Incident case

Transit Swap 2022 routing and approval exploit

An input-validation flaw in Transit Swap routing and permissions contracts allowed attackers to transfer assets from wallets that had approved the affected contract. Public estimates varied from approximately USD 21 million to USD 28.9 million as the incident scope was reconciled, and substantial assets were later returned.

reviewedcurrent

Incident facts

Incident title
Transit Swap 2022 routing and approval exploit
Bridge
Transit Swap
Incident date
2022-10-01
Incident type
Exploit
Major incident
Yes
Affected chains
BNB Chain, Ethereum, Unknown
Affected assets
ETH, WETH, BNB, USDC, USDT, Unknown
Attack category
Smart Contract Bug
Reported loss
USD 21 million initial technical estimate; USD 28.9 million later scope
Amount confidence
Disputed
Loss amount basis
Mixed Sources
Recovery
Partial Recovery
Reimbursement
Not Announced
Restart
Reopened
Current outcome
Active After Incident
Postmortem
Unclear
Resolution
Unresolved
Last reviewed
2026-07-28
Last verified
2026-07-28

Amount and valuation

Numen and early reporting described a loss near USD 21 million, while later reporting and SlowMist's incident database described approximately USD 28.9 million after broader reconciliation.

Retain the USD 21 million and USD 28.9 million figures because they represent different public snapshots and scopes. Returned funds are recorded separately and are not subtracted from the incident amount.

Why this remains unresolved

Timeline events

  • Transit Swap routing exploit occurred2022-10-01

    Attackers used an unchecked routing and permissions path to transfer assets from wallets that had approved the affected Transit Swap contract.

    Exploit OccurredHigh

    This is an aggregator routing and approval incident, not an underlying bridge-reserve compromise.

  • Transit Swap incident disclosed and traced2022-10-02

    Transit Finance and security firms disclosed the incident, traced attacker addresses, and began communicating for asset return.

    Hack DisclosedHigh
  • Main attacker returned approximately 70 percent2022-10-03

    Security analysis and reporting stated that the main attacker returned approximately 70 percent of the initially reported stolen assets.

    Funds ReturnedHigh

    Attacker return is not protocol-funded reimbursement.

  • Swap and cross-chain services formally suspended2022-10-10

    Transit Finance announced that swap and cross-chain swap services were suspended while technical upgrades continued.

    Transfers SuspendedHigh
  • Additional BNB returns reported2022-10-13

    SlowMist's incident record reported additional BNB returns after an agreement with the principal attacker, while other actors and final reconciliation remained separate.

    Funds ReturnedMedium

    Do not infer full recovery from the principal-attacker agreement.

  • Transit Swap relaunched after contract replacement2022-10-21

    Transit Finance restored swap and cross-chain functions after changing approval handling, whitelisting external calls, hardening bridge interactions, abolishing old-contract authority, publishing replacement contracts, and completing a SlowMist audit.

    Bridge ReopenedHigh

    Relaunch does not establish completed restitution for every affected user.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Conflicting claims

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.