{"id":67953,"date":"2022-10-02T10:22:41","date_gmt":"2022-10-02T07:22:41","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=67953"},"modified":"2025-09-07T11:24:02","modified_gmt":"2025-09-07T08:24:02","slug":"decentralized-exchange-transit-swap-loses-21-million-in-hacker-attack","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/decentralized-exchange-transit-swap-loses-21-million-in-hacker-attack\/","title":{"rendered":"Decentralized exchange Transit Swap loses $21 million in hacker attack"},"content":{"rendered":"<p>The decentralized cross-chain exchange Transit Swap has lost about $21 million in a hacker attack. The attacker exploited a bug in the service&#8217;s smart contract.<\/p>\n<blockquote class=\\\"twitter-tweet\\\">\n<p lang=\\\"en\\\" dir=\\\"ltr\\\">1\/2 According to the analysis of data on chain, TransitSwap has been attacked by hackers. The technical team has urgently suspended the service, and the contract has been completely suspended, no operations can be performed.<\/p>\n<p>\u2014 Transit Swap | Transit Buy | NFT (@TransitFinance) <a href=\\\"https:\/\/twitter.com\/TransitFinance\/status\/1576331732349222912?ref_src=twsrc%5Etfw\\\">October 1, 2022<\/a><\/p><\/blockquote>\n<p> <script async=\\\"\\\" src=\\\"https:\/\/platform.twitter.com\/widgets.js\\\" charset=\\\"utf-8\\\"><\/script><\/p>\n<blockquote class=\\\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\\\">\n<p>&#8220;According to on-chain data analysis, Transit Swap has been attacked by a hacker. The technical team urgently suspended the service and the smart contract; no operations on the platform can be performed,&#8221; the statement said.<\/p>\n<\/blockquote>\n<div class=\\\"wp-block-text-wrappers-update-2 article_update\\\"><time class=\\\"gtb_text-wrappers_update_time\\\">2 October 2022 | 13:51<\/time><span class=\\\"gtb_text-wrappers_update_head\\\">Update: <\/span>\\n<\/p>\n<p>The project team said that the hacker returned about 70% of the stolen funds. The attacker was asked to contact the developers.<\/p>\n<blockquote class=\\\"twitter-tweet\\\">\n<p lang=\\\"en\\\" dir=\\\"ltr\\\">\ud83d\udce2\ud83d\udce2\ud83d\udce2Updates about TransitFinance<br \/>1\/5 We are here to update the latest news about TransitFinance Hacking Event. With the joint efforts of all parties, the hacker has returned about 70% of the stolen assets to the following two addresses:<\/p>\n<p>\u2014 Transit Swap | Transit Buy | NFT (@TransitFinance) <a href=\\\"https:\/\/twitter.com\/TransitFinance\/status\/1576463550557483008?ref_src=twsrc%5Etfw\\\">October 2, 2022<\/a><\/p><\/blockquote>\n<p> <script async=\\\"\\\" src=\\\"https:\/\/platform.twitter.com\/widgets.js\\\" charset=\\\"utf-8\\\"><\/script>\n<\/div>\n<p>Later, Transit Swap explained that the attacker exploited a bug in the project&#8217;s codebase. According to PeckShield researchers, the exploit is linked to the smart contract responsible for swap operations.<\/p>\n<blockquote class=\\\"twitter-tweet\\\">\n<p lang=\\\"en\\\" dir=\\\"ltr\\\">\ud83d\udea8 \ud83d\udea8 \ud83d\udea8 It seems there is a composability issue with or misplaced trust on the swap contract of <a href=\\\"https:\/\/twitter.com\/TransitFinance?ref_src=twsrc%5Etfw\\\">@TransitFinance<\/a> that just results in the loss of >$15M. The stolen funds are located at: <a href=\\\"https:\/\/t.co\/NRwWJncFpl\\\">https:\/\/t.co\/NRwWJncFpl<\/a> <a href=\\\"https:\/\/t.co\/j8mgySbRRF\\\">pic.twitter.com\/j8mgySbRRF<\/a><\/p>\n<p>\u2014 PeckShield Inc. (@peckshield) <a href=\\\"https:\/\/twitter.com\/peckshield\/status\/1576312546482475008?ref_src=twsrc%5Etfw\\\">October 1, 2022<\/a><\/p><\/blockquote>\n<p> <script async=\\\"\\\" src=\\\"https:\/\/platform.twitter.com\/widgets.js\\\" charset=\\\"utf-8\\\"><\/script><\/p>\n<p>Analysts estimated the value of the stolen assets at about $21 million.