SwapNet Exploit Drains $16.8M After Approval Flaw on Matcha Meta

CoincuInsights
ETH2,95%
ARB5,45%
BNB3,07%

In Brief

  • SwapNet exploit drains $16.8M after users disabled one-time approval protections.
  • Attacker swapped $10.5M USDC to ETH on Base before bridging to Ethereum.
  • Matcha Meta disables affected contracts as security firms flag wider DeFi risks.

A security breach linked to SwapNet led to losses of about $16.8 million, affecting users interacting through Matcha Meta. The incident mainly impacted users who disabled one-time approvals, thereby exposing persistent token permissions.

Blockchain security firm PeckShieldAlert identified the exploit and traced the initial fund movements. The attacker targeted SwapNet router contracts that retained unlimited approvals from affected user wallets.

On the Base network, the attacker exchanged roughly $10.5 million in USDC for about 3,655 ether. Soon after, the attacker began bridging the converted assets to the Ethereum mainnet to complicate tracking.

SwapNet operates as a liquidity router used by Matcha Meta to source pricing and deep liquidity. The exploit involved abusing existing approvals rather than breaching private keys or core infrastructure.

Matcha Meta, built by the 0x team, confirmed the issue and immediately disabled affected SwapNet contracts. The platform also removed the option allowing users to grant direct approvals to third-party aggregators.

Investigation Expands as Security Firms Flag Wider Risks

Further analysis suggested the exploit stemmed from an arbitrary call vulnerability within SwapNet contracts. This flaw allowed attackers to transfer approved tokens without requesting new permissions.

Security firm BlockSec reported that multiple contracts across chains suffered losses exceeding $17 million. Affected networks included Ethereum, Arbitrum, Base, and BNB Chain, increasing the incident’s scope.

Separately, CertiK estimated that stolen funds near $13.3 million in USDC from related activity.
Some contracts involved remained closed-source and unverified at deployment.

Matcha Meta later confirmed that 0x core contracts were not affected by the incident.
Users relying on one-time approvals through 0x infrastructure remained unaffected.

The incident renewed scrutiny around persistent token approvals in decentralized finance.
Unlimited permissions offer convenience but increase exposure during smart contract failures.

Meanwhile, on-chain investigator ZachXBT criticized Circle’s delayed response to freeze remaining USDC. Roughly $3 million reportedly remained at addresses eligible for freezing during the response window.

The breach adds to a growing list of DeFi security failures early in 2026. Industry data shows stolen crypto funds reached record levels in recent years, increasing pressure on protocol security practices.

DISCLAIMER: The information on this website is provided as general market commentary and does not constitute investment advice. We encourage you to do your own research before investing.
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Articoli correlati

Fantasy.top 捲款風波:天使投資人指控失聯,創辦人稱從未動用一分錢

Fantasy.top 的創辦人否認對天使投資者的退款指控,強調公司兩年來依靠產品收入運營并未動用投資者資金。部分投資者表示未收到應有的財務報告,呼籲創辦人負責。該平台曾獲得良好評價,但近期已轉向預測市場,仍待官方進一步說明。

MarketWhisper03-12 02:16

Fantasy.top 创始人否认"软 Rug Pull"质疑,称未动用投资者资金

Fantasy.top 面临天使投资者指控,称团队失联拒退约5万美元,引发"软Rug Pull"质疑。创始人Travis Bickle反驳称公司依靠产品收入运营,未动用投资者资金。多位知名投资者也表示遭遇类似情况。

GateNews03-12 00:12

YZi Labs要求CEA Industries回应运营问题并终止与10X Capital 20年资管协议

YZi Labs在3月11日声明称,CEA Industries面临运营危机,缺乏关键管理团队与基础设施,董事会监督失效。YZi Labs要求董事会公开回应并调查董事Hans Thomas,同时终止与10X Capital Asset Management的协议。

GateNews03-11 12:50

美国司法部调查伊朗通过某全球大型 CEX 规避制裁,涉及逾 10 亿美元可疑资金

Gate News 消息,3 月 11 日,美国司法部正在调查伊朗如何利用某全球大型加密货币交易所规避美国制裁。据公司文件和知情人士透露,此前该交易所内部一项针对逾 10 亿美元可疑资金流向的调查被叫停,这些资金通过平台流向一个为伊朗支持的恐怖组织(包括也门胡塞武装)提供资金的网络。调查重点是相关资金流在该平台上的流转情况及其合规风险。

GateNews03-11 11:04

某 CEX 违反反洗钱规定,面临暂停新客户服务处分

韩国金融情报院对某加密货币交易所采取制裁措施,因其允许用户向未登记海外平台转账并未执行KYC程序,可能面临6个月的新客户服务暂停。该交易所此前因操作失误损失400亿美元比特币,现也遭受广告监管调查。

GateNews03-11 02:59

湖南金融办确认煜志金融彻底跑路,各地警方已开通维权登记通道

Gate News 消息,3 月 10 日,湖南金融办确认,以"虚拟资产跟单交易"为名的煜志金融有限公司已彻底"跑路"。目前,各地警方已开通维权登记通道,受影响用户可通过官方渠道进行登记。

GateNews03-10 12:46
Commento
0/400
Nessun commento