{"investigation":{"slug":"transit-swap","entity_name":"Transit Swap","trust_score":18,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Transit Swap is a cross-chain DEX aggregator incubated by TokenPocket, supporting swaps across Ethereum, BNB Chain, Polygon, Tron, Solana, and other networks. On October 1–2, 2022, an attacker exploited an input validation vulnerability in the platform's swap contract, draining approximately $21–28.9 million in user funds across Ethereum and BNB Chain. The attacker subsequently returned roughly 70% of stolen assets after security firms identified the exploiter's IP address and email, though an estimated 30% of funds — including amounts routed through Tornado Cash — remain unrecovered.","sections":[{"content":"Transit Swap (Transit Finance) is a cross-chain DEX aggregator incubated by TokenPocket, one of the largest multi-chain crypto wallet providers. The platform integrates liquidity from more than 30 decentralized exchanges across over ten public blockchains, including Ethereum, BNB Chain, Polygon, HECO, TRON, and Solana. Its core value proposition is one-stop cross-chain swapping, allowing users to exchange assets across supported networks in a single transaction. To use Transit Swap, users grant an approval to the platform's permissions management contract, permitting it to withdraw tokens from their wallets on their behalf. At the time of the October 2022 exploit, the swap contract code was unverified — meaning its source code was not publicly available on-chain — which significantly complicated independent security review.","heading":"Background","sources":[{"url":"https://docs.transit.finance/","name":"","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-transit-swap-hack-october-2022","name":"","type":"other","credibility":3},{"url":"https://medium.com/@TransitSwap/multi-chain-dex-aggregator-transit-swap-6f6c62ea3335","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"On October 1–2, 2022, an attacker exploited a critical input validation vulnerability in Transit Swap's swap contract, draining an estimated $21 million to $28.9 million in user tokens across Ethereum and BNB Chain. The root cause was insufficient data validation in the contract's claimTokens function. Because users had previously granted broad token approvals to Transit Swap's permissions management contract (address: 0xed1afc8c4604958c2f38a3408fa63b32e737c428), the attacker was able to craft malicious call data that redirected these pre-authorized token transfers to attacker-controlled addresses. The attack flow involved: (1) calling the entry contract to initiate the swap mechanism; (2) invoking the callBytes() function on the router contract with a malicious payload; (3) querying getFeeRate() to manipulate rate parameters; and (4) executing claimTokens() with crafted parameters that bypassed address and amount validation, causing the contract to call transferFrom() on arbitrary token contracts and drain user balances. The attacker's primary address was 0x75F2abA6a44580D7be2C4e42885D4a1917bFFD46. The BNB Chain exploit transaction hash is 0x181a7882aac0eab1036eedba25bc95a16e10f61b5df2e99d240a16c334b9b189. The fact that the swap contract's source code was unverified at the time of the exploit contributed to the vulnerability going undetected. SlowMist noted the attack was linked to a legacy code issue originating from an old contract on Tron.","heading":"The Exploit","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-transit-swap-hack-october-2022","name":"","type":"other","credibility":3},{"url":"https://slowmist.medium.com/cross-chain-dex-aggregator-transit-swap-hacked-analysis-74ba39c22020","name":"","type":"other","credibility":3},{"url":"https://www.numencyber.com/transit-swap-hack-analysis/","name":"","type":"other","credibility":3},{"url":"https://beincrypto.com/hacker-exploits-21m-vulnerability-in-transit-swap/","name":"","type":"other","credibility":3},{"url":"https://blog.solidityscan.com/transit-swap-hack-analysis-13c1e04e7de0/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"The exploit is fully traceable on-chain. Key contract addresses involved include the entry point (0x8785bb8deae13783b24d7afe250d42ea7d7e9d72), the router/caller contract (0x0B47275E0Fe7D5054373778960c99FD24F59ff52), the fee rate contract (0x75fa557bb38daa465f06f5e605e46abe0d5ce9ec), the vulnerable token claims contract (0xed1afc8c4604958c2f38a3408fa63b32e737c428), and the primary attacker address (0x75F2abA6a44580D7be2C4e42885D4a1917bFFD46). The BNB Chain exploit transaction (0x181a7882aac0eab1036eedba25bc95a16e10f61b5df2e99d240a16c334b9b189) and the Ethereum exploit transaction (0x743e4ee2c478300ac768fdba415eb4a23ae66981c076f9bff946c0bf530be0c7) are both publicly verifiable. On-chain analysis by SlowMist, PeckShield, and Bitrace tracked the attacker's movements and confirmed that approximately 2,500 BNB (roughly $715,000 at the time) was routed through Tornado Cash in an apparent attempt to launder proceeds. The attacker also allegedly attempted a withdrawal through the LATOKEN exchange. The combination of Tornado Cash mixing and exchange withdrawal attempts is consistent with deliberate asset concealment, though the attacker later engaged in on-chain communication with the Transit Finance