SwapNet Exploit Drains $17M, Exposes DeFi Approval Risks

TheNewsCryptoPubblicato 2026-01-26Pubblicato ultima volta 2026-01-26

Introduzione

A significant security breach occurred at DEX aggregator SwapNet, resulting in a loss of approximately $16.8 million. The exploit was first identified by security firm PeckShield. The attacker swapped $10.5 million in USDC for Ether on Base network and bridged the funds to Ethereum. The vulnerability stemmed from users disabling the "One-Time Approval" feature designed to restrict token permissions. By doing so, they inadvertently granted direct and persistent approvals to underlying contracts, including SwapNet’s router, which the attacker exploited. Matcha Meta, the meta-DEX aggregator through which SwapNet was accessed, clarified that the issue did not originate from its core system but from this user configuration choice. SwapNet paused its contracts to mitigate further damage and investigate the incident. Users were urged to revoke approvals granted outside the One-Time Approval framework, especially for SwapNet’s router. The event underscores a critical DeFi trade-off: one-time approvals enhance security but add friction, while unlimited approvals improve usability but create persistent risk if a platform is compromised. This incident is part of a broader pattern of exploits targeting unverified code and standing approvals, highlighting ongoing risks in DeFi’s interconnected ecosystem. SwapNet has not yet released a technical post-mortem or confirmed user compensation.

A massive smart contract hack has been identified in the on-chain DEX aggregator SwapNet, which resulted in crypto assets to the tune of close to $16.8 million being siphoned off.

Peck Shield, a security company, first reported the attack, noting the suspicious action on the platform’s SwapNet integrations, which can be found through Matcha Meta, a meta-Dex aggregator platform that the 0x team designed. On the Base network, the hacker swapped $10.5 million in USDC tokens for approximately 3,655 Ether. The attacker then bridged the funds to the Ethereum network, which can be complicated to track and trace.

Matcha Meta explained, however, that the bug didn’t even emanate from its primary stack. The issue for users began with them disabling 0x’s own feature, called “One-Time Approval,” which is designed to restrict tokens’ permissions. In disabling this, users inadvertently allowed approvals directly, rather than restricting them, even for underlying aggregator contracts like SwapNet’s router, which is used by this attacker.

Matcha Meta recognized this publicly and stated that it had collaborated with the SwapNet team. SwapNet had paused the smart contracts to contain the damage and identify the exploit path for their investigation.

Approval settings under scrutiny

The platform urged users to immediately revoke approvals granted outside the One-Time Approval framework. It highlighted SwapNet’s router contract as a priority target for revocation. Without intervention, wallets would have remained exposed even after the exploit stopped.

This situation highlights an important trade-off inherent in DeFi applications. With One-Time Approvals, each transaction must be separately authorized. This, of course, helps with reduced permissions but also introduces friction. By contrast, Unlimited approvals facilitate smooth trading but grant contracts persistent access to funds. When attackers compromise a contract, those standing permissions become a direct risk.

SwapNet has not yet published a detailed technical post-mortem. The team also has not confirmed whether it will compensate affected users. That lack of clarity adds pressure on aggregator platforms to improve transparency and tighten integration standards.

Broader pattern of smart contract risks

The SwapNet exploit has not happened in a vacuum. In fact, on the same day, a different Ethereum exploit was spotted by Pashov, a security auditor, where about 37 WBTC, valued at over $3.1 million, was stolen. The exploit targeted a closed-source and unverified code deployed just weeks earlier. In fact, this code exposed the bytecode only, and it was difficult to evaluate it easily.

All of these attacks create a sense of a topological threat landscape on DeFi protocols, specifically around unverified codes, continuous token approvals, and complex routing layers connecting various protocols. Clearly, in spite of improved audits and better tools, threat actors continue to leverage design optimization and integration blind spots.

As DeFi grows more interconnected, developers must harden approval systems and reduce hidden trust assumptions. Meanwhile, users must actively manage permissions and understand the security implications of convenience features. The SwapNet exploit shows that small configuration choices can have multi-million-dollar consequences.

Highlighted Crypto News:

Japan Targets First Crypto ETFs Approval by 2028

Tagscrypto securityDeFiDEXOnchainSmart Contract

Domande pertinenti

QWhat was the total amount of crypto assets drained in the SwapNet exploit?

AClose to $16.8 million (or $17 million) in crypto assets was drained.

QWhich security company first reported the SwapNet attack and on which platform's integrations was the suspicious action noted?

