HomeNewsDEX Aggregator Hit by $16.8M SwapNet Exploit After Approval Bypass

DEX Aggregator Hit by $16.8M SwapNet Exploit After Approval Bypass

- Advertisement -

Decentralized exchange aggregator Matcha Meta has confirmed a security incident linked to its SwapNet integration, resulting in an estimated $16.8 million loss.

The breach was first flagged by blockchain security firm PeckShield, with further technical analysis later provided by CertiK.

What Went Wrong

According to findings shared by security researchers, the exploit specifically impacted users who had disabled Matcha Meta’s “One-Time Approval” feature. By opting out, those users granted persistent permissions directly to the SwapNet router contract, creating an attack surface that was later abused.

CertiK identified the root cause as an “arbitrary call” vulnerability in the SwapNet contract. This flaw allowed an attacker to initiate unauthorized transfers from wallets that had previously approved the router, effectively bypassing normal safeguards.

Fund Movement and Scope

On-chain activity shows the attacker swapped approximately $10.5 million in USDC on Base for around 3,655 ETH, before bridging the assets to Ethereum. The cross-chain movement appears designed to complicate tracking and recovery efforts.

Importantly, the incident did not affect all Matcha users. Exposure was limited to wallets that had manually disabled one-time approvals and granted direct permissions to SwapNet contracts.

Emergency Response Measures

In response to the exploit, Matcha Meta has taken several immediate steps:

  • SwapNet contracts have been suspended to prevent further losses.
  • Users have been urged to revoke existing approvals, particularly for the SwapNet router contract
    (0x616000e384Ef1C2B52f5f3A88D57a3B64F23757e).
  • The platform has removed the option to disable one-time approvals, aiming to reduce similar risks going forward.

The incident highlights the security trade-offs associated with persistent contract approvals and reinforces the importance of regular permission reviews, especially when interacting with aggregators and routing contracts.

Disclaimer: ETHNews does not endorse and is not responsible for or liable for any content, accuracy, quality, advertising, products, or other materials on this page. Readers should do their own research before taking any actions related to cryptocurrencies. ETHNews is not responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods, or services mentioned.
Steve Kaaru
Steve Kaaru
Steve, a seasoned blockchain writer with eight years of dedicated experience, brings a wealth of knowledge and passion to the world of cryptocurrency. With a deep-rooted commitment to advancing the adoption of blockchain solutions, he strives to bridge the gap between innovation and impact, making the world a better place through blockchain's incredible potential.
RELATED ARTICLES

LATEST ARTICLES