SwapNet Exploit Drains $17M, Exposes DeFi Approval Risks

TheNewsCrypto发布于2026-01-26更新于2026-01-26

文章摘要

A significant security breach occurred at DEX aggregator SwapNet, resulting in a loss of approximately $16.8 million. The exploit was first identified by security firm PeckShield. The attacker swapped $10.5 million in USDC for Ether on Base network and bridged the funds to Ethereum. The vulnerability stemmed from users disabling the "One-Time Approval" feature designed to restrict token permissions. By doing so, they inadvertently granted direct and persistent approvals to underlying contracts, including SwapNet’s router, which the attacker exploited. Matcha Meta, the meta-DEX aggregator through which SwapNet was accessed, clarified that the issue did not originate from its core system but from this user configuration choice. SwapNet paused its contracts to mitigate further damage and investigate the incident. Users were urged to revoke approvals granted outside the One-Time Approval framework, especially for SwapNet’s router. The event underscores a critical DeFi trade-off: one-time approvals enhance security but add friction, while unlimited approvals improve usability but create persistent risk if a platform is compromised. This incident is part of a broader pattern of exploits targeting unverified code and standing approvals, highlighting ongoing risks in DeFi’s interconnected ecosystem. SwapNet has not yet released a technical post-mortem or confirmed user compensation.

A massive smart contract hack has been identified in the on-chain DEX aggregator SwapNet, which resulted in crypto assets to the tune of close to $16.8 million being siphoned off.

Peck Shield, a security company, first reported the attack, noting the suspicious action on the platform’s SwapNet integrations, which can be found through Matcha Meta, a meta-Dex aggregator platform that the 0x team designed. On the Base network, the hacker swapped $10.5 million in USDC tokens for approximately 3,655 Ether. The attacker then bridged the funds to the Ethereum network, which can be complicated to track and trace.

Matcha Meta explained, however, that the bug didn’t even emanate from its primary stack. The issue for users began with them disabling 0x’s own feature, called “One-Time Approval,” which is designed to restrict tokens’ permissions. In disabling this, users inadvertently allowed approvals directly, rather than restricting them, even for underlying aggregator contracts like SwapNet’s router, which is used by this attacker.

Matcha Meta recognized this publicly and stated that it had collaborated with the SwapNet team. SwapNet had paused the smart contracts to contain the damage and identify the exploit path for their investigation.

Approval settings under scrutiny

The platform urged users to immediately revoke approvals granted outside the One-Time Approval framework. It highlighted SwapNet’s router contract as a priority target for revocation. Without intervention, wallets would have remained exposed even after the exploit stopped.

This situation highlights an important trade-off inherent in DeFi applications. With One-Time Approvals, each transaction must be separately authorized. This, of course, helps with reduced permissions but also introduces friction. By contrast, Unlimited approvals facilitate smooth trading but grant contracts persistent access to funds. When attackers compromise a contract, those standing permissions become a direct risk.

SwapNet has not yet published a detailed technical post-mortem. The team also has not confirmed whether it will compensate affected users. That lack of clarity adds pressure on aggregator platforms to improve transparency and tighten integration standards.

Broader pattern of smart contract risks

The SwapNet exploit has not happened in a vacuum. In fact, on the same day, a different Ethereum exploit was spotted by Pashov, a security auditor, where about 37 WBTC, valued at over $3.1 million, was stolen. The exploit targeted a closed-source and unverified code deployed just weeks earlier. In fact, this code exposed the bytecode only, and it was difficult to evaluate it easily.

All of these attacks create a sense of a topological threat landscape on DeFi protocols, specifically around unverified codes, continuous token approvals, and complex routing layers connecting various protocols. Clearly, in spite of improved audits and better tools, threat actors continue to leverage design optimization and integration blind spots.

As DeFi grows more interconnected, developers must harden approval systems and reduce hidden trust assumptions. Meanwhile, users must actively manage permissions and understand the security implications of convenience features. The SwapNet exploit shows that small configuration choices can have multi-million-dollar consequences.

Highlighted Crypto News:

Japan Targets First Crypto ETFs Approval by 2028

Tagscrypto securityDeFiDEXOnchainSmart Contract

相关问答

QWhat was the total amount of crypto assets drained in the SwapNet exploit?

AClose to $16.8 million (or $17 million) in crypto assets was drained.

QWhich security company first reported the SwapNet attack and on which platform's integrations was the suspicious action noted?

APeckShield first reported the attack, noting the suspicious action on the platform's SwapNet integrations, which can be found through Matcha Meta.

QWhat specific user action, related to a 0x feature, inadvertently allowed the vulnerability to be exploited?

AUsers disabling the 'One-Time Approval' feature, which is designed to restrict tokens' permissions, inadvertently allowed direct and persistent approvals.

QAccording to the article, what is the critical trade-off between 'One-Time Approvals' and 'Unlimited Approvals' in DeFi?

AOne-Time Approvals reduce permissions but introduce friction by requiring separate authorization for each transaction, while Unlimited Approvals facilitate smooth trading but grant contracts persistent access to funds, creating a direct risk if a contract is compromised.

QBesides the SwapNet incident, what other exploit was reported on the same day and what was the value of the assets stolen?

AA different Ethereum exploit was spotted by security auditor Pashov on the same day, where about 37 WBTC, valued at over $3.1 million, was stolen.