team regarding fund return.","heading":"On-Chain Evidence","sources":[{"url":"https://slowmist.medium.com/cross-chain-dex-aggregator-transit-swap-hacked-analysis-74ba39c22020","name":"","type":"other","credibility":3},{"url":"https://www.numencyber.com/transit-swap-hack-analysis/","name":"","type":"other","credibility":3},{"url":"https://cryptoslate.com/transit-swap-hacker-returns-16-5m-of-stolen-funds/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Within approximately 24 hours of the exploit, the attacker returned roughly 70% of stolen assets — approximately $16.2–18.9 million — to two addresses on Ethereum and BNB Chain. The returned funds included 3,180 ETH (approximately $4.2 million), 1,500 Binance-Pegged ETH (approximately $2 million), and approximately $10–14 million worth of BNB. The recovery was facilitated by a collaborative effort among security firms SlowMist, PeckShield, and Bitrace, who were able to identify the attacker's IP address, email address, and associated on-chain addresses, and communicated with the attacker via both email and on-chain messaging. Following this initial return, negotiations continued regarding the remaining approximately 30% of funds. The attacker initially asserted a right to retain the balance, while Transit Finance counter-offered a 5% bounty. The attacker subsequently communicated — via on-chain message — that they were willing to reduce their retention demand to 10% if Transit Finance guaranteed 100% repayment to all affected users. No public confirmation exists that this second-stage recovery was completed. Transit Finance stated that if remaining funds could not be recovered, the platform itself would compensate affected users, though the mechanism and timeline for this were not specified in available sources. The attacker's alleged claim that they could have targeted additional chains for a further $100 million suggests a degree of restraint was exercised, though this claim is unverified and comes solely from attacker-side communications.","heading":"Partial Recovery","sources":[{"url":"https://cryptoslate.com/transit-swap-hacker-returns-16-5m-of-stolen-funds/","name":"","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/transit-swap-hacker-returns-70-of-23m-in-stolen-funds","name":"","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2022/10/03/transit-swap-exploiter-returns-large-chunk-of-289m-hack","name":"","type":"other","credibility":3},{"url":"https://www.theblock.co/post/174307/hacker-returns-70-of-21-million-taken-from-transit-swap-dex","name":"","type":"other","credibility":3},{"url":"https://247wallst.com/investing/2022/10/06/transit-swap-hacker-offers-to-return-90-of-funds-if-users-refunded/","name":"","type":"other","credibility":3},{"url":"https://forkast.news/hacker-return-funds-us23-mln-transit-swap/","name":"","type":"other","credibility":3}],"severity":"medium"},{"content":"Transit Swap's October 2022 exploit reflects multiple compounding risk factors. First, the swap contract was unverified at the time of the attack, making independent audit impossible and allowing a severe input validation flaw to persist undetected. Second, the platform's approval architecture — requiring users to grant broad token approvals to a centralized permissions management contract — created a single point of failure: once that contract was compromised, all user-granted approvals were exploitable. Third, between $3–10 million in residual funds remain unaccounted for, with a portion confirmed to have been laundered through Tornado Cash. Following the incident, Transit Finance relaunched on October 21, 2022 with a new contract audited by SlowMist, open-sourced code, an updated whitelist mechanism for external calls, and a $1,000,000 bug bounty program. A Transit Security Fund allocating 10% of monthly platform revenue toward security was also established. Despite these remediation steps, the platform's prior conduct — deploying an unverified contract for a protocol requiring large user token approvals — constitutes a significant historical risk factor. Affected users seeking compensation should note that the platform's commitment to repay users for unrecovered funds has not been verified against confirmed disbursements in available public sources.","heading":"Risk Assessment","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-transit-swap-hack-october-2022","name":"","type":"other","credibility":3},{"url":"https://docs.transit.finance/announcement/announcement/relaunch","name":"","type":"other","credibility":3},{"url":"https://www.vidma.io/blog/transit-swap-hack-a-21m-lesson-in-smart-contract-vulnerabilities","name":"","type":"other","credibility":3},{"url":"https://neptunemutual.com/blog/decoding-transit-finances-contract-vulnerability/","name":"","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2022-10","event":"Attacker exploits input validation vulnerability in Transit Swap's swap contract across Ethereum and BNB Chain, draining approximately $21–28.9 million in user funds.","source":"","date_original":"2022-10-01"},{"date":"2022-10-02","event":"SlowMist, Numen Cyber Labs, PeckShield, and Bitrace publish on-chain analysis identifying the attacker's address (0x75F2abA6a44580D7be2C4e42885D4a1917bFFD46), IP address, and email. Transit