Transit Swap 2022 routing and approval exploit
An input-validation flaw in Transit Swap routing and permissions contracts allowed attackers to transfer assets from wallets that had approved the affected contract. Public estimates varied from approximately USD 21 million to USD 28.9 million as the incident scope was reconciled, and substantial assets were later returned.
Incident facts
- Incident title
- Transit Swap 2022 routing and approval exploit
- Bridge
- Transit Swap
- Incident date
- 2022-10-01
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- BNB Chain, Ethereum, Unknown
- Affected assets
- ETH, WETH, BNB, USDC, USDT, Unknown
- Attack category
- Smart Contract Bug
- Reported loss
- USD 21 million initial technical estimate; USD 28.9 million later scope
- Recovery
- Partial Recovery
- Reimbursement
- Not Announced
- Restart
- Reopened
- Current outcome
- Active After Incident
- Resolution
- Unresolved
- Last reviewed
- 2026-07-28
- Last verified
- 2026-07-28
Timeline events
Transit Swap routing exploit occurred2022-10-01
Attackers used an unchecked routing and permissions path to transfer assets from wallets that had approved the affected Transit Swap contract.
Transit Swap incident disclosed and traced2022-10-02
Transit Finance and security firms disclosed the incident, traced attacker addresses, and began communicating for asset return.
Main attacker returned approximately 70 percent2022-10-03
Security analysis and reporting stated that the main attacker returned approximately 70 percent of the initially reported stolen assets.
Swap and cross-chain services formally suspended2022-10-10
Transit Finance announced that swap and cross-chain swap services were suspended while technical upgrades continued.
Additional BNB returns reported2022-10-13
SlowMist's incident record reported additional BNB returns after an agreement with the principal attacker, while other actors and final reconciliation remained separate.
Transit Swap relaunched after contract replacement2022-10-21
Transit Finance restored swap and cross-chain functions after changing approval handling, whitelisting external calls, hardening bridge interactions, abolishing old-contract authority, publishing replacement contracts, and completing a SlowMist audit.
Evidence records
- Cross-chain DEX Aggregator Transit Swap Hacked AnalysisSlowMist · Tier 1 · 2022-10-02
- Transit Swap Hack AnalysisNumen Cyber Labs · Tier 2 · 2022-10-02
- Hacker returns nearly USD 19 million stolen on Transit Swap DeFi platformRecorded Future News · Tier 2 · 2022-10-04
- Main hacker in Transit Swap exploit agrees to return remaining fundsCointelegraph · Tier 2 · 2022-10-10
- Announcement on the suspension of TransitSwap serviceTransit Finance · Tier 1 · 2022-10-10
- Transit Swap is officially re-launchTransit Finance · Tier 1 · 2022-10-21
- SlowMist Hacked target: Transit SwapSlowMist · Tier 2 · 2022-10-02
Known unknowns
- The exact final value of assets retained as bounty or left with copycat actors remains unresolved.
- Public amount estimates changed during the first days of incident reconciliation.
- A service relaunch does not prove that every affected user received full restitution.