SwapNet Exploit Drains $17M, Exposes DeFi Approval Risks

TheNewsCryptoОпубліковано о 2026-01-26Востаннє оновлено о 2026-01-26

Анотація

A significant security breach occurred at DEX aggregator SwapNet, resulting in a loss of approximately $16.8 million. The exploit was first identified by security firm PeckShield. The attacker swapped $10.5 million in USDC for Ether on Base network and bridged the funds to Ethereum. The vulnerability stemmed from users disabling the "One-Time Approval" feature designed to restrict token permissions. By doing so, they inadvertently granted direct and persistent approvals to underlying contracts, including SwapNet’s router, which the attacker exploited. Matcha Meta, the meta-DEX aggregator through which SwapNet was accessed, clarified that the issue did not originate from its core system but from this user configuration choice. SwapNet paused its contracts to mitigate further damage and investigate the incident. Users were urged to revoke approvals granted outside the One-Time Approval framework, especially for SwapNet’s router. The event underscores a critical DeFi trade-off: one-time approvals enhance security but add friction, while unlimited approvals improve usability but create persistent risk if a platform is compromised. This incident is part of a broader pattern of exploits targeting unverified code and standing approvals, highlighting ongoing risks in DeFi’s interconnected ecosystem. SwapNet has not yet released a technical post-mortem or confirmed user compensation.

A massive smart contract hack has been identified in the on-chain DEX aggregator SwapNet, which resulted in crypto assets to the tune of close to $16.8 million being siphoned off.

Peck Shield, a security company, first reported the attack, noting the suspicious action on the platform’s SwapNet integrations, which can be found through Matcha Meta, a meta-Dex aggregator platform that the 0x team designed. On the Base network, the hacker swapped $10.5 million in USDC tokens for approximately 3,655 Ether. The attacker then bridged the funds to the Ethereum network, which can be complicated to track and trace.

Matcha Meta explained, however, that the bug didn’t even emanate from its primary stack. The issue for users began with them disabling 0x’s own feature, called “One-Time Approval,” which is designed to restrict tokens’ permissions. In disabling this, users inadvertently allowed approvals directly, rather than restricting them, even for underlying aggregator contracts like SwapNet’s router, which is used by this attacker.

Matcha Meta recognized this publicly and stated that it had collaborated with the SwapNet team. SwapNet had paused the smart contracts to contain the damage and identify the exploit path for their investigation.

Approval settings under scrutiny

The platform urged users to immediately revoke approvals granted outside the One-Time Approval framework. It highlighted SwapNet’s router contract as a priority target for revocation. Without intervention, wallets would have remained exposed even after the exploit stopped.

This situation highlights an important trade-off inherent in DeFi applications. With One-Time Approvals, each transaction must be separately authorized. This, of course, helps with reduced permissions but also introduces friction. By contrast, Unlimited approvals facilitate smooth trading but grant contracts persistent access to funds. When attackers compromise a contract, those standing permissions become a direct risk.

SwapNet has not yet published a detailed technical post-mortem. The team also has not confirmed whether it will compensate affected users. That lack of clarity adds pressure on aggregator platforms to improve transparency and tighten integration standards.

Broader pattern of smart contract risks

The SwapNet exploit has not happened in a vacuum. In fact, on the same day, a different Ethereum exploit was spotted by Pashov, a security auditor, where about 37 WBTC, valued at over $3.1 million, was stolen. The exploit targeted a closed-source and unverified code deployed just weeks earlier. In fact, this code exposed the bytecode only, and it was difficult to evaluate it easily.

All of these attacks create a sense of a topological threat landscape on DeFi protocols, specifically around unverified codes, continuous token approvals, and complex routing layers connecting various protocols. Clearly, in spite of improved audits and better tools, threat actors continue to leverage design optimization and integration blind spots.

As DeFi grows more interconnected, developers must harden approval systems and reduce hidden trust assumptions. Meanwhile, users must actively manage permissions and understand the security implications of convenience features. The SwapNet exploit shows that small configuration choices can have multi-million-dollar consequences.

Highlighted Crypto News:

Japan Targets First Crypto ETFs Approval by 2028

Tagscrypto securityDeFiDEXOnchainSmart Contract

Пов'язані питання

QWhat was the total amount of crypto assets drained in the SwapNet exploit?

