Transit Finance Loses $1.88 Million in Cross-Chain DeFi Exploit
Transit Finance was exploited on May 13, 2026 for $1.88 million in DAI, now held at Ethereum address 0x8a634DfA2609358849D7D65FFA270C8A57a8abA5. The cross-chain DeFi protocol offered the attacker a 48-hour bug bounty window for fund return. This marks Transit Finance's second major breach after an October 2022 hack that drained $21-29 million, though that attacker returned approximately 70% of stolen funds.
Transit Finance exploit details
▪Transit Finance's main interfaces transit.finance and swap.transit.finance allow users to perform seamless cross-chain transactions in one place.
▪Blockchain security firm PeckShield detected suspicious activity on the Transit Finance protocol on May 13, 2026.
▪A portion of the funds drained from Transit Finance originated from the Tron network.
▪Transit Finance was hacked on May 13, 2026, with losses estimated at around $1.88 million.
▪The stolen funds from the Transit Finance hack are held in approximately 1.875 million DAI at the Ethereum address 0x8a634DfA2609358849D7D65FFA270C8A57a8abA5.
▪Tracing activity related to the Transit Finance hack pointed toward connections with the HitBTC exchange.
On-chain bounty offer
▪The Transit Finance team sent an on-chain message to the attacker's address offering a bug bounty in exchange for the return of the funds.
▪Transit Finance provided a 48-hour window for a potential white-hat resolution with the attacker.
▪As of May 13, 2026 evening, the stolen Transit Finance funds remained unmoved in the attacker's wallet.
October 2022 hack history
▪The October 2022 Transit Finance attacker exploited a composability issue that allowed unauthorized arbitrary external calls, draining user-approved tokens across multiple chains.
▪Transit Finance suffered a hack in October 2022 that resulted in losses estimated between $21 million and $29 million.
▪The primary attacker in the October 2022 Transit Finance hack returned approximately 70% of the stolen funds, around $18–19 million, within a few days.
DeFi security vulnerabilities
▪Attackers in the Ink Finance exploit on Polygon reportedly abused a treasury proxy whitelist flaw through a flash loan attack.
▪Transit Finance functions as a multi-chain swap platform that aggregates liquidity from various decentralized exchanges and provides bridging services across different blockchains.
▪The exact root cause of the May 13, 2026 Transit Finance exploit has not yet been publicly disclosed by the project.
User approval revocation advice
▪Several accounts advised users to immediately revoke token approvals related to Transit Finance as a safety precaution following the May 13, 2026 hack.
▪Users who have interacted with the Transit Finance platform are strongly recommended to check their wallet approvals and revoke any unnecessary permissions linked to the protocol.
Story comments
Loading comments…