Skip to main content
Sign in
TeleSwap1 decision on this page

Audit log

Every state-changing event for TeleSwap: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions carry three independent witnesses — the original source, an Internet Archive snapshot taken at submission time, and a Solana memo signed by our publicly-disclosed publisher key.

  1. #1publishby system:backfill
    2026-07-22 02:26:06Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    MSrq5d6wDZst…EBQzjxUosha256 → base58
    verifying row…
    canonical bytes (11435 B) ▸
    {"actor":"system:backfill","investigation_id":"488caf70-269a-41ac-9388-4207e8167b2b","kind":"publish","page_slug":"teleswap","published_at":"2026-07-22T02:26:06.469Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"TeleSwap","sections":[{"content":"TeleSwap is a cross-chain bridge and swap protocol, rebranded from TeleportDAO, that describes itself as a \"fully trustless bridge protocol\" enabling transfers of Bitcoin and Runes to EVM-compatible chains, TON, and Solana. Its architecture is built around a light-client verification system, decentralized custodians referred to as \"Lockers\" and \"Teleporters,\" a native TeleportDAO Bitcoin bridge, and an integrated AMM DEX. The protocol's native token is TST (Teleport System Token), with a fixed supply of 1,000,000,000. TeleSwap raised a $2.5 million seed round in March 2023 led by AppWorks and DefinanceX, with participation from CoinList, Gate Labs, Quantstamp, SNZ Holding, and Candaq Fintech Group, followed by a $7.125 million public token sale in April 2024 at a $75 million valuation. Separately, a CoinGecko-listed token also named \"TeleSwap\" (ticker TSWAP) exists on The Open Network (TON) as a Telegram mini-app swap exchange; that token has a market capitalization of roughly $1,200 and appears to have stopped trading on all listed exchanges as of mid-2026. It is unclear from available sources whether this TON-based TSWAP token has any operational relationship to the teleswap.xyz Bitcoin-bridge project, and this naming overlap should not be conflated when assessing the bridge exploit allegations below.","heading":"What TeleSwap Is","severity":"low","sources":[{"credibility":2,"name":"TeleSwap Docs — Protocol Overview","type":"official","url":"https://docs.teleswap.xyz/inside-teleswap/protocol-overview"},{"credibility":2,"name":"TeleSwap (ex TeleportDAO) — Interoperability Project, Crypto-Fundraising","type":"research","url":"https://crypto-fundraising.info/projects/teleportdao/"},{"credibility":2,"name":"TeleSwap Price (TSWAP/USD), CoinGecko","type":"on_chain","url":"https://www.coingecko.com/en/coins/teleswap"},{"credibility":2,"name":"Teleport System Token (TST) Tokenomics, TeleSwap Docs","type":"official","url":"https://docs.teleswap.xyz/protocol/tokenomics/"}]},{"content":"On July 15, 2026, TeleSwap's Bitcoin hot wallet allegedly experienced suspicious outflows totaling over $735,000 before ceasing to process transactions. The incident is recorded in SlowMist's Hacked incident database, which lists the date, the approximate loss figure, and notes the attack method as \"Unknown\" — indicating that even this security-research tracker did not have a confirmed technical root cause at the time of listing. Multiple crypto-news aggregators reported that the funds were subsequently moved through Tornado Cash, a mixing service commonly used to obscure the trail of stolen crypto assets. No party — including TeleSwap itself — has published a detailed technical explanation of how the alleged exploit occurred, and no independent, named security firm has issued a signed root-cause report specific to TeleSwap. A separate, differently-sourced description surfaced during research describing a zero-knowledge-proof verification bypass tied to a bridge loss of roughly $5 million; that description appears in search results under a conflated \"TeleSwap/ZKSwap\" label and could not be independently confirmed as pertaining to TeleSwap rather than the unrelated ZKSwap protocol, so