Transit Swap ‘hacker’ returns 70% of $23M in stolen funds

0

[ad_1]

A quick response from a number of blockchain security companies has helped facilitate the return of around 70% of the $23 million exploit of decentralized exchange (DEX) aggregator Transit Swap.

The DEX aggregator lost the funds after a hacker exploited an internal bug on a swap contract on Oct. 1, leading to a quick response from Transit Finance team along with security companies Peckshield, SlowMist, Bitrace and TokenPocket, who were able to quickly work out the hacker’s IP, email address and associated-on chain addresses.

It appears these efforts have already born fruit, as less than 24 hours after the hack, Transit Finance noted that “with joint efforts of all parties” the hacker has returned 70% of the stolen assets to two addresses, equating to roughly $16.2 million.

These funds came in the form of 3,180 Ether (ETH) ($4.2 million), 1,500 Binance-Peg ETH and ($2 million) and 50,000 BNB ($14.2 million), according to BscScan and EtherScan.

In the most recent update, Transit Finance stated that “the project team is rushing to collect the specific data of the stolen users and formulate a specific return plan” but also remains focused on retrieving the final 30% of stolen funds.

At present, the security companies and project teams of all parties are still continuing to track the hacking incident and communicate with the hacker through email and on-chain methods. The team will continue to work hard to recover more assets,” it said. 

Related: $160M stolen from crypto market maker Wintermute

Cybersecurity firm SlowMist in an analysis of the incident noted that the hacker used a vulnerability in Transit Swap’s smart contract code, which came directly from the transferFrom() function, which essentially allowed users’ tokens to be transferred directly to the exploiter’s address. 

“The root cause of this attack is that the Transit Swap protocol does not strictly check the data passed in by the user during token swap, which leads to the issue of arbitrary external calls. The attacker exploited this arbitrary external call issue to steal the tokens approved by the user for Transit Swap.”

[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 86,482.00
ethereum
Ethereum (ETH) $ 2,925.86
tether
Tether (USDT) $ 0.999778
bnb
BNB (BNB) $ 858.73
xrp
XRP (XRP) $ 1.91
usd-coin
USDC (USDC) $ 0.999832
tron
TRON (TRX) $ 0.280020
staked-ether
Lido Staked Ether (STETH) $ 2,923.06
dogecoin
Dogecoin (DOGE) $ 0.130513
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
cardano
Cardano (ADA) $ 0.378741
whitebit
WhiteBIT Coin (WBT) $ 57.30
wrapped-steth
Wrapped stETH (WSTETH) $ 3,572.95
bitcoin-cash
Bitcoin Cash (BCH) $ 545.61
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 86,161.00
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 3,176.46
usds
USDS (USDS) $ 0.999849
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999441
chainlink
Chainlink (LINK) $ 12.71
wrapped-eeth
Wrapped eETH (WEETH) $ 3,169.79
leo-token
LEO Token (LEO) $ 9.17
monero
Monero (XMR) $ 426.34
weth
WETH (WETH) $ 2,925.40
hyperliquid
Hyperliquid (HYPE) $ 26.93
stellar
Stellar (XLM) $ 0.217561
zcash
Zcash (ZEC) $ 392.56
ethena-usde
Ethena USDe (USDE) $ 0.999079
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 86,428.00
litecoin
Litecoin (LTC) $ 78.91
sui
Sui (SUI) $ 1.48
avalanche-2
Avalanche (AVAX) $ 12.13
hedera-hashgraph
Hedera (HBAR) $ 0.113134
susds
sUSDS (SUSDS) $ 1.08
shiba-inu
Shiba Inu (SHIB) $ 0.000008
usdt0
USDT0 (USDT0) $ 0.999736
dai
Dai (DAI) $ 0.999571
mantle
Mantle (MNT) $ 1.30
paypal-usd
PayPal USD (PYUSD) $ 0.999459
the-open-network
Toncoin (TON) $ 1.54
world-liberty-financial
World Liberty Financial (WLFI) $ 0.134948
crypto-com-chain
Cronos (CRO) $ 0.094287
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.21
uniswap
Uniswap (UNI) $ 5.08
polkadot
Polkadot (DOT) $ 1.87
memecore
MemeCore (M) $ 1.69
aave
Aave (AAVE) $ 183.84
usd1-wlfi
USD1 (USD1) $ 0.998947
canton-network
Canton (CC) $ 0.071430
rain
Rain (RAIN) $ 0.007619
bitget-token
Bitget Token (BGB) $ 3.49
Shares