Decentralized exchange aggregator Matcha Meta has disclosed a security incident tied to its integrated liquidity provider SwapNet, in which an attacker abused token approvals to drain user funds. Blockchain security firm PeckShield reported that around $16.8 million in crypto was stolen, primarily affecting users who had disabled Matcha Meta’s default “One-Time Approval” flow and instead granted direct, often infinite, approvals to SwapNet’s own contracts.
According to Matcha Meta’s post-mortem, the core 0x infrastructure (including the AllowanceHolder and Settler contracts) was not compromised; the exploit targeted SwapNet’s smart contracts, which contained an arbitrary call vulnerability that allowed the attacker to drain any tokens users had previously approved to those contracts. Impact was concentrated in a small group of users: Matcha Meta later calculated about $13.43 million in losses for 18 users, including one very large account, while external estimates of ~$16.8 million folded in losses from a separate Aperture Finance incident occurring at the same time. On the Base network, the attacker converted roughly 10.5 million USDC into about 3,655 ETH and began bridging funds to Ethereum.
In response, Matcha Meta urged all potentially affected users to immediately revoke token approvals to SwapNet’s router/contract addresses using tools such as Revoke.cash, and emphasized that users who only used the default One-Time Approval setting are not at risk. SwapNet paused its contracts across chains after the exploit was detected, and Matcha Meta has since removed SwapNet from its routing and disabled the user option to bypass One-Time Approvals, forcing all future trades through its more controlled approval system. The incident has become a prominent example of how broad, direct token approvals to third-party DeFi contracts can be weaponized at scale, reinforcing industry warnings about the security trade-offs of infinite approvals and aggregator integrations.
"entities":["Matcha Meta","SwapNet","0x","0x AllowanceHolder","0x Settler","PeckShield","CertiK","Base (Layer 2 network)","Ethereum","USDC","ETH","Revoke.cash","Aperture Finance","Blockaid","Circle","Truebit (TRU)"]}`
✨ AI-generated background, compiled from web sources — not editorial content.