HomeNewsDEX Aggregator Hit by $16.8M SwapNet Exploit After Approval Bypass

DEX Aggregator Hit by $16.8M SwapNet Exploit After Approval Bypass

- Advertisement -

Decentralized exchange aggregator Matcha Meta has confirmed a security incident linked to its SwapNet integration, resulting in an estimated $16.8 million loss.

The breach was first flagged by blockchain security firm PeckShield, with further technical analysis later provided by CertiK.

What Went Wrong

According to findings shared by security researchers, the exploit specifically impacted users who had disabled Matcha Meta’s “One-Time Approval” feature. By opting out, those users granted persistent permissions directly to the SwapNet router contract, creating an attack surface that was later abused.

CertiK identified the root cause as an “arbitrary call” vulnerability in the SwapNet contract. This flaw allowed an attacker to initiate unauthorized transfers from wallets that had previously approved the router, effectively bypassing normal safeguards.

Fund Movement and Scope

On-chain activity shows the attacker swapped approximately $10.5 million in USDC on Base for around 3,655 ETH, before bridging the assets to Ethereum. The cross-chain movement appears designed to complicate tracking and recovery efforts.

Importantly, the incident did not affect all Matcha users. Exposure was limited to wallets that had manually disabled one-time approvals and granted direct permissions to SwapNet contracts.

Emergency Response Measures

In response to the exploit, Matcha Meta has taken several immediate steps:

  • SwapNet contracts have been suspended to prevent further losses.
  • Users have been urged to revoke existing approvals, particularly for the SwapNet router contract
    (0x616000e384Ef1C2B52f5f3A88D57a3B64F23757e).
  • The platform has removed the option to disable one-time approvals, aiming to reduce similar risks going forward.

The incident highlights the security trade-offs associated with persistent contract approvals and reinforces the importance of regular permission reviews, especially when interacting with aggregators and routing contracts.

Disclaimer: ETHNews does not endorse and is not responsible for or liable for any content, accuracy, quality, advertising, products, or other materials on this page. Readers should do their own research before taking any actions related to cryptocurrencies. ETHNews is not responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods, or services mentioned.
Ralf
Ralfhttps://www.proz.com/translator/2515043
Ralf Klein is a computer engineer specializing in database technology, and as such, he was immediately fascinated by the possibilities of blockchain when he first heard about it, especially since this distributed, tamper-proof technology can be the foundation for much more than just cryptocurrencies. At ETHNews, he translates the articles of his English-speaking colleagues for the German readers. Business Email: [email protected] Phone: +49 160 92211628
RELATED ARTICLES

LATEST ARTICLES