Log in
For business
KYT office
Compliance solution to monitor risks, detect sanctions and ensure AML rules.
KYT office
Compliance solution to monitor risks, detect sanctions and ensure AML rules.
AML certification
How industry players can get up-to-date knowledge and professional certification.
AML certification
How industry players can get up-to-date knowledge and professional certification.
Comprehensive transaction analytics that helps to build graphs and trace funds.
Graph
Travel rule
(soon)
For personal use
Telegram bot
Bot for checking crypto for risks, providing AML reports.
Telegram bot
Bot for checking crypto for risks, providing AML reports.
Crypto recovery
Services are focused on tracking
and recovering crypto assets.
Сrypto recovery
Services are focused on tracking
and recovery crypto assets.
Docs and reports
All types of documents related
to cryptocurrency.
Docs and reports
All types of documents related
to cryptocurrency.
Portfolio tracker
Information about all assets and risk assessment in one place.
Portfolio tracker
Information about all assets and risk assessment in one place.
AML checks
Сhecking wallets and transactions
for illicit funds.
AML checks
Сhecking wallets and transactions
for illicit funds.
ES
FR
中文
Вход
AML-сертификация
Актуальные знания в области AML/KYT от ведущих экспертов отрасли.
AML-сертификация
Актуальные знания в области AML/KYT от ведущих экспертов отрасли.
Graph
Визуализация перемещения активов
и связей между кошельками.
Graph
Визуализация перемещения активов
и связей между кошельками.
KYT Office
Мониторинг транзакций и кошельков для вашего отдела комплаенса.
KYT Office
Мониторинг транзакций и кошельков для вашего отдела комплаенса.
Для себя
Для Бизнеса
Travel rule
(Cкоро)
Телеграм-бот
Бот для проверки кошельков и транзакций с выдачей отчётов.
Телеграм-бот
Бот для проверки кошельков и транзакций с выдачей отчётов.
Возврат средств
Услуги по отслеживанию и возврату украденных криптоактивов.
Возврат средств
Услуги по отслеживанию и возврату украденных криптоактивов.
AML-проверки
Проверка кошельков и транзакций на наличие "грязной" криптовалюты.
AML-проверки
Проверка кошельков и транзакций на наличие "грязной" криптовалюты.
Портфолио трекер
Информация о всех активах и оценка рисков в одном месте.
Портфолио трекер
Информация о всех активах и оценка рисков в одном месте.
Отчёты
Все типы документов связанные
с криптовалютой.
Отчёты
Все типы документов связанные
с криптовалютой.
PRIVATE
Government
Financial institutions
Exchanges
PSP's
Wallets
Gambling platforms
Investment platforms
Stablecoin issuers
Investigators
Regulators
Law enforcement
Для бизнеса
Госсектор
Финансовые организации
Биржи
Платежные провайдеры
Кошельки
Игровые платформы
Инвестиционные платформы
Эмитенты стейблкоинов
Расследователи
Регуляторы
Правоохранительные органы
ES
FR
中文
22.07.2026

Inside the $ 735,000 TeleSwap Cross-Chain Bridge Hack That No One Is Talking About

On July 15, 2026, funds began disappearing from wallets associated with the TeleSwap cross-chain bridge. The assets were sent to an address with no known connection to the service. Within a few hours, more than ten Bitcoins and tens of thousands of dollars in stablecoins had accumulated there. The TeleSwap wallet that initiated the transfers was drained to zero and stopped operating. Yet the developers did not publicly respond to the incident, leaving users in the dark.

BitOK analysts reconstructed the attacker’s laundering route. Here is what appears to have happened—and what crypto users should learn from it.


Table of content:

  1. How More Than $735,000 Was Drained from TeleSwap
  2. What Was Stolen
  3. How the Attacker Covered Their Tracks
  4. Attack Timeline
  5. What It All Means
  6. The Main Lesson

How More Than $735,000 Was Drained from TeleSwap

The attack began on the afternoon of July 15 and unfolded rapidly. The transaction pattern immediately suggests that this was not a software bug. Instead, the attacker appears to have gained direct control over the service’s funds.

