Transit Swap 2022 routing and approval exploit
An input-validation flaw in Transit Swap routing and permissions contracts allowed attackers to transfer assets from wallets that had approved the affected contract. Public estimates varied from approximately USD 21 million to USD 28.9 million as the incident scope was reconciled, and substantial assets were later returned.
Incident facts
- Incident title
- Transit Swap 2022 routing and approval exploit
- Bridge
- Transit Swap
- Incident date
- 2022-10-01
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- BNB Chain, Ethereum, Unknown
- Affected assets
- ETH, WETH, BNB, USDC, USDT, Unknown
- Attack category
- Smart Contract Bug
- Reported loss
- USD 21 million initial technical estimate; USD 28.9 million later scope
- Amount confidence
- Disputed
- Loss amount basis
- Mixed Sources
- Recovery
- Partial Recovery
- Reimbursement
- Not Announced
- Restart
- Reopened
- Current outcome
- Active After Incident
- Postmortem
- Unclear
- Resolution
- Unresolved
- Last reviewed
- 2026-07-28
- Last verified
- 2026-07-28
Amount and valuation
Numen and early reporting described a loss near USD 21 million, while later reporting and SlowMist's incident database described approximately USD 28.9 million after broader reconciliation.
Retain the USD 21 million and USD 28.9 million figures because they represent different public snapshots and scopes. Returned funds are recorded separately and are not subtracted from the incident amount.
unauthorized user-asset transfers across affected approvalsnearly USD 21 million
Initial technical estimate used as the lower bound.
later reconciled incident scopeapproximately USD 28.9 million
Retained as the upper public scope rather than silently replacing the initial estimate.
Why this remains unresolved
- The final aggregate returned amount across the main attacker, imitators, arbitrageurs, and retained bounty is not fully reconciled in stable primary documentation.
- No reviewed source establishes a completed protocol-funded reimbursement program distinct from attacker returns.
Timeline events
Transit Swap routing exploit occurred2022-10-01
Attackers used an unchecked routing and permissions path to transfer assets from wallets that had approved the affected Transit Swap contract.
This is an aggregator routing and approval incident, not an underlying bridge-reserve compromise.
Transit Swap incident disclosed and traced2022-10-02
Transit Finance and security firms disclosed the incident, traced attacker addresses, and began communicating for asset return.
Main attacker returned approximately 70 percent2022-10-03
Security analysis and reporting stated that the main attacker returned approximately 70 percent of the initially reported stolen assets.
Attacker return is not protocol-funded reimbursement.
Swap and cross-chain services formally suspended2022-10-10
Transit Finance announced that swap and cross-chain swap services were suspended while technical upgrades continued.
Additional BNB returns reported2022-10-13
SlowMist's incident record reported additional BNB returns after an agreement with the principal attacker, while other actors and final reconciliation remained separate.
Do not infer full recovery from the principal-attacker agreement.
Transit Swap relaunched after contract replacement2022-10-21
Transit Finance restored swap and cross-chain functions after changing approval handling, whitelisting external calls, hardening bridge interactions, abolishing old-contract authority, publishing replacement contracts, and completing a SlowMist audit.
Relaunch does not establish completed restitution for every affected user.
Evidence records
- Cross-chain DEX Aggregator Transit Swap Hacked AnalysisSlowMist · Tier 1 · High reliability · secondary · 2022-10-02Claim scope: Incident Case
Technical routing and approval-path analysis with an initial amount above USD 23 million.
- Transit Swap Hack AnalysisNumen Cyber Labs · Tier 2 · High reliability · secondary · 2022-10-02Claim scope: Amount
Initial technical estimate near USD 21 million and approximately 70 percent returned.
- Hacker returns nearly USD 19 million stolen on Transit Swap DeFi platformRecorded Future News · Tier 2 · High reliability · secondary · 2022-10-04Claim scope: Recovery
Reports the later USD 28.9 million scope and just under USD 19 million returned.
- Main hacker in Transit Swap exploit agrees to return remaining fundsCointelegraph · Tier 2 · Medium reliability · secondary · 2022-10-10Claim scope: Recovery
Agreement and bounty context; does not establish complete recovery from all actors.
- Announcement on the suspension of TransitSwap serviceTransit Finance · Tier 1 · High reliability · primary · 2022-10-10Claim scope: Status
First-party suspension and upgrade notice.
- Transit Swap is officially re-launchTransit Finance · Tier 1 · High reliability · primary · 2022-10-21Claim scope: Restart
First-party relaunch and contract-hardening statement.
- SlowMist Hacked target: Transit SwapSlowMist · Tier 2 · High reliability · secondary · 2022-10-02Claim scope: Amount
Later USD 28.9 million incident scope and dated BNB-return entries.
- Cross-chain DEX Aggregator Transit Swap Hacked AnalysisSlowMist · Tier 1 · High reliability · secondary · 2022-10-02Claim scope: Incident Case
Event-scoped duplicate supporting Transit Swap disclosure, attacker tracing, and early response.
- Transit Swap Hack AnalysisNumen Cyber Labs · Tier 2 · High reliability · secondary · 2022-10-02Claim scope: Incident Case
Event-scoped duplicate independently supporting the disclosed routing and approval exploit.
- Transit Swap Hack AnalysisNumen Cyber Labs · Tier 2 · High reliability · secondary · 2022-10-02Claim scope: Recovery
Event-scoped duplicate supporting the approximately 70 percent asset return.
- Transit Finance recovery update: approximately 70 percent returnedTransit Finance · Tier 1 · High reliability · primary · 2022-10-02Claim scope: Recovery
First-party update reporting that approximately 70 percent of stolen assets had been returned to identified addresses.
- Updates about TransitFinanceTransit Finance · Tier 1 · High reliability · primary · 2022-10-12Claim scope: Recovery
First-party update recording a second returned-funds batch including 10,000 BNB and the cumulative recovery and reimbursement plan.
- Updates about TransitFinanceTransit Finance · Tier 1 · High reliability · primary · 2022-10-12Claim scope: Incident Case
Event-scoped duplicate of bir_src_000279: Transit Finance states that hackers attacked at 18:33 UTC on October 1, 2022 and reports the later reconciled USD 28.9 million scope; technical routing-path analysis remains supported by independent security sources.
- Updates about TransitFinanceTransit Finance · Tier 1 · High reliability · primary · 2022-10-12Claim scope: Incident Case
Event-scoped duplicate of bir_src_000279: Transit Finance directly acknowledges the incident and documents attacker/white-hat buckets, returned and unrecovered amounts, and continuing recovery/legal handling; independent security sources retain detailed tracing analysis.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- The exact final value of assets retained as bounty or left with copycat actors remains unresolved.
- Public amount estimates changed during the first days of incident reconciliation.
- A service relaunch does not prove that every affected user received full restitution.
Conflicting claims
Reported incident amount
Reported values: Nearly USD 21 million initial technical estimate · Approximately USD 28.9 million later reconciled scope
Current treatment: Retain a range because the sources reflect different snapshots and scopes.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.