APeckShield first reported the attack, noting the suspicious action on the platform's SwapNet integrations, which can be found through Matcha Meta.

QWhat specific user action, related to a 0x feature, inadvertently allowed the vulnerability to be exploited?

AUsers disabling the 'One-Time Approval' feature, which is designed to restrict tokens' permissions, inadvertently allowed direct and persistent approvals.

QAccording to the article, what is the critical trade-off between 'One-Time Approvals' and 'Unlimited Approvals' in DeFi?

AOne-Time Approvals reduce permissions but introduce friction by requiring separate authorization for each transaction, while Unlimited Approvals facilitate smooth trading but grant contracts persistent access to funds, creating a direct risk if a contract is compromised.

QBesides the SwapNet incident, what other exploit was reported on the same day and what was the value of the assets stolen?

AA different Ethereum exploit was spotted by security auditor Pashov on the same day, where about 37 WBTC, valued at over $3.1 million, was stolen.

Letture associate

In-depth: The Foreign Guest Genspark

The article "The Foreign Guest: Genspark" investigates the identity and business practices of AI startup Genspark, which presents itself as a Palo Alto-based "AI Costco" offering a subscription bundle of over 70 models and numerous AI agent tools. Despite its official Silicon Valley narrative, Genspark's founding team has deep roots in Chinese tech giant Baidu, a history systematically downplayed in its branding. The company actively cultivates an image as an elite US firm, heavily publicizing partnerships and endorsements from OpenAI, Anthropic, and Microsoft, while distancing itself from the Chinese AI community and obscuring its connections to Chinese investors and open-weight models (like those from DeepSeek, Moonshot AI, and MiniMax) that power its services. Genspark's core strategy involves rapidly cloning and integrating successful AI product concepts (e.g., from Perplexity, Manus, Plaud) into its unified platform, supported by aggressive marketing, including Super Bowl ads and paid native content in publications like The Wall Street Journal. Critically, the article suggests a significant portion of its engineering and product development is conducted by a team in Beijing, operating outside its official US corporate structure. This duality allows Genspark to leverage Chinese talent and models for efficiency and cost reduction while constructing a public facade as a purely American success story. The piece concludes that Genspark's most effective agent is its own corporate identity, meticulously engineered to obscure its Chinese underpinnings and be perceived solely as a Silicon Valley company.

marsbit40 min fa

In-depth: The Foreign Guest Genspark

marsbit40 min fa

Debate: Korean Workers Fear Unemployment, While Musk Envisions a Society 'Without Work'?

While South Korean auto workers fear job losses from robotics, Elon Musk envisions a future where AI and robots render most work optional. This article explores the growing tension between immediate anxieties over automation and long-term visions of a post-work society. The piece begins with recent strikes at Hyundai's Korean plants, where unions, amid standard wage negotiations, also sought job guarantees against advancing robotics—specifically mentioning Boston Dynamics' Atlas. This reflects how anxiety about technological displacement is emerging even before robots are fully capable of replacing skilled labor on assembly lines. The author argues that while current robotics still struggle with the nuanced, experiential knowledge of veteran workers, the *perception* of imminent replacement is fueling social conflict prematurely. This modern "Luddite" sentiment is compared to the 19th-century English textile workers who smashed machines. Historically, Luddites weren't simply anti-technology; they were protesting the rapid devaluation of their skills and the unequal distribution of productivity gains. Similarly, today's workers ask who will bear the cost of transition and share in the new wealth created by machines. In contrast, figures like Elon Musk propose an optimistic endpoint: with AI and robotics driving extreme abundance, the link between work and survival could break. He suggests concepts like "Universal High Income" could allow society to share the technological bounty, transforming work from a necessity into a choice. The core challenge, however, lies in the transition. The author notes that technology's benefits diffuse slowly, while its disruptive costs—job losses, skill obsolescence—can be concentrated and immediate. The risk is a painful interim period where productivity gains are captured by a few before new social contracts, safety nets, and retraining systems are established. The conclusion calls for proactive governance. Just as past industrial revolutions gave rise to labor standards and social safety nets, the robotics era needs its own frameworks. These should address job transition support, distribution of productivity gains, safety liability, and ethical deployment. Embracing such "constraints" is not opposition to progress but a necessary step to ensure technology benefits society broadly. The discussion sparked by Hyundai's workers, therefore, is not premature but essential.

marsbit53 min fa

Debate: Korean Workers Fear Unemployment, While Musk Envisions a Society 'Without Work'?

marsbit53 min fa

Trading

Spot
活动图片