Transit Swap ‘hacker’ returns 70% of $23M in stolen funds

Transit Swap ‘hacker’ returns 70% of $23M in stolen funds



A quick response from a number of blockchain security companies has helped facilitate the return of around 70% of the $23 million exploit of decentralized exchange (DEX) aggregator Transit Swap.

The DEX aggregator lost the funds after a hacker exploited an internal bug on a swap contract on Oct. 1, leading to a quick response from the Transit Finance team along with security companies Peckshield, SlowMist, Bitrace and TokenPocket, who were able to quickly work out the hacker’s IP, email address and associated-on chain addresses.

It appears these efforts have already borne fruit, as less than 24 hours after the hack, Transit Finance noted that “with joint efforts of all parties,” the hacker has returned 70% of the stolen assets to two addresses, equating to roughly $16.2 million.

These funds came in the form of 3,180 Ether (ETH) at $4.2 million, 1,500 Binance-Peg ETH at $2 million and 50,000 BNB at $14.2 million, according to BscScan and EtherScan.

okex

In the most recent update, Transit Finance stated that “the project team is rushing to collect the specific data of the stolen users and formulate a specific return plan” but also remains focused on retrieving the final 30% of stolen funds.

At present, the security companies and project teams of all parties are still continuing to track the hacking incident and communicate with the hacker through email and on-chain methods. The team will continue to work hard to recover more assets,” it said. 

Related: $160M stolen from crypto market maker Wintermute

Cybersecurity firm SlowMist in an analysis of the incident noted that the hacker used a vulnerability in Transit Swap’s smart contract code, which came directly from the transferFrom() function, which essentially allowed users’ tokens to be transferred directly to the exploiter’s address:

“The root cause of this attack is that the Transit Swap protocol does not strictly check the data passed in by the user during token swap, which leads to the issue of arbitrary external calls. The attacker exploited this arbitrary external call issue to steal the tokens approved by the user for Transit Swap.”



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *

You have not selected any currency to display

Pin It on Pinterest

Crypto-Moon
BTCC
Crypto-Moon
Transit Swap ‘hacker’ returns 70% of $23M in stolen funds
okex
BTCC
Ether's Spike In Social Dominance Signals Potential Price Risk
Hyperlane’s Warp Routes 2.0 Sends HYPER to New All-Time High
Ripple Co-Founder Moves $175M XRP, Draws Criticism Over Timing
Should Investors Buy Low-Cap Altcoins in Q3 2025? Analysts Weigh In
Spot Bitcoin ETFs Surge with $363M Inflows, Extend 12-Day Rally to $6.6B
Altcoin Season Expected by November End: Analyst Says ‘Buy and Hold’
BTCC
Changelly
Hive Digital Technologies Rings Nasdaq Closing Bell, Eyes $100M HPC Growth
Robinhood US lists Hedera HBAR, extending support for classic coins following XRP, SOL, ADA
Ethereum ETFs Hit 1 Year On US Market
Tea App That Claimed to Protect Women Exposes 72,000 IDs in Epic Security Fail
Dragonfly Capital Faces DOJ Threat Over Tornado Cash Ties
Hive Digital Technologies Rings Nasdaq Closing Bell, Eyes $100M HPC Growth
Robinhood US lists Hedera HBAR, extending support for classic coins following XRP, SOL, ADA
Ethereum ETFs Hit 1 Year On US Market
Tea App That Claimed to Protect Women Exposes 72,000 IDs in Epic Security Fail