{"id":36974,"date":"2022-10-03T05:02:41","date_gmt":"2022-10-03T09:02:41","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=36974"},"modified":"2022-10-03T05:02:44","modified_gmt":"2022-10-03T09:02:44","slug":"transit-swap-recovers-70-of-stolen-funds-from-recent-hack","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/transit-swap-recovers-70-of-stolen-funds-from-recent-hack\/","title":{"rendered":"Transit Swap recovers 70% of stolen funds from recent hack"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\" id=\"h-transit-swap-a-dex-aggregator-was-recently-hacked-to-the-tune-of-23-million-due-to-a-swift-response-from-many-blockchain-security-firms-about-70-of-the-stolen-funds-have-been-returned\">Transit Swap, a<a href=\"https:\/\/coinscreed.com\/staging\/dex-aggregator-trading-volumes-reaches-new-all-time-high.html\"> DEX aggregator <\/a>was recently hacked to the tune of $23 million, due to a swift response from many blockchain security firms about 70%of the stolen funds have been returned.<\/h5>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/10\/image.png\" alt=\"Transit Swap recovers 70% of stolen funds from recent hack\" class=\"wp-image-36977\" width=\"632\" height=\"348\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/10\/image.png 439w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/10\/image-300x165.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/10\/image-150x83.png 150w\" sizes=\"(max-width: 632px) 100vw, 632px\" \/><figcaption>Transit Swap recovers 70% of stolen funds from recent hack<\/figcaption><\/figure>\n\n\n\n<p>The Transit Swap DEX aggregator lost the funds on October 1 after a hacker took advantage of an internal flaw in a swap contract. The Transit Finance team and security firms Peckshield, SlowMist, Bitrace, and TokenPocket responded quickly and were able to identify the hacker's IP address, email address, and associated-on-chain addresses.<\/p>\n\n\n\n<p>Less than 24 hours after the hack, <a href=\"https:\/\/www.google.com\/search?q=Transit+Swap+recovers+70%25+of+stolen+funds+from+recent+hack&rlz=1C1SQJL_enNG889NG889&oq=Transit+Swap+recovers+70%25+of+stolen+funds+from+recent+hack&aqs=chrome..69i57.548j0j4&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noreferrer noopener\">Transit Finance <span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>reported that &#8220;through combined efforts of all parties,&#8221; the hacker has returned 70% of the stolen funds to two addresses, totaling about $16.2 million. This suggests that the hacker's efforts have already paid off.<\/p>\n\n\n\n<p>According to BscScan and EtherScan, these monies were distributed as 3,180 Ether (ETH) worth $4.2 million, 1,500 Binance-Peg ETH worth $2 million, and 50,000 BNB worth $14.2 million.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">\ud83d\udce2\ud83d\udce2\ud83d\udce2Updates about TransitFinance<br>1\/5 We are here to update the latest news about TransitFinance Hacking Event. With the joint efforts of all parties, the hacker has returned about 70% of the stolen assets to the following two addresses:<\/p>&mdash; Transit (@TransitFinance) <a href=\"https:\/\/twitter.com\/TransitFinance\/status\/1576463550557483008?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">October 2, 2022<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Transit Finance said in its most recent update that while &#8220;the project team is hurrying to collect the precise data of the stolen customers and design a detailed return plan,&#8221; it is still committed to recovering the remaining 30% of the cash that has been taken.<\/p>\n\n\n\n<p>The <a href=\"https:\/\/coinscreed.com\/staging\/ethereum-foundation-confirms-merge-upgrade-date.html\" target=\"_blank\" rel=\"noreferrer noopener\">security firms<\/a> and project teams of all parties are still tracking the hacking event and corresponding with the hacker via email and on-chain techniques as of right now. The team will keep putting in a lot of effort to find other assets, it stated.<\/p>\n\n\n\n<p>In a study of the issue, cybersecurity company SlowMist reported that the hacker had taken use of a flaw in the Transit Swap smart contract code that originated from the transferFrom() function, effectively allowing users' tokens to be sent directly to the exploiter's address:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\" id=\"h-the-root-cause-of-this-attack-is-that-the-transit-swap-protocol-does-not-strictly-check-the-data-passed-in-by-the-user-during-token-swap-which-leads-to-the-issue-of-arbitrary-external-calls-the-attacker-exploited-this-arbitrary-external-call-issue-to-steal-the-tokens-approved-by-the-user-for-transit-swap\"><p>\u201cThe root cause of this attack is that the Transit Swap protocol does not strictly check the data passed in by the user during <a href=\"https:\/\/coinscreed.com\/staging\/over-4-7-million-stolen-in-uniswap-fake-token-phishing-attack.html\" target=\"_blank\" rel=\"noreferrer noopener\">token swap<\/a>, which leads to the issue of arbitrary external calls. The attacker exploited this arbitrary external call issue to steal the tokens approved by the user for Transit Swap.\u201d<\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>Transit Swap, a DEX aggregator was recently hacked to the tune of $23 million, due to a swift response from many blockchain security firms about 70%of the stolen funds have been returned. The Transit Swap DEX aggregator lost the funds on October 1 after a hacker took advantage of an internal flaw in a swap [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":36977,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[1400,1496,11672],"class_list":["post-36974","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-dex","tag-hack","tag-transit-swap"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/10\/image.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/36974","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=36974"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/36974\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/36977"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=36974"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=36974"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=36974"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}