SwapNet Exploit Drains $17M, Exposes DeFi Approval Risks

TheNewsCrypto发布于2026-01-26更新于2026-01-26

文章摘要

A significant security breach occurred at DEX aggregator SwapNet, resulting in a loss of approximately $16.8 million. The exploit was first identified by security firm PeckShield. The attacker swapped $10.5 million in USDC for Ether on Base network and bridged the funds to Ethereum. The vulnerability stemmed from users disabling the "One-Time Approval" feature designed to restrict token permissions. By doing so, they inadvertently granted direct and persistent approvals to underlying contracts, including SwapNet’s router, which the attacker exploited. Matcha Meta, the meta-DEX aggregator through which SwapNet was accessed, clarified that the issue did not originate from its core system but from this user configuration choice. SwapNet paused its contracts to mitigate further damage and investigate the incident. Users were urged to revoke approvals granted outside the One-Time Approval framework, especially for SwapNet’s router. The event underscores a critical DeFi trade-off: one-time approvals enhance security but add friction, while unlimited approvals improve usability but create persistent risk if a platform is compromised. This incident is part of a broader pattern of exploits targeting unverified code and standing approvals, highlighting ongoing risks in DeFi’s interconnected ecosystem. SwapNet has not yet released a technical post-mortem or confirmed user compensation.

A massive smart contract hack has been identified in the on-chain DEX aggregator SwapNet, which resulted in crypto assets to the tune of close to $16.8 million being siphoned off.

Peck Shield, a security company, first reported the attack, noting the suspicious action on the platform’s SwapNet integrations, which can be found through Matcha Meta, a meta-Dex aggregator platform that the 0x team designed. On the Base network, the hacker swapped $10.5 million in USDC tokens for approximately 3,655 Ether. The attacker then bridged the funds to the Ethereum network, which can be complicated to track and trace.

Matcha Meta explained, however, that the bug didn’t even emanate from its primary stack. The issue for users began with them disabling 0x’s own feature, called “One-Time Approval,” which is designed to restrict tokens’ permissions. In disabling this, users inadvertently allowed approvals directly, rather than restricting them, even for underlying aggregator contracts like SwapNet’s router, which is used by this attacker.

Matcha Meta recognized this publicly and stated that it had collaborated with the SwapNet team. SwapNet had paused the smart contracts to contain the damage and identify the exploit path for their investigation.

Approval settings under scrutiny

The platform urged users to immediately revoke approvals granted outside the One-Time Approval framework. It highlighted SwapNet’s router contract as a priority target for revocation. Without intervention, wallets would have remained exposed even after the exploit stopped.

This situation highlights an important trade-off inherent in DeFi applications. With One-Time Approvals, each transaction must be separately authorized. This, of course, helps with reduced permissions but also introduces friction. By contrast, Unlimited approvals facilitate smooth trading but grant contracts persistent access to funds. When attackers compromise a contract, those standing permissions become a direct risk.

SwapNet has not yet published a detailed technical post-mortem. The team also has not confirmed whether it will compensate affected users. That lack of clarity adds pressure on aggregator platforms to improve transparency and tighten integration standards.

Broader pattern of smart contract risks

The SwapNet exploit has not happened in a vacuum. In fact, on the same day, a different Ethereum exploit was spotted by Pashov, a security auditor, where about 37 WBTC, valued at over $3.1 million, was stolen. The exploit targeted a closed-source and unverified code deployed just weeks earlier. In fact, this code exposed the bytecode only, and it was difficult to evaluate it easily.

All of these attacks create a sense of a topological threat landscape on DeFi protocols, specifically around unverified codes, continuous token approvals, and complex routing layers connecting various protocols. Clearly, in spite of improved audits and better tools, threat actors continue to leverage design optimization and integration blind spots.

As DeFi grows more interconnected, developers must harden approval systems and reduce hidden trust assumptions. Meanwhile, users must actively manage permissions and understand the security implications of convenience features. The SwapNet exploit shows that small configuration choices can have multi-million-dollar consequences.

Highlighted Crypto News:

Japan Targets First Crypto ETFs Approval by 2028

Tagscrypto securityDeFiDEXOnchainSmart Contract

相关问答

QWhat was the total amount of crypto assets drained in the SwapNet exploit?

AClose to $16.8 million (or $17 million) in crypto assets was drained.

