Transit Finance Hack
What happened
On December 20, 2023, an attacker drained about $110K from Transit Finance's swap router on BNB Smart Chain and Ethereum. The router's exactInputV3Swap function did not check that the pools in a caller-supplied swap path were real Uniswap/PancakeSwap V3 pools. The attacker put a contract it controlled first in the path. That fake pool reported a large output without sending any tokens, and the router used the fake amount as the input for the next, real pool, spending tokens held by the router itself.
BlockSec Phalcon flagged the attack with losses over $100K. Verichains said user assets were not directly affected because the attack drained the router's own token balances.
How it happened
- The attacker deployed a contract that mimics a V3 pool, exposing
token0(),token1(),fee()and aswap()that returns whatever amounts the attacker chooses. - It called
exactInputV3Swapon the router with a 1 wei BNB input and apoolspath whose first entry was the fake pool and whose second was a real WBNB/USDT pool. - The fake pool's
swap()reported an output equal to the router's entire USDT balance, but no tokens moved. - The router did not validate the pool and treated that reported amount as the input for the next hop, so it swapped its own USDT through the real WBNB/USDT pool.
- The resulting BNB went to the attacker. In the BSC transaction
0x93ae5f0a...de1081, the DeFiHackLabs reproduction turns about 43.8K USDT held by the router into about 173.9 BNB. The attacker repeated the technique on other chains, including Ethereum.
Protocol details
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.