According to Beosin's EagleEye security risk monitoring, early warning and blocking platform, the Transit Finance project was attacked. The Beosin security team analyzed and found that the exactInputV3Swap function in Transit Finance's SwapRouter was attacked due to the lack of legal verification of the pool input. Taking the 0x93ae5...6de1081 transaction as an example, the attacker passed in the forged pool and WBNB/BUSD pool subpath, thereby controlling the actualAmountIn in the first exchange, causing SwapRouter to use the forged actualAmountIn as the exchange in the WBNB/BUSD pool. Initial value, thus stealing the BUSD in SwapRouter.
Related address: https://eagleeye.space/risk/0xf7552ba0ee5bed0f306658f4a1201f421d703898.