QWhich security company first reported the SwapNet attack and on which platform's integrations was the suspicious action noted?

APeckShield first reported the attack, noting the suspicious action on the platform's SwapNet integrations, which can be found through Matcha Meta.

QWhat specific user action, related to a 0x feature, inadvertently allowed the vulnerability to be exploited?

AUsers disabling the 'One-Time Approval' feature, which is designed to restrict tokens' permissions, inadvertently allowed direct and persistent approvals.

QAccording to the article, what is the critical trade-off between 'One-Time Approvals' and 'Unlimited Approvals' in DeFi?

AOne-Time Approvals reduce permissions but introduce friction by requiring separate authorization for each transaction, while Unlimited Approvals facilitate smooth trading but grant contracts persistent access to funds, creating a direct risk if a contract is compromised.

QBesides the SwapNet incident, what other exploit was reported on the same day and what was the value of the assets stolen?

AA different Ethereum exploit was spotted by security auditor Pashov on the same day, where about 37 WBTC, valued at over $3.1 million, was stolen.

你可能也喜欢

帕克·刘易斯解释为何比特币仍是最佳货币

知名比特币分析师帕克·刘易斯在访谈中批评了某些上市公司以“数字信贷”形式销售永续优先股的营销策略,认为这从根本上扭曲了比特币的本质。他指出,比特币在算法层面不具备法币收益性,承诺定期分红主要依赖牛市吸引新投资者来维持,风险极高。 刘易斯引用数据说明此类衍生品的巨大风险:全球信贷市场规模达300万亿美元,而永续优先股市场仅约1万亿美元,这表明机构有意规避这种无还款期限的资产,将风险转嫁给信息不足的散户。 针对“比特币波动性太大”的常见观点,他认为波动性是这一供应量严格受限的新资产被大规模采用过程中的自然数学结果。新人入场需出更高价从早期持有者手中购买,导致价格剧烈波动。他建议投资者直接持有比特币,这比投资MicroStrategy等公司发行的衍生品更安全。 投资者将焦点从直接持有加密货币转向公司衍生品,会忽视法币急速贬值的真正威胁。刘易斯以自创的“肋眼牛排指数”为例,指出其本地超市一款牛排价格从2020年的19.99美元涨至37.99美元,反映年化约12-13%的真实通胀,远超官方平滑后的CPI数据。 在全球通胀环境下,最明智、保守且安全的策略仍是直接持有比特币并完全掌控私钥。追逐加密货币国库股等公司工具的收益只会叠加隐性系统风险,而理解去中心化货币的本质才能有效保护财富免受宏观经济动荡影响。

cryptonews.ru1小时前

帕克·刘易斯解释为何比特币仍是最佳货币

cryptonews.ru1小时前

比特币为何在美联储强硬暂停后守住 64,000 美元关口

比特币在美联储暂停加息后维持在64,000美元附近,结束了7月的交易。市场对美联储维持利率不变的决定反应剧烈,但并未获得政策即将转向的明确信号。在此背景下,资金重新流入比特币现货ETF,加密货币总市值保持在2.29万亿美元左右,主要山寨币走势分化。 投资者目前处于观望状态。一方面,高利率和美联储的强硬立场抑制了风险偏好;另一方面,市场未出现恐慌性抛售、比特币ETF恢复资金净流入以及关键价位的韧性表明,数字资产市场尚未准备好大幅下跌。 **关键信息:** - 美联储维持利率在3.50%-3.75%,投票结果为9:3,三位委员支持加息。 - 比特币现货ETF净流入3210万美元,结束了连续流出;以太坊ETF则净流出约1865万美元。 - 比特币在63,000-66,000美元区间内盘整,63,000-63,500美元构成支撑,66,000美元是近期阻力。 - 以太坊价格在1,900美元附近承压,但其网络基本面(如质押意愿)保持稳定。 - 资金在主要加密货币间轮动,比特币重获机构青睐,Solana相关产品也有资金流入。 - 美国CLARITY Act法案审议被推迟至秋季,降低了其在2026年内通过的可能性。 技术层面,比特币能否在63,000美元上方保持稳固、以太坊能否守住1,860美元以及机构资金流入能否持续,被视为市场能否在2026年下半年构筑复苏基础的关键信号。

cryptonews.ru1小时前

比特币为何在美联储强硬暂停后守住 64,000 美元关口

cryptonews.ru1小时前

交易

现货
活动图片