Oct 2022 - Transit Finance Swap Exploit Thefts - $28.69m (Global)

"On Friday last week, the hacker capitalized on an exploit on Transit Swap's swap contract, which typically facilitates the exchange of assets."
A hacker that stole $28.9 million from cross-bridge DeFi platform Transit Finance transferred 2,500 BNB tokens ($686,000) to sanctioned privacy protocol Tornado Cash. The hacker also reportedly agreed to return 10,000 BNB ($2.74 million) to victims of the exploit.
"Transit Swap said that $18.9 million has been returned after a slew of security firms helped triangulate the hacker's IP address."
"Transit Swap, a cross-chain decentralized exchange (DEX), has received 70% of stolen funds back from a hacker that exploited a smart contract vulnerability."
"Up to now, white hats have returned funds worth $24M, and funds worth $4.9M remained unrefunded (144,000 USDT worth of funds were sent into the blackhole by hacker#1 and permanently destroyed, and 1.4 million USDT worth of funds were lost when hacked#1 swap USDT to BNB and cannot be recovered forever)."
"With a responsible attitude towards users’ assets, TransitFinance Official will bear 100% of users’ losses"
"On October 14th, users can visit the refund website to claim the second batch of refunds and certificates(TS)."
"The remaining 3.94 million certificates(TS) will be exchanged monthly, and TransitFinance Official will give users an additional 3% as a waiting reward."
Further Analysis
A hacker exploited a vulnerability in cross-chain DeFi platform Transit Finance, stealing $28.9 million. The hacker transferred 2,500 BNB tokens ($686,000) to Tornado Cash, a sanctioned privacy protocol. The hacker agreed to return 10,000 BNB ($2.74 million) to victims of the exploit. Security firms helped trace the hacker's IP address, leading to the return of $18.9 million. Transit Swap, the DEX affected, has received 70% of stolen funds back, with white hat hackers returning $24 million. Some funds were destroyed and irrecoverable. TransitFinance has taken responsibility for users' losses and will facilitate refunds and certificates for affected users. Additional rewards are also being offered to users waiting for refunds.
How Could This Have Been Prevented?
More Cryptocurrency Exchange Hacks/Scams/Frauds
Memeland MVP NFT Scammed Raymond Lai > > < < Wintermute Profanity Private Key Breach
Sources/Further Reading
Transit Swap Exploiter Returns Large Chunk of $28.9M Hack (Dec 31)
TransitSwap Exploiter | Address 0x75f2aba6a44580d7be2c4e42885d4a1917bffd46 | BscScan
(Dec 31)
https://medium.com/@TransitSwap/updates-about-transitfinance-317f4fe67931 (Dec 31)
BNB Smart Chain Transaction Hash (Txhash) Details | BscScan
(Dec 31)
BNB Smart Chain Transaction Hash (Txhash) Details | BscScan
(Dec 31)
https://medium.com/@TransitSwap/updates-about-transitfinance-4731c38d6910 (Dec 31)
Ethereum Transaction Hash (Txhash) Details | Etherscan
(Dec 31)
https://medium.com/@TransitSwap/transit-swap-is-officially-re-launch-abe58f242d28 (Dec 31)
https://medium.com/@TransitSwap/updates-about-transitfinance-1a7c821b34f7 (Dec 31)
https://medium.com/@TransitSwap/transit-swap-refund-update-dec-5th-2022-e57a355caabb (Dec 31)
https://medium.com/@TransitSwap/transit-swap-refund-update-nov-25th-2022-7c4a6479da8a (Dec 31)
https://medium.com/@TransitSwap/updates-about-transitfinance-1f955e5f2787 (Dec 31)
https://medium.com/@TransitSwap/updates-about-transitfinance-79bee950c33f (Dec 31)
https://medium.com/@TransitSwap/updates-about-transitfinance-dbeb146363a0 (Dec 31)
https://medium.com/@TransitSwap/updates-about-transitfinance-13328734eeb (Dec 31)
https://medium.com/@TransitSwap/updates-about-transitfinance-d05176918897 (Dec 31)
Transit Swap (Dec 31)
Transit Swap (Dec 31)
t.me/QuadrigaInitiative
|
/r/QuadrigaInitiative
|
@QuadrigaInit
|
info@quadrigainitiative.com
|
t.me/QuadrigaInitiative
/r/QuadrigaInitiative
@QuadrigaInit
info@quadrigainitiative.com