SwapNet Exploit Drains $16.8M After Approval Flaw on Matcha Meta

CoincuInsights
USDC0,01%
ETH0,98%
ARB1,54%
BNB0,93%

In Brief

  • SwapNet exploit drains $16.8M after users disabled one-time approval protections.
  • Attacker swapped $10.5M USDC to ETH on Base before bridging to Ethereum.
  • Matcha Meta disables affected contracts as security firms flag wider DeFi risks.

A security breach linked to SwapNet led to losses of about $16.8 million, affecting users interacting through Matcha Meta. The incident mainly impacted users who disabled one-time approvals, thereby exposing persistent token permissions.

Blockchain security firm PeckShieldAlert identified the exploit and traced the initial fund movements. The attacker targeted SwapNet router contracts that retained unlimited approvals from affected user wallets.

On the Base network, the attacker exchanged roughly $10.5 million in USDC for about 3,655 ether. Soon after, the attacker began bridging the converted assets to the Ethereum mainnet to complicate tracking.

SwapNet operates as a liquidity router used by Matcha Meta to source pricing and deep liquidity. The exploit involved abusing existing approvals rather than breaching private keys or core infrastructure.

Matcha Meta, built by the 0x team, confirmed the issue and immediately disabled affected SwapNet contracts. The platform also removed the option allowing users to grant direct approvals to third-party aggregators.

Investigation Expands as Security Firms Flag Wider Risks

Further analysis suggested the exploit stemmed from an arbitrary call vulnerability within SwapNet contracts. This flaw allowed attackers to transfer approved tokens without requesting new permissions.

Security firm BlockSec reported that multiple contracts across chains suffered losses exceeding $17 million. Affected networks included Ethereum, Arbitrum, Base, and BNB Chain, increasing the incident’s scope.

Separately, CertiK estimated that stolen funds near $13.3 million in USDC from related activity.
Some contracts involved remained closed-source and unverified at deployment.

Matcha Meta later confirmed that 0x core contracts were not affected by the incident.
Users relying on one-time approvals through 0x infrastructure remained unaffected.

The incident renewed scrutiny around persistent token approvals in decentralized finance.
Unlimited permissions offer convenience but increase exposure during smart contract failures.

Meanwhile, on-chain investigator ZachXBT criticized Circle’s delayed response to freeze remaining USDC. Roughly $3 million reportedly remained at addresses eligible for freezing during the response window.

The breach adds to a growing list of DeFi security failures early in 2026. Industry data shows stolen crypto funds reached record levels in recent years, increasing pressure on protocol security practices.

DISCLAIMER: The information on this website is provided as general market commentary and does not constitute investment advice. We encourage you to do your own research before investing.
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Articoli correlati

已停运交易所 BITGIN 洗钱案主犯在中国台湾被起诉,涉案金额逾 1.5 亿新台币

台湾检方起诉加密货币交易所"币竟"及其负责人等10人,因涉嫌与诈骗集团合作,实施诈骗和洗钱,涉及46名受害者,诈骗金额逾1.5亿元。张氏兄妹可能面临12年徒刑。

GateNews11h fa

Aave User Loses Millions in $50M Swap Amid High Price Impact

A $50M AAVE swap failed due to a significant price impact, despite the user confirming slippage warnings. Aave will refund $600K in fees, highlighting the need for improved user protections in DeFi trades, while CoW Swap functions correctly amid extreme market conditions.

CryptoFrontNews03-13 10:06

Fantasy.top 捲款風波:天使投資人指控失聯,創辦人稱從未動用一分錢

Fantasy.top 的創辦人否認對天使投資者的退款指控,強調公司兩年來依靠產品收入運營并未動用投資者資金。部分投資者表示未收到應有的財務報告,呼籲創辦人負責。該平台曾獲得良好評價,但近期已轉向預測市場,仍待官方進一步說明。

MarketWhisper03-12 02:16

Fantasy.top 创始人否认"软 Rug Pull"质疑,称未动用投资者资金

Fantasy.top 面临天使投资者指控,称团队失联拒退约5万美元,引发"软Rug Pull"质疑。创始人Travis Bickle反驳称公司依靠产品收入运营,未动用投资者资金。多位知名投资者也表示遭遇类似情况。

GateNews03-12 00:12

YZi Labs要求CEA Industries回应运营问题并终止与10X Capital 20年资管协议

YZi Labs在3月11日声明称,CEA Industries面临运营危机,缺乏关键管理团队与基础设施,董事会监督失效。YZi Labs要求董事会公开回应并调查董事Hans Thomas,同时终止与10X Capital Asset Management的协议。

GateNews03-11 12:50

美国司法部调查伊朗通过某全球大型 CEX 规避制裁,涉及逾 10 亿美元可疑资金

Gate News 消息,3 月 11 日,美国司法部正在调查伊朗如何利用某全球大型加密货币交易所规避美国制裁。据公司文件和知情人士透露,此前该交易所内部一项针对逾 10 亿美元可疑资金流向的调查被叫停,这些资金通过平台流向一个为伊朗支持的恐怖组织(包括也门胡塞武装)提供资金的网络。调查重点是相关资金流在该平台上的流转情况及其合规风险。

GateNews03-11 11:04
Commento
0/400
Nessun commento