Investigator’s note: This does not look like a smart contract exploit. The transaction pattern points to a compromised private key, internal server, or TeleSwap signing infrastructure.
Key facts about the attack:
  • Estimated losses: at least $735,000.
  • How the attacker gained access: The most likely scenarios are a compromised private key—the secret credential that gives full control over a wallet—access to TeleSwap’s internal infrastructure, or control of the system used to sign transactions. There are no signs that the smart contract code itself was exploited.
At 17:09 on July 15, TeleSwap’s hot wallet stopped processing transactions entirely and was left with a zero balance.

Notably, the project’s last post on X was published on July 10. The account has been inactive ever since. The website remains online, but users say the platform is not working and have accused the developers of staying silent about the exploit.

What Was Stolen

The attacker collected assets across two blockchains: Bitcoin and Ethereum.
All 10.29264370 BTC came from Bitcoin wallets linked to TeleSwap and were consolidated at a single newly created attacker address:

bc1pz95zv3qhpmt52yezs84a5zrddrk5jsxm8a60rln5kzlk06e87a3q8pf79l

The funds came from several source wallets. Of the total, 4.39085980 BTC was transferred directly from TeleSwap’s hot wallet (bc1q5wnpn4k99wc587maaaa6eqnx27g4r6mduxg2s5), while the remainder came from other wallets associated with the service.

Alongside the Bitcoin, the attacker received 35,000.63 USDT and 12,000.03 USDC. The stablecoins were not held for long: they were immediately swapped for ETH through OKX Web3.
How the attacker moved the funds. The graph was built using BitOK's Graph tool.

How the Attacker Covered Their Tracks

This is where the operation becomes more sophisticated. Rather than simply cashing out, the attacker built a multi-stage laundering route designed to obscure the trail:

1. Converting everything into one asset. The Bitcoin was routed through Chainflip, a decentralized cross-chain exchange that allows users to swap assets between blockchains—for example, BTC for ETH—without using a conventional centralized exchange or creating an account.

The BTC swaps produced roughly 350.6 ETH. Combined with the ETH previously obtained from the stablecoins, the attacker accumulated 382.7 ETH. Consolidating everything into one asset simplifies the next stages of the laundering process.

2. Waiting. The consolidated funds remained in an intermediary wallet for almost five days.
Investigator’s note: The five-day delay was likely deliberate. Analysts focus most heavily on the first hours after a theft. By waiting, the attacker may have hoped to move the funds after scrutiny had eased.

3. Splitting and mixing. On July 20, the attacker deposited 382.6 ETH into Tornado Cash, a mixer that combines funds from many users and breaks the visible on-chain link between sender and recipient.

To make analysis even harder, the funds were not deposited all at once. Instead, the attacker made 19 separate deposits in round amounts: three deposits of 100 ETH, eight of 10 ETH, two of 1 ETH, and six of 0.1 ETH.

4. A secondary exit route. A small remainder of 0.0922 ETH was routed separately through MayaChain, another cross-chain exchange. It was converted into 0.32046171 ZEC and sent to transparent Zcash addresses.

Between these stages, the ETH moved through three addresses. Funds from Chainflip first arrived at 0x2448cbae…0dc2718, were then consolidated at 0xfc5048…c5bb47, and, after the five-day pause, were transferred to the final address, 0xf8706a…6a12c7. From there, the assets were split between Tornado Cash and MayaChain.

Attack Timeline

What It All Means

The attacker converted most of the stolen assets into ETH, waited about five days, and then moved the funds into Tornado Cash. A small remainder was routed through MayaChain into Zcash.

Investigator’s note: The pauses, structured deposits, and two independent exit routes suggest an attacker who understands blockchain analytics and prepared in advance to evade tracing.

The Main Lesson

The most important takeaway is not about blockchain mechanics, but about where the real security perimeter lies.
  • Access—not code—is often the real target. There are no signs of a smart contract exploit here. The funds were lost because someone appears to have obtained a private key or control over the server that signed transactions. For service providers, this means protecting keys, servers, and signing procedures is at least as important as auditing smart contracts. The same principle applies to individual users: whoever controls the private key controls the funds. Keep keys offline and avoid storing large balances in a single hot wallet.
  • Speed matters. The attacker deliberately waited five days, likely expecting attention to fade. Fund movements are easiest to detect in the first hours after a theft, so the sooner an incident is identified and disclosed, the better the chance that exchanges and cross-chain services along the route can respond.
Once funds have been mixed through Tornado Cash, recovery becomes extremely difficult. In crypto, preventing a theft is almost always cheaper than investigating it afterward.
Support
Get it

To inquire about our plans, click here

Try BitOK for free