it is not treated as a verified claim about TeleSwap here.","heading":"Alleged July 2026 Bridge Exploit (~$735,000)","severity":"high","sources":[{"credibility":2,"name":"SlowMist Hacked incident database — TeleSwap entry","type":"research","url":"https://hacked.slowmist.io/"},{"credibility":3,"name":"Across, Allbridge, TeleSwap lost $5.7M to bridge hacks in past week — BitRss","type":"news_article","url":"https://bitrss.com/across-allbridge-teleswap-lost-5-7m-to-bridge-hacks-in-past-week-233544"}]},{"content":"Pseudonymous blockchain investigator ZachXBT publicly stated that TeleSwap had been exploited on July 15, 2026, and criticized the project for \"not disclos[ing] the incident publicly after five days.\" As of the most recent available reporting, TeleSwap's official X (Twitter) account had not acknowledged the alleged attack, and no incident report, user-fund-safety statement, or remediation plan had been published by the project. A prolonged silence of this kind following a suspected loss of user or protocol funds is, independent of the unresolved technical details, treated here as a governance and transparency red flag, consistent with patterns seen in other under-disclosed bridge incidents. Because TeleSwap has not corroborated or denied the claim, it is not possible to independently verify the exact loss amount, whether user funds (versus protocol-owned liquidity) were affected, or the current status of any recovery effort.","heading":"Non-Disclosure and Transparency Concerns","severity":"high","sources":[{"credibility":3,"name":"Across, Allbridge, TeleSwap lost $5.7M to bridge hacks in past week — BitRss (citing ZachXBT)","type":"news_article","url":"https://bitrss.com/across-allbridge-teleswap-lost-5-7m-to-bridge-hacks-in-past-week-233544"},{"credibility":2,"name":"ZachXBT — Wikipedia (background on the investigator cited)","type":"other","url":"https://en.wikipedia.org/wiki/ZachXBT"}]},{"content":"This investigation should be read with the understanding that the underlying story is thinly sourced. Every account of the alleged exploit found during research traces back to the same two threads: a claim attributed to on-chain investigator ZachXBT, and a corresponding entry in SlowMist's community-maintained \"Hacked\" incident tracker (which itself lists the attack method as unknown). No Tier-1 outlet (e.g., Reuters, Bloomberg, major wire services) and no established crypto-native newsroom byline (e.g., CoinDesk, The Block, Decrypt) coverage was located during multiple targeted searches; the only narrative write-up identified was from a lower-tier aggregator site (BitRss) republishing the ZachXBT/SlowMist claims alongside two other unrelated bridge incidents (Allswap, Across Protocol) from the same week. TeleSwap has not issued any statement confirming, denying, or clarifying the incident. Given this, confidence in the specific dollar figure, attack vector, and scope of the alleged exploit is low-to-moderate; confidence that a suspicious wallet event and public non-disclosure occurred is comparatively higher, since it is consistently reported across the available (if limited) sources.","heading":"Sourcing Quality Assessment","severity":"medium","sources":[{"credibility":3,"name":"Across, Allbridge, TeleSwap lost $5.7M to bridge hacks in past week — BitRss","type":"news_article","url":"https://bitrss.com/across-allbridge-teleswap-lost-5-7m-to-bridge-hacks-in-past-week-233544"},{"credibility":2,"name":"SlowMist Hacked incident database","type":"research","url":"https://hacked.slowmist.io/"}]},{"content":"The alleged TeleSwap incident was reported as part of a cluster of cross-chain bridge attacks in the same week: reporting indicates Allswap lost approximately $1.65 million and Across Protocol lost approximately $3.35 million in incidents around the same period, for a combined figure cited as roughly $5.7 million across the three protocols. This context does not itself establish additional wrongdoing by TeleSwap, but indicates that cross-chain bridges