<\/p>\n<blockquote class=\\\"twitter-tweet\\\">\n<p lang=\\\"en\\\" dir=\\\"ltr\\\">Here comes the flow of stolen assets w\/ the cost of ~$21M. <a href=\\\"https:\/\/twitter.com\/0xTransition?ref_src=twsrc%5Etfw\\\">@0xTransition<\/a> Note the hacker may have performed earlier withdrawals from known exchanges. <a href=\\\"https:\/\/t.co\/cZhQk2fotf\\\">https:\/\/t.co\/cZhQk2fotf<\/a> <a href=\\\"https:\/\/t.co\/eGGFiD0LIW\\\">pic.twitter.com\/eGGFiD0LIW<\/a><\/p>\n<p>\u2014 PeckShield Inc. (@peckshield) <a href=\\\"https:\/\/twitter.com\/peckshield\/status\/1576419241414524929?ref_src=twsrc%5Etfw\\\">October 2, 2022<\/a><\/p><\/blockquote>\n<p> <script async=\\\"\\\" src=\\\"https:\/\/platform.twitter.com\/widgets.js\\\" charset=\\\"utf-8\\\"><\/script><\/p>\n<p>The developers noted that SlowMist and other security-focused blockchain-service providers were brought in to investigate the incident.<\/p>\n<blockquote class=\\\"twitter-tweet\\\">\n<p lang=\\\"en\\\" dir=\\\"ltr\\\">3\/4 we now have a lot of valid information such as the hacker\u2019s IP, email address, and associated on-chain addresses. We will try our best to track the hacker and try to communicate with the hacker and help everyone recover their losses.<\/p>\n<p>\u2014 Transit Swap | Transit Buy | NFT (@TransitFinance) <a href=\\\"https:\/\/twitter.com\/TransitFinance\/status\/1576414287261638656?ref_src=twsrc%5Etfw\\\">October 2, 2022<\/a><\/p><\/blockquote>\n<p> <script async=\\\"\\\" src=\\\"https:\/\/platform.twitter.com\/widgets.js\\\" charset=\\\"utf-8\\\"><\/script><\/p>\n<blockquote class=\\\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\\\">\n<p>&#8220;We now have more verified information such as the hacker&#8217;s IP address, email address, and affiliated on-chain addresses. We will do our best to track the hacker, contact him, and help everyone recover their losses,&#8221; said Transit Swap.<\/p>\n<\/blockquote>\n<p>Earlier in September 2022, market maker Wintermute <a href=\"https:\/\/u1f987.com\/en\/news\/hackers-stole-160-million-from-wintermute\">lost assets worth $160 million<\/a> in a hacker attack.<\/p>\n<p>Follow ForkLog&#8217;s Bitcoin news on our <a href=\\\"\/\/telegram.me\/forklog\\\" target=\\\"\u201c_blank\u201d\\\" rel=\\\"\u201cnofollow\u201d noopener\\\">Telegram<\/a> \u2014 crypto news, prices and analysis.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Decentralized cross-chain exchange Transit Swap has lost about $21 million in a hacker attack. The attacker exploited a bug in the service&#8217;s smart contract.<\/p>\n","protected":false},"author":1,"featured_media":67954,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1154,787],"class_list":["post-67953","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-crimes","tag-dex"],"aioseo_notices":[],"amp_enabled":true,"views":"19","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/67953","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=67953"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/67953\/revisions"}],"predecessor-version":[{"id":67955,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/67953\/revisions\/67955"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/67954"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=67953"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=67953"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=67953"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}