Finance issues a public apology.","source":""},{"date":"2022-10-02","event":"Attacker routes approximately 2,500 BNB through Tornado Cash and attempts a withdrawal via LATOKEN exchange.","source":""},{"date":"2022-10-03","event":"Attacker returns approximately 70% of stolen funds (roughly $16.2–18.9 million) to two addresses on Ethereum and BNB Chain, following communications with security firms and Transit Finance.","source":""},{"date":"2022-10-06","event":"Negotiations continue: attacker communicates on-chain willingness to return an additional portion of funds if Transit Finance guarantees 100% repayment to all affected users; Transit Finance had offered a 5% bounty, attacker countered at 10%.","source":""},{"date":"2022-10-21","event":"Transit Swap officially relaunches with a new open-source contract audited by SlowMist, a whitelist mechanism for external calls, a $1,000,000 bug bounty program, and a Transit Security Fund allocating 10% of monthly revenue to security.","source":""}],"sources_used":[{"url":"https://docs.transit.finance/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260511122536/https://docs.transit.finance/","credibility":3,"archive_timestamp":"2026-05-11T12:25:36+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-transit-swap-hack-october-2022","name":"","type":"other","archive_url":"http://web.archive.org/web/20260415072820/https://www.halborn.com/blog/post/explained-the-transit-swap-hack-october-2022","credibility":3,"archive_timestamp":"2026-04-15T07:28:20+00:00"},{"url":"https://medium.com/@TransitSwap/multi-chain-dex-aggregator-transit-swap-6f6c62ea3335","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://slowmist.medium.com/cross-chain-dex-aggregator-transit-swap-hacked-analysis-74ba39c22020","name":"","type":"other","archive_url":"http://web.archive.org/web/20260819234322/https://slowmist.medium.com/cross-chain-dex-aggregator-transit-swap-hacked-analysis-74ba39c22020","credibility":3,"archive_timestamp":"2026-08-19T23:43:22+00:00"},{"url":"https://www.numencyber.com/transit-swap-hack-analysis/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260610034623/https://www.numencyber.com/transit-swap-hack-analysis/","credibility":3,"archive_timestamp":"2026-06-10T03:46:23+00:00"},{"url":"https://beincrypto.com/hacker-exploits-21m-vulnerability-in-transit-swap/","name":"","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://blog.solidityscan.com/transit-swap-hack-analysis-13c1e04e7de0/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260830040511/https://blog.solidityscan.com/transit-swap-hack-analysis-13c1e04e7de0/","credibility":3,"archive_timestamp":"2026-08-30T04:05:11+00:00"},{"url":"https://cryptoslate.com/transit-swap-hacker-returns-16-5m-of-stolen-funds/","name":"","type":"other","archive_url":"http://web.archive.org/web/20251212041957/https://cryptoslate.com/transit-swap-hacker-returns-16-5m-of-stolen-funds/","credibility":3,"archive_timestamp":"2025-12-12T04:19:57+00:00"},{"url":"https://cointelegraph.com/news/transit-swap-hacker-returns-70-of-23m-in-stolen-funds","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829234613/https://cointelegraph.com/news/transit-swap-hacker-returns-70-of-23m-in-stolen-funds","credibility":3,"archive_timestamp":"2026-08-29T23:46:13+00:00"},{"url":"https://www.coindesk.com/business/2022/10/03/transit-swap-exploiter-returns-large-chunk-of-289m-hack","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.theblock.co/post/174307/hacker-returns-70-of-21-million-taken-from-transit-swap-dex","name":"","type":"other","archive_url":"http://web.archive.org/web/20260729134751/https://www.theblock.co/post/174307/hacker-returns-70-of-21-million-taken-from-transit-swap-dex","credibility":3,"archive_timestamp":"2026-07-29T13:47:51+00:00"},{"url":"https://247wallst.com/investing/2022/10/06/transit-swap-hacker-offers-to-return-90-of-funds-if-users-refunded/","name":"","type":"other","archive_url":"https://web.archive.org/web/20260829123440/https://247wallst.com/investing/2022/10/06/transit-swap-hacker-offers-to-return-90-of-funds-if-users-refunded/","credibility":3,"archive_timestamp":"2026-08-29T12:34:40+00:00"},{"url":"https://forkast.news/hacker-return-funds-us23-mln-transit-swap/","name":"","type":"other","archive_url":"http://web.archive.org/web/20260515053846/https://forkast.news/hacker-return-funds-us23-mln-transit-swap/","credibility":3,"archive_timestamp":"2026-05-15T05:38:46+00:00"},{"url":"https://docs.transit.finance/announcement/announcement/relaunch","name":"","type":"other","archive_url":"http://web.archive.org/web/20260307172444/https://docs.transit.finance/announcement/announcement/relaunch","credibility":3,"archive_timestamp":"2026-03-07T17:24:44+00:00"},{"url":"https://www.vidma.io/blog/transit-swap-hack-a-21m-lesson-in-smart-contract-vulnerabilities","name":"","type":"other","archive_url":"http://web.archive.org/web/20260315235923/https://www.vidma.io/blog/transit-swap-hack-a-21m-lesson-in-smart-contract-vulnerabilities","credibility":3,"archive_timestamp":"2026-03-15T23:59:23+00:00"},{"url":"https://neptunemutual.com/blog/decoding-transit-finances-contract-vulnerability/","name":"","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:47.898036+00:00","updated_at":"2026-08-30T05:14:12.57512+00:00"}}