analysis and Audit Failures","sources":[{"url":"https://halborn.com/explained-the-chainswap-hack-july-2021/","name":"halborn.com","type":"other","credibility":3},{"url":"https://losslessdefi.medium.com/chainswap-post-mortem-deep-dive-into-the-exploit-b5e7d2f58758","name":"losslessdefi.medium.com","type":"other","credibility":3},{"url":"https://chain-swap.medium.com/chainswap-exploit-11-july-2021-post-mortem-6e4e346e5a32","name":"chain-swap.medium.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-03-21","event":"ChainSwap launches a Polkastarter bridge, signaling early multi-chain ambitions","source":""},{"date":"2021-04-07","event":"ChainSwap closes a $3 million strategic funding round led by NGC Ventures, with Alameda Research, OKEx Block Dream Fund, CMS Holdings, and others participating","source":""},{"date":"2021-04-23","event":"ASAP/CHAINS token reaches all-time high of approximately $3.62","source":""},{"date":"2021-07-02","event":"First exploit: smart contract vulnerability drained approximately $800,000. Bridge frozen within 30 minutes; ChainSwap pledges 1:1 ASAP airdrop to affected holders","source":""},{"date":"2021-07-10","event":"CHAINS token falls to all-time low of approximately $0.002 as second exploit begins; attacker address 0xEda5066780dE29D00dfb54581A707ef6F52D8113 begins draining 20+ tokens on Ethereum and BSC","source":""},{"date":"2021-07-11","event":"Second exploit confirmed: approximately $4.4 million drained directly, with broader market impact cited as high as $8 million. 16+ partner project tokens crash 85-99%. ChainSwap freezes bridge and mapping tokens","source":""},{"date":"2021-07-14","event":"ChainSwap announces expanded compensation plan: 1:1 ASAP airdrop, ~717,200 ASAP (~$150,000) liquidated from treasury for partner projects, and stablecoins from team fund. Commits to deep audit before reopening","source":""},{"date":"2022-11","event":"Alameda Research (ChainSwap investor) collapses amid the FTX fraud scandal, further tarnishing the credibility of entities in its investment portfolio","source":"","date_original":"2022-11-01"},{"date":"2026","event":"The @ChainSwapERC Twitter account announces rebranding to ChainHub, pivoting to a Telegram trading bot platform for Solana and EVM networks","source":"","date_original":"2026-01-01"}],"sources_used":[{"url":"https://cointelegraph.com/news/chainswap-raises-3m-from-investors-including-alameda-research-and-ngc-ventures","name":"cointelegraph.com","type":"other","archive_url":"https://web.archive.org/web/20260830083709/https://cointelegraph.com/news/chainswap-raises-3m-from-investors-including-alameda-research-and-ngc-ventures","credibility":3,"archive_timestamp":"2026-08-30T08:37:09+00:00"},{"url":"https://insidebitcoins.com/news/3m-investment-round-for-chainswap-led-by-ngc-ventures","name":"insidebitcoins.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://decrypt.co/75698/chainswap-exploit-leads-to-multi-million-loss-for-defi-tokens","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260516142444/https://decrypt.co/75698/chainswap-exploit-leads-to-multi-million-loss-for-defi-tokens","credibility":3,"archive_timestamp":"2026-05-16T14:24:44+00:00"},{"url":"https://rekt.news/chainswap-rekt/","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260607072910/https://rekt.news/chainswap-rekt","credibility":3,"archive_timestamp":"2026-06-07T07:29:10+00:00"},{"url":"https://cryptopotato.com/chainswap-exploited-projects-using-the-bridge-protocol-crashed-99/","name":"cryptopotato.com","type":"other","archive_url":"http://web.archive.org/web/20260418141612/https://cryptopotato.com/chainswap-exploited-projects-using-the-bridge-protocol-crashed-99/","credibility":3,"archive_timestamp":"2026-04-18T14:16:12+00:00"},{"url":"https://chain-swap.medium.com/chainswap-exploit-11-july-2021-post-mortem-6e4e346e5a32","name":"chain-swap.medium.com","type":"other","archive_url":"http://web.archive.org/web/20260322055929/https://chain-swap.medium.com/chainswap-exploit-11-july-2021-post-mortem-6e4e346e5a32","credibility":3,"archive_timestamp":"2026-03-22T05:59:29+00:00"},{"url":"https://halborn.com/explained-the-chainswap-hack-july-2021/","name":"halborn.com","type":"other","archive_url":"https://web.archive.org/web/20260830085759/https://www.halborn.com/blog/post/explained-the-chainswap-hack-july-2021","credibility":3,"archive_timestamp":"2026-08-30T08:57:59+00:00"},{"url":"https://cryptobriefing.com/8-million-lost-major-chainswap-exploit/","name":"cryptobriefing.com","type":"other","archive_url":"http://web.archive.org/web/20260207163416/https://cryptobriefing.com/8-million-lost-major-chainswap-exploit/","credibility":3,"archive_timestamp":"2026-02-07T16:34:16+00:00"},{"url":"https://losslessdefi.medium.com/chainswap-post-mortem-deep-dive-into-the-exploit-b5e7d2f58758","name":"losslessdefi.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"forbiddenaccess","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://0xweb3.medium.com/chainswap-hack-investigation-scam-or-not-29dccd4937f2","name":"0xweb3.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.cryptovibes.com/blog/2021/07/14/chainswap-to-compensate-and-deep-audit-plan-after-8m-exploit/","name":"cryptovibes.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://x.com/chain_swap/status/1413985428336693251","name":"x.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://coinquora.com/chainswap-to-airdrop-compensation-tokens-after-8m-hack/","name":"coinquora.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://coinrivet.com/chainswap-hackers-steal-8m-and-crash-token-prices/","name":"coinrivet.com","type":"other","archive_url":"https://web.archive.org/web/20260829191644/https://coinrivet.com/chainswap-hackers-steal-8m-and-crash-token-prices/","credibility":3,"archive_timestamp":"2026-08-29T19:16:44+00:00"},{"url":"https://etherscan.io/token/0xa1f830aa68b53fd3ee3bb86d7f8254e604740c8b","name":"etherscan.io","type":"other","archive_url":"http://web.archive.org/web/20250906015222/https://etherscan.io/token/0xa1F830AA68B53fD3eE3BB86D7F8254E604740C8b","credibility":3,"archive_timestamp":"2025-09-06T01:52:22+00:00"},{"url":"https://x.com/chainswaperc","name":"x.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://etherscan.io/token/0xae41b275aaaf484b541a5881a2dded9515184cca","name":"etherscan.io","type":"other","archive_url":"http://web.archive.org/web/20260714092559/https://etherscan.io/token/0xae41b275aaaf484b541a5881a2dded9515184cca","credibility":3,"archive_timestamp":"2026-07-14T09:25:59+00:00"},{"url":"https://www.chainswap.com/","name":"chainswap.com","type":"other","archive_url":"http://web.archive.org/web/20260608134642/https://www.chainswap.com/","credibility":3,"archive_timestamp":"2026-06-08T13:46:42+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:53.263978+00:00","updated_at":"2026-08-30T09:45:04.580903+00:00"}}