Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Transit Finance Loses $1.88 Million in Cross-Chain DeFi Exploit
00

Transit Finance Loses $1.88 Million in Cross-Chain DeFi Exploit

May 13, 2026

Transit Finance was exploited on May 13, 2026 for $1.88 million in DAI, now held at Ethereum address 0x8a634DfA2609358849D7D65FFA270C8A57a8abA5. The cross-chain DeFi protocol offered the attacker a 48-hour bug bounty window for fund return. This marks Transit Finance's second major breach after an October 2022 hack that drained $21-29 million, though that attacker returned approximately 70% of stolen funds.

Transit Finance exploit details

  • ▪Transit Finance's main interfaces transit.finance and swap.transit.finance allow users to perform seamless cross-chain transactions in one place
  • ▪Blockchain security firm PeckShield detected suspicious activity on the Transit Finance protocol on May 13, 2026
  • ▪A portion of the funds drained from Transit Finance originated from the Tron network
  • ▪Transit Finance was hacked on May 13, 2026, with losses estimated at around $1.88 million
  • ▪The stolen funds from the Transit Finance hack are held in approximately 1.875 million DAI at the Ethereum address 0x8a634DfA2609358849D7D65FFA270C8A57a8abA5
  • ▪Tracing activity related to the Transit Finance hack pointed toward connections with the HitBTC exchange

On-chain bounty offer

  • ▪The Transit Finance team sent an on-chain message to the attacker's address offering a bug bounty in exchange for the return of the funds
  • ▪Transit Finance provided a 48-hour window for a potential white-hat resolution with the attacker
  • ▪As of May 13, 2026 evening, the stolen Transit Finance funds remained unmoved in the attacker's wallet

October 2022 hack history

  • ▪The October 2022 Transit Finance attacker exploited a composability issue that allowed unauthorized arbitrary external calls, draining user-approved tokens across multiple chains
  • ▪Transit Finance suffered a hack in October 2022 that resulted in losses estimated between $21 million and $29 million
  • ▪The primary attacker in the October 2022 Transit Finance hack returned approximately 70% of the stolen funds, around $18–19 million, within a few days

DeFi security vulnerabilities

  • ▪Attackers in the Ink Finance exploit on Polygon reportedly abused a treasury proxy whitelist flaw through a flash loan attack
  • ▪Transit Finance functions as a multi-chain swap platform that aggregates liquidity from various decentralized exchanges and provides bridging services across different blockchains
  • ▪The exact root cause of the May 13, 2026 Transit Finance exploit has not yet been publicly disclosed by the project

User approval revocation advice

  • ▪Several accounts advised users to immediately revoke token approvals related to Transit Finance as a safety precaution following the May 13, 2026 hack
  • ▪Users who have interacted with the Transit Finance platform are strongly recommended to check their wallet approvals and revoke any unnecessary permissions linked to the protocol

2 sources

Cryptotimes
$1.88M Drained from Transit Finance: Stolen DAI Sits in Fresh ETH Wallet
View source article
Cryip
Transit Finance Hacked Again: Cross-Chain DeFi Protocol Loses $1.88 Million in Latest Exploit | Cryip
View source article

Story comments

Loading comments…

Related entities

DaiEthereum

Topics

DeFiDeFi security exploitsStablecoinsCrypto hacksBlockchain interoperability