TeleSwap Bridge Exploited for $735K, Still Undisclosed After Five Days
Security & Exploits ·
The cross-chain bridge lost over $735,000 in a July 15 exploit that it has not publicly acknowledged, while the attacker has already moved to launder the funds.
The exploit was flagged by researcher zachxbt and relayed in a post on X, which put the loss at $735K+ and noted that TeleSwap has issued no public disclosure of the incident five days after it occurred. The same post detailed the aftermath: shortly after the suspicious outflows, TeleSwap's Bitcoin hot wallet stopped processing transactions altogether, and roughly two hours before the report, the attacker deposited the stolen funds into Tornado, a mixing service commonly used to obscure the trail of illicit crypto transfers.
Four theft-linked addresses were identified in connection with the exploit, including a Bitcoin address beginning bc1pz95zv3qhpmt52yezs84a5zrddrk5jsxm8a60rln5kzlk06e87a3q8pf79l and three Ethereum-format addresses starting 0x2448cbaee50a67030692b7519a954e5550dc2718, 0xfc5048fbba2f74ed482ffcd7663601f818c5bb47, and 0xf8706a51f8df01a71f408e50c901dd14916a12c7. TeleSwap's own Bitcoin hot wallet was identified as bc1q5wnpn4k99wc587maaaa6eqnx27g4r6mduxg2s5, the wallet that reportedly went dormant after the exploit.
The lack of transaction activity on TeleSwap's hot wallet following the outflows is being read as a possible sign that the bridge either paused operations in response to the breach or lost control of that wallet's normal function, though no confirmation from the project has emerged. The move of stolen funds into Tornado complicates efforts to trace or recover the assets, a step typically taken once an attacker anticipates scrutiny.
The cluster is corroborated by a second account describing the same $735K exploit, the five-day silence, and the transfer of funds to the Tornado mixer, indicating the core facts are not isolated to a single report. What remains unknown is the exact mechanism of the exploit, whether TeleSwap has any plan to compensate affected users, and whether the bridge will issue a formal statement. The dormant hot wallet and the attacker's continued on-chain activity suggest the situation is still unfolding, warranting continued monitoring of the listed addresses for further movement.