broadly remained a high-value attack surface in mid-2026, consistent with their historical status as frequent targets given the liquidity they custody.","heading":"Broader Context: Wave of Bridge Hacks (Week of July 15, 2026)","severity":"low","sources":[{"credibility":3,"name":"Across, Allbridge, TeleSwap lost $5.7M to bridge hacks in past week — BitRss","type":"news_article","url":"https://bitrss.com/across-allbridge-teleswap-lost-5-7m-to-bridge-hacks-in-past-week-233544"}]}],"sources_used":[{"credibility":2,"name":"TeleSwap Docs — Protocol Overview","type":"official","url":"https://docs.teleswap.xyz/inside-teleswap/protocol-overview"},{"credibility":2,"name":"TeleSwap (ex TeleportDAO) — Interoperability Project, Crypto-Fundraising","type":"research","url":"https://crypto-fundraising.info/projects/teleportdao/"},{"credibility":2,"name":"TeleSwap Price (TSWAP/USD), CoinGecko","type":"on_chain","url":"https://www.coingecko.com/en/coins/teleswap"},{"credibility":2,"name":"Teleport System Token (TST) Tokenomics, TeleSwap Docs","type":"official","url":"https://docs.teleswap.xyz/protocol/tokenomics/"},{"credibility":2,"name":"SlowMist Hacked incident database — TeleSwap entry","type":"research","url":"https://hacked.slowmist.io/"},{"credibility":3,"name":"Across, Allbridge, TeleSwap lost $5.7M to bridge hacks in past week — BitRss","type":"news_article","url":"https://bitrss.com/across-allbridge-teleswap-lost-5-7m-to-bridge-hacks-in-past-week-233544"},{"credibility":2,"name":"ZachXBT — Wikipedia","type":"other","url":"https://en.wikipedia.org/wiki/ZachXBT"}],"summary":"TeleSwap (formerly TeleportDAO) is a cross-chain bridge protocol that lets users move Bitcoin and Runes to EVM chains, TON, and Solana using light-client and \"Locker\"/\"Teleporter\" custodian architecture, funded by a $2.5M 2023 seed round and a 2024 public token sale. On July 15, 2026, on-chain investigator ZachXBT and the SlowMist Hacked incident database reported suspicious outflows of roughly $735,000 from TeleSwap's Bitcoin hot wallet followed by laundering through Tornado Cash; as of this writing TeleSwap has not issued a public confirmation, technical postmortem, or the underlying transaction details, which is itself a notable transparency concern. Overall reporting quality on the incident is thin — it traces back mainly to one investigator's claim and aggregator write-ups rather than a project statement, a named security-firm root-cause report, or Tier-1 news coverage, so key facts (attack vector, exact amount, affected users) remain unverified.","timeline":[{"date":"2023-03-01","event":"TeleportDAO (later rebranded TeleSwap) raises a $2.5 million seed round led by AppWorks and DefinanceX, with participation from CoinList, Gate Labs, Quantstamp, SNZ Holding, and Candaq Fintech Group.","source":"Crypto-Fundraising project profile","source_url":"https://crypto-fundraising.info/projects/teleportdao/"},{"date":"2024-04-01","event":"TeleportDAO/TeleSwap completes a $7.125 million public token sale at a $75 million valuation.","source":"Crypto-Fundraising project profile","source_url":"https://crypto-fundraising.info/projects/teleportdao/"},{"date":"2026-07-15","event":"Suspicious outflows of roughly $735,000 are recorded from TeleSwap's Bitcoin hot wallet; the wallet reportedly stops processing transactions shortly afterward. Attack method listed as unknown.","source":"SlowMist Hacked incident database","source_url":"https://hacked.slowmist.io/"},{"date":"2026-07-20","event":"Blockchain investigator ZachXBT publicly states TeleSwap was exploited on July 15 and criticizes the project for not disclosing the incident five days later; reports indicate the stolen funds were routed through Tornado Cash.","source":"BitRss (aggregating ZachXBT statement)","source_url":"https://bitrss.com/across-allbridge-teleswap-lost-5-7m-to-bridge-hacks-in-past-week-233544"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 7fbaa8b5-60f2-4c4f-9fab-f5c6d1f014ee
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.