AClose to $16.8 million (or $17 million) in crypto assets was drained.

QWhich security company first reported the SwapNet attack and on which platform's integrations was the suspicious action noted?

APeckShield first reported the attack, noting the suspicious action on the platform's SwapNet integrations, which can be found through Matcha Meta.

QWhat specific user action, related to a 0x feature, inadvertently allowed the vulnerability to be exploited?

AUsers disabling the 'One-Time Approval' feature, which is designed to restrict tokens' permissions, inadvertently allowed direct and persistent approvals.

QAccording to the article, what is the critical trade-off between 'One-Time Approvals' and 'Unlimited Approvals' in DeFi?

AOne-Time Approvals reduce permissions but introduce friction by requiring separate authorization for each transaction, while Unlimited Approvals facilitate smooth trading but grant contracts persistent access to funds, creating a direct risk if a contract is compromised.

QBesides the SwapNet incident, what other exploit was reported on the same day and what was the value of the assets stolen?

AA different Ethereum exploit was spotted by security auditor Pashov on the same day, where about 37 WBTC, valued at over $3.1 million, was stolen.

Пов'язані матеріали

Three Consecutive Quarters of Decline: The Crypto Market is Experiencing Its Longest Ebb Since 2022

The cryptocurrency market experienced its third consecutive quarterly decline in Q2 2026, marking its longest downturn since 2022, according to a CoinGecko report. The total market capitalization fell 12.6% to $2.1 trillion, a retreat of roughly 52% from its October 2025 peak. Multiple indicators signal an orderly capital exit from the sector. For the first time since Q3 2023, the total stablecoin market cap shrank (-1.6% to $305.1B), indicating funds are leaving the ecosystem entirely, not just rotating to safer crypto assets. Trading volumes on centralized exchanges dropped 27.9%, while DeFi's Total Value Locked (TVL) plummeted 23.4%. Both Bitcoin (-14.2%) and Ethereum (-25.4%) underperformed traditional risk assets like equities in Q2, breaking from previous correlative narratives. Ethereum saw its first-ever three-quarter losing streak, with its market share falling to around 10%. A few areas saw growth. Prediction market volumes surged 48.7%, largely driven by sports betting. Hyperliquid's HYPE token entered the top 10 by market cap, and tokenized collectibles platforms grew, though primarily via gamified mechanics. Despite a ~9.8% Bitcoin rebound in July, historical trends suggest caution for August. The market, now ~49% below its 2025 high, is undergoing a measured retreat. Its recovery hinges on future Federal Reserve policy and the industry's ability to develop sustainable revenue streams beyond speculation.

marsbit8 хв тому

Three Consecutive Quarters of Decline: The Crypto Market is Experiencing Its Longest Ebb Since 2022

marsbit8 хв тому

Insurance Agent in Hong Kong Loses Over $3.3 Million Due to 'Romantic' Crypto Scam

An experienced Hong Kong insurance agent fell victim to a "romance scam" involving fake crypto investments, losing over HK$26 million (approximately US$3.3 million), according to local police. Authorities reported 25 similar cases of online romance-linked investment fraud in just one week in late July, with total losses nearing HK$70 million. The scam began when an acquaintance introduced the victim to a woman seeking insurance advice. The woman later connected him via WhatsApp to a man nicknamed "Uncle," who claimed to sell cars. Over time, "Uncle" built trust and an online romantic relationship with the victim. He then claimed to have successful investment experience and persuaded the victim to invest in cryptocurrencies, directing him to install a fake crypto investment platform app and introducing a person posing as the platform's owner to "help" manage a crypto wallet. Over roughly six months, the victim personally handed over more than HK$4 million in cash across various Hong Kong locations and transferred nearly HK$22 million to bank accounts provided by the scammers. Suspicion only arose when the fake app showed returns exceeding 800% and withdrawal attempts were blocked. Subsequently, both the "romantic partner" and the supposed expert cut off all contact. Police emphasized that even financially experienced individuals can be defrauded when scammers use emotional pressure and gradually build trust.

cryptonews.ru41 хв тому

Insurance Agent in Hong Kong Loses Over $3.3 Million Due to 'Romantic' Crypto Scam

cryptonews.ru41 хв тому

Торгівля

Спот
活动图片