Transit Finance reportedly lost $1.8 million in DAI in a fresh exploit. Blockchain security firm PeckShield said the stolen funds were moved to a single Ethereum wallet shortly after the incident surfaced on Wednesday. The attack quickly renewed scrutiny of weak points in cross-chain DeFi infrastructure.
Cross-chain design leaves a wider attack surface
Transit Finance operates as a cross-chain swap aggregator, connecting liquidity across multiple blockchain ecosystems. That setup gives users broader routing options, but it also means transactions pass through several linked networks. More connections create more possible failure points. Protocols built around cross-chain architecture and automated routing have remained attractive targets for attackers.
This is not the first security breakdown tied to the platform. In October 2022, Transit Finance suffered another exploit after attackers abused weaknesses in its swap validation system and stole about $28.9 million. That earlier incident enabled unauthorized token transfers from wallets that had granted approval permissions. The protocol later recovered part of the funds, yet the latest breach has again raised questions about long-term security controls and operating resilience.
DeFi losses in 2026 keep climbing
Large attacks recorded in April pushed the sector’s losses much higher. Kelp DAO lost $293 million on April 19, while Drift Protocol suffered a separate $280 million exploit earlier in the month. Those two cases accounted for most of the DeFi-related losses reported during April.
Current projections suggest total DeFi exploit losses could approach $2.3 billion before the end of 2026. The estimate reflects mounting pressure on decentralized platforms as hackers continue to focus on vulnerable smart contracts and cross-chain systems. Financial damage is only part of the picture. Repeated breaches have also weighed on investor confidence, while protocols face louder calls for stronger audits, tighter security reviews, and better transaction monitoring.
Lazarus-linked activity remains a central concern
Cybersecurity researchers believe the North Korea-linked Lazarus Group is still responsible for a large share of crypto attacks this year. A recent TRM Labs report said the group accounted for roughly 76% of crypto hack losses through April 2026. That estimate has added urgency to discussions about organized cybercrime in digital asset markets.
The Transit Finance exploit is smaller than some of the biggest cases seen this year, but it lands in a sensitive area of the market. Cross-chain protocols remain under pressure, and this latest theft shows that security risks in interconnected DeFi systems have not eased.

