Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
No Result
View All Result
Home News Security & Hacks

Transit Finance Hacked Again: Cross-Chain DeFi Protocol Loses $1.88 Million in Latest Exploit

Security researchers traced suspicious fund movements linked to Tron and HitBTC as Transit Finance urges hacker to return stolen DAI within 48 hours.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
May 13, 2026 - Updated on May 14, 2026
in Security & Hacks
0 0
Transit Finance Hacked Again

Created By Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

Cross-chain decentralized exchange aggregator Transit Finance appears to have been hacked, with losses estimated at around $1.88 million. The incident has drawn quick attention from on-chain security monitors and the wider crypto community today.

According to blockchain security firm PeckShield, suspicious activity was detected on the protocol, with reports indicating that a portion of the drained funds originated from the Tron network. Some tracing activity has also pointed toward connections with the HitBTC exchange.

Transit Finance functions as a multi-chain swap platform that aggregates liquidity from various decentralized exchanges and provides bridging services across different blockchains. Its main interfaces transit.finance and swap.transit.finance allow users to perform seamless cross-chain transactions in one place.

#PeckShieldAlert @TransitFinance seems to have been hacked for ~$1.88M

The stolen funds are currently sitting in the following address in $DAI: 0x8a634DfA2609358849D7D65FFA270C8A57a8abA5 pic.twitter.com/9RSQkgdfX6

— PeckShieldAlert (@PeckShieldAlert) May 13, 2026

Project’s On-Chain Response

The Transit Finance team has already sent an on-chain message to the attacker’s address, offering a bug bounty in exchange for the return of the funds. They provided a 48-hour window for a potential white-hat resolution.

The stolen funds are currently held in approximately 1.875 million DAI at the Ethereum address 0x8a634DfA2609358849D7D65FFA270C8A57a8abA5. As of Wednesday evening, the funds remain unmoved in this wallet. The exact root cause of the exploit has not yet been publicly disclosed by the project.

Community reactions have been swift, with several accounts advising users to immediately revoke token approvals related to Transit Finance as a safety precaution. Comments such as “another day, another DeFi incident” reflect the persistent security challenges in the space.The incident further highlights growing concerns around DeFi security, especially after the Ink Finance exploit on Polygon where attackers reportedly abused a treasury proxy whitelist flaw through a flash loan attack

Past Security Incidents

📢📢📢Updates about TransitFinance
1/5 We are here to update the latest news about TransitFinance Hacking Event. With the joint efforts of all parties, the hacker has returned about 70% of the stolen assets to the following two addresses:

— Transit (@TransitFinance) October 2, 2022

This is not the first time Transit Finance has faced a major exploit. In October 2022, the project (then widely known as Transit Swap) suffered a significant hack that resulted in losses estimated between $21 million and $29 million. The attacker exploited a critical vulnerability in the project’s swap contract. Specifically, a composability issue allowed unauthorized arbitrary external calls, draining user-approved tokens across multiple chains. Security researchers quickly got involved and tracked the hacker’s on-chain movements. Following intense negotiations, the primary attacker returned approximately 70% of the stolen funds (around $18–19 million) within a few days.The current incident, while considerably smaller in scale, adds to ongoing concerns about smart contract security and approval mechanisms in cross-chain DeFi protocols.

Current Status and Advice

As this story develops, the stolen funds continue to sit in the attacker-controlled address. The Transit Finance team is believed to be conducting an internal investigation, though no detailed official statement has been released beyond the on-chain communication.

Users who have interacted with the Transit Finance platform are strongly recommended to:

  • Check their wallet approvals
  • Revoke any unnecessary permissions linked to the protocol
  • Monitor transactions carefully in the coming days

Further updates are expected once the project shares more technical details about the exploit vector and any recovery progress. On-chain analysts and security researchers are actively monitoring the situation for any movement in the affected wallet.