你可能也喜欢

深度:外宾 Genspark

文章《深度:外宾 Genspark》揭示了人工智能创业公司Genspark及其母公司MainFunc在身份叙事与商业运作上的复杂性。 Genspark自称是总部位于加州帕洛阿尔托、由微软等前员工创立的“硅谷公司”,并积极利用与OpenAI、Anthropic、微软等巨头的合作(如API采购、客户案例、高管合影)来强化其“美国AI公司”的品牌形象。然而,其核心创始人景鲲和朱凯华均出身百度,这段重要履历在对外宣传中被系统性地淡化或省略。 文章指出,Genspark在面对不同社群时姿态迥异:积极亮相主流国际商业会议并赞助,但对硅谷华人社区活动和中国同行则显得疏离甚至回避。在技术合作上,它热情宣布接入美国闭源模型(如GPT、Claude),却通过第三方平台间接调用中国的开放权重模型(如Kimi、DeepSeek),避免与中国模型公司产生直接的品牌关联。其重要投资方之一、来自新加坡的蓝驰创投也被在对外叙事中“隐身”。 商业层面,Genspark被描述为“AI界的Costco”,其核心模式并非技术创新,而是快速复制市场已验证的热门AI产品形态(如Perplexity的搜索、Manus的通用Agent、Plaud的硬件等),将其整合进统一的订阅套餐,再通过大规模、高调的广告投放(如超级碗、纽约地铁)和联盟营销驱动增长。尽管网站流量存在波动,但其宣称的年化收入快速攀升至2.5亿美元。有分析认为,其收入可能部分来自无法直接获取美国前沿模型服务的中国客户,通过Genspark进行“中转”。 文章最终揭示,Genspark的成功依赖于一套精密的双重策略:在台前构筑纯正的硅谷身份,充分利用美国科技生态的品牌和资源;在幕后,则可能依赖一个未公开的、位于中国的研发团队作为其“产品工厂”,并隐秘地整合来自中国的资本、技术供应链与潜在客户。它试图让世界相信其只是一家美国公司,而其真正的竞争力恰恰来自这种游走于中美两个世界之间、却选择性呈现的商业与叙事系统。

marsbit40分钟前

深度:外宾 Genspark

marsbit40分钟前

比特币该不该“一成不变”?Craig Wright再掀治理路线之争

比特币治理再次成为焦点,核心问题是:一套运行十多年的去中心化规则,谁有权改变?Craig Wright近期主张协议应永久固定,认为比特币的核心价值在于其公开、透明、不可随意改变的货币规则,而非交易速度或功能扩展。这重新引发了社区关于治理模式的讨论。 支持固定协议者强调,规则的确定性是比特币区别于传统金融体系、建立信任的基石。若协议可被频繁修改,恐将削弱其核心价值。另一方面,反对者认为,面对安全威胁、效率问题和用户需求的变化,系统必须具备升级能力。真正的争议并非“改或不改”,而在于改变的权力归属与过程是否符合去中心化原则。 文章回顾了比特币并非一成不变,如隔离见证(SegWit)和Taproot等重要升级均通过社区共识完成。然而,治理过程也暴露矛盾,例如2017年的区块扩容之争最终导致了分叉。争论的实质是“规则优先”与“适应现实”两种价值理念的冲突。 同时,开发者角色的影响力也成为隐忧。尽管比特币没有中心管理机构,但核心开发者在维护代码和推动讨论中具有重要话语权。然而,任何重大升级最终仍需依赖矿工、节点运营商及广大用户的社会共识,这是一种独特的协调机制。 对于市场参与者而言,治理争论直接影响比特币的长期价值:协议稳定性关乎市场信任,而技术升级能力则决定其网络竞争力。比特币未来的挑战在于,如何在保持核心规则稳定与适应现实需求之间取得平衡。 Craig Wright的个人争议虽影响其可信度,但其提出的治理问题具有讨论价值。比特币最大的创新或许不仅在于技术,更在于这种无中心权威的全球治理实验。其未来发展很可能是在核心稳定的基础上,通过社区共识进行有限且谨慎的升级。这场关于稳定与进化的争论,仍将持续。

marsbit42分钟前

比特币该不该“一成不变”?Craig Wright再掀治理路线之争

marsbit42分钟前

讨论:韩国工人害怕失业,马斯克却在预想“没有工作”的社会?

本文探讨了韩国现代汽车工人因担忧AI与机器人技术威胁就业而发起罢工,与埃隆·马斯克所描绘的AI和机器人将创造“极度丰裕”、使工作成为可选项的未来图景,两者之间形成的鲜明对比与深刻分歧。 文章指出,工人的焦虑源于技术替代的长期可能性被舆论提前兑现,尽管当前人形机器人要稳定替代汽车生产线上的熟练工人仍面临巨大技术挑战。这种情绪与历史上的“卢德运动”一脉相承,其核心并非反对技术本身,而是追问技术提升效率后,新增财富如何分配,以及转型成本由谁承担。 马斯克提出的“全民高收入”愿景,其实现前提是技术创造的巨大生产力能被社会广泛分享。然而,从当前依赖劳动获取收入的社会,过渡到那个理想未来,中间可能存在漫长的“阵痛期”,部分群体可能首先承担失业与技能贬值的代价。 文章最后强调,面对机器人产业化趋势,社会不应只是被动等待。正如工业革命伴随产生了劳动保障等一系列社会规则,对于AI与机器人技术,也需要提前建立关于利益分配、就业转型、安全责任等方面的规范与框架。这种对“条条框框”的探讨,并非阻碍技术进步,而是确保其能够健康、包容地融入社会,最终让技术红利惠及更多人。韩国工人的忧虑虽然可能早于技术成熟度,但相关的社会讨论已然刻不容缓。

marsbit53分钟前

讨论:韩国工人害怕失业,马斯克却在预想“没有工作”的社会?

marsbit53分钟前

交易

现货
活动图片