Transit Swap said on October 2, 2022 that an attacker had returned about 70% of assets taken from users of its decentralized-exchange aggregation service, turning an initially reported loss of roughly $21 million into an unusually rapid partial recovery.
The return did not erase the breach or establish a final loss. It did, however, change the immediate risk picture. Transit had already suspended the affected service after identifying an internal code flaw. Its October 2 update said security teams had helped trace information associated with the attacker and that returned assets had reached two designated addresses.
What the record established
Transit’s public statements and contemporaneous reporting support three event-day facts. First, the service attributed the incident to a flaw in its own code rather than to a compromise of one user’s credentials. Second, the team halted contract activity while it investigated. Third, by October 2 it said roughly 70% of the assets then counted as stolen had been returned.
The dollar figure available on October 2 was provisional. The Block reported an approximately $21 million theft and described the 70% return as an update from Transit. That pairing should not be read as a final accounting or as a mark-to-market valuation at a uniform timestamp. The assets spanned tokens and networks, and contemporaneous coverage did not publish a complete, independently reconciled inventory with one pricing methodology.
Why the approval path mattered
A technical analysis published by SharkTeam on October 6 traced the attack path through contracts used by Transit Swap. Its report said the relevant contracts failed to adequately verify the destination contract, called function and parameters supplied during execution. That gap allowed an attacker to reach a token contract’s `transferFrom` function and move tokens that users had previously approved.
That distinction mattered institutionally. Transit Swap described itself as an aggregator, not a conventional custodian holding all customer balances in one omnibus account. Yet broad token approvals created a path from a routing or validation failure to assets still sitting in individual wallets. The incident therefore exposed a form of protocol risk that did not depend on the operator possessing users’ private keys.
The recovery was also not a normal protocol rollback. Public records described transfers back to addresses identified by the project after tracing and communication efforts involving blockchain-security firms. On October 2, the identities and roles of every address involved were not fully settled, and the team had not published a final victim-by-victim reconciliation.
What remained uncertain on October 2
The largest uncertainty was the denominator. “About 70%” reflected the project’s live estimate, while the approximately $21 million headline represented the early loss tally in contemporaneous reporting. Neither number established the final number of affected wallets, the value ultimately made whole, or the legal status of the returning party.
A second uncertainty concerned attribution. Transit said it had obtained information including associated on-chain addresses and off-chain identifiers, but those claims were not equivalent to a public identification verified by law enforcement or a court. The available evidence supported recovery activity; it did not support a definitive account of who controlled every participating address.
Later accounting, kept separate
On October 3, 2022, Transit expanded its accounting to $28.9 million taken across multiple addresses and said $18.9 million had been returned. That later update clarifies why the October 2 percentages and dollar totals should be treated as a developing snapshot, not contradictory final figures. It does not alter the event-day conclusion: a code-validation failure enabled approved user tokens to be moved, service was suspended, and a substantial partial return was reported on October 2.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