Disclaimer: Cryip is an independent media and research outlet providing news, data, and analysis on the cryptocurrency industry. Content is for informational and research purposes only and does not constitute financial, legal, tax, or investment advice. Cryptocurrency markets are volatile and past performance is not indicative of future results. References to specific assets, platforms, or incidents are for journalistic purposes only and do not imply endorsement, and readers assume full responsibility for their decisions.
Tags: Crypto Hacks

Related Posts

Humanity Protocol Hack Linked to North Korean Actors as Quantstamp Investigation Reveals $36M Exploit
Security & Hacks

Humanity Protocol Hack Linked to North Korean Actors as Quantstamp Investigation Reveals $36M Exploit

by Saravana Kumar Mahendran
June 13, 2026

Humanity Protocol, the biometric decentralized identity project, has come under fresh scrutiny after a blockchain security firm’s investigation revealed strong...

Read moreDetails
Raydium Suffers $1.34M Exploit as Attacker Drains Dormant Legacy AMM V3 Liquidity Pools on Solana

Raydium Suffers $1.34M Exploit as Attacker Drains Dormant Legacy AMM V3 Liquidity Pools on Solana

June 11, 2026
Token of Power Loses $1.58M in Governance Exploit as Attacker Hijacks Aragon DAOEthereum

Token of Power Loses $1.58M in Governance Exploit as Attacker Hijacks Aragon DAOEthereum

June 10, 2026
Humanity Protocol Faces $36M Bridge Exploit: Detailed Incident Update on Multisig Compromise

Humanity Protocol Faces $36M Bridge Exploit: Detailed Incident Update on Multisig Compromise

June 9, 2026
Humanity Protocol Token Crashes Nearly 90% After Foundation Member’s Private Keys Compromised

Humanity Protocol Token Crashes Nearly 90% After Foundation Member’s Private Keys Compromised

June 9, 2026
Yuga Labs Executes White-Hat Rescue of High-Value NFTs

Yuga Labs Executes White-Hat Rescue of High-Value NFTs Following Flooring Protocol Exploit

June 8, 2026
ATM Token Exploited

ATM Token Exploited on BNB Chain: $243,500 Drained via Hidden Swap Loophole

June 5, 2026
Next Post
Metaplanet Posts $725M Q1 Loss Due to Bitcoin Valuation Losses

Metaplanet Posts $725M Q1 Loss Due to Bitcoin Valuation Losses

Recommended

  • All
  • News
SpaceX IPO Disclosure Brings Bitcoin Into the Mag8 as Tesla and SpaceX Hold More Than 30,000 BTC Combined

Michael Saylor Says 25% of the Mag8 Now Holds Bitcoin After SpaceX Reveals 18,712 BTC

June 13, 2026
US Government Orders Anthropic to Disable Claude Fable 5 and Mythos 5 Globally

US Government Orders Anthropic to Disable Claude Fable 5 and Mythos 5 Globally

June 13, 2026
Humanity Protocol Hack Linked to North Korean Actors as Quantstamp Investigation Reveals $36M Exploit

Humanity Protocol Hack Linked to North Korean Actors as Quantstamp Investigation Reveals $36M Exploit

June 13, 2026
Blockworks Acquires Messari to Expand Crypto Market Data and Infrastructure Capabilities

Blockworks Acquires Messari to Expand Crypto Market Data and Infrastructure Capabilities

June 13, 2026
SpaceX IPO Disclosure Brings Bitcoin Into the Mag8 as Tesla and SpaceX Hold More Than 30,000 BTC Combined

Michael Saylor Says 25% of the Mag8 Now Holds Bitcoin After SpaceX Reveals 18,712 BTC

June 13, 2026
US Government Orders Anthropic to Disable Claude Fable 5 and Mythos 5 Globally

US Government Orders Anthropic to Disable Claude Fable 5 and Mythos 5 Globally

June 13, 2026
Humanity Protocol Hack Linked to North Korean Actors as Quantstamp Investigation Reveals $36M Exploit

Humanity Protocol Hack Linked to North Korean Actors as Quantstamp Investigation Reveals $36M Exploit

June 13, 2026
Blockworks Acquires Messari to Expand Crypto Market Data and Infrastructure Capabilities

Blockworks Acquires Messari to Expand Crypto Market Data and Infrastructure Capabilities

June 13, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Michael Saylor Says 25% of the Mag8 Now Holds Bitcoin After SpaceX Reveals 18,712 BTC
  • US Government Orders Anthropic to Disable Claude Fable 5 and Mythos 5 Globally
  • Humanity Protocol Hack Linked to North Korean Actors as Quantstamp Investigation Reveals $36M Exploit

Categories

  • AI × Crypto
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.