SwapNet exploit highlights smart contract risks as crypto theft tops $3.41B, driven by cross-chain moves and weak approvals. Decentralized exchange aggregator MatchaSwapNet exploit highlights smart contract risks as crypto theft tops $3.41B, driven by cross-chain moves and weak approvals. Decentralized exchange aggregator Matcha

Matcha Meta Removes Direct Allowances After $16.8M SwapNet Exploit as Crypto Hacks Rise

2026/01/27 00:45
4 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

SwapNet exploit highlights smart contract risks as crypto theft tops $3.41B, driven by cross-chain moves and weak approvals.

Decentralized exchange aggregator Matcha Meta has reported a security incident tied to its SwapNet integration. According to several onchain watchers, malicious actors have pulled out crypto assets worth about $16.8 million after an attack that targeted the platform’s smart contract weakness. 

SwapNet Integration Exploit Triggers Security Incident at Matcha Meta

In a Monday notice, Matcha Meta explained that it was a victim of a security breach the previous day. As contained in the disclosure, attackers moved digital assets from an external aggregator linked to Matcha Meta’s interface, SwapNet. 

The platform disclosed that it spotted the suspicious movements after noticing large, unauthorized transfers from SwapNet’s router contract. In the statement, MM confirmed that it had contacted the SwapNet team to temporarily disable its contracts.

As per reports from blockchain security firm PeckShield, losses from the breach are pegged at roughly $16.8 million. Analysis showed the attacker swapped about $10.5 million in USDC on Base for around 3,655 ETH. Afterwards, the funds were bridged to Ethereum. 

Meanwhile, CertiK earlier placed the loss closer to $13.3 million in USDC on Base. CertiK linked the attack to an “arbitrary call” vulnerability in the SwapNet contract, which allowed previously approved funds to be transferred to the contract.

Matcha Meta has not confirmed whether user funds were fully lost. An initial statement said exposure was limited to users who had disabled One-Time Approvals and instead set direct allowances on specific aggregator contracts. The protocol added that accounts using One-Time Approval were not affected.

But following a review with the protocol team at 0x, Matcha Meta clarified that the issue did not involve 0x’s AllowanceHolder or Settler contracts.

The team clarified that users who disable One-Time Approval and rely on direct allowances assume additional risk tied to each aggregator. Matcha Meta added that it has removed the option to set direct allowances on aggregators to prevent similar incidents.

Smart Contract Flaws and Cross-Chain Laundering Fuel Rising Crypto Hacks

With the increasing growth of the crypto market, security breaches continue to pressure projects and platforms in the sector. According to Chainalysis, crypto-related theft exceeded $3.41 billion in 2025, slightly higher than the previous year. 

A large share of illicit activity involved rapid asset movement across chains and services designed to obscure transaction trails.

Interestingly, research by Elliptic shows that many laundering operations now rely on coin-swapping services. Such services often operate through standalone websites or Telegram channels, enabling attackers to quickly move stolen funds. 

Similar risks surfaced last year when decentralized exchange aggregator CoWSwap reported a breach. During the onchain raid, about $180,000 in DAI was withdrawn via the GPv2Settlement smart contract.

As observed by market watchers, smart contract flaws remain a leading cause of losses. SlowMist reported that contract vulnerabilities accounted for just over 30% of crypto exploits in 2025. 

Image Source: SlowMist

Additionally, experts have pointed to advances in AI technology as another factor driving active exploitation. Artificial intelligence helps drive vulnerability discovery and active exploitation.

A single $1.5 billion hack of Bybit represented 44% of all losses in the past year. Meanwhile, North Korea-linked groups stole a record $2.02 billion.

Since the turn of the year, crypto-focused platforms have seen a surge in attacks. DeFi protocol Makina Finance lost about $4.13 million after hackers drained its DUSD/USDC pool on Curve. Shortly after, Layer-1 network Saga paused its SagaEVM chain following an exploit that moved nearly $7 million in assets to Ethereum.

Image by Clint Patterson from Unsplash

The post Matcha Meta Removes Direct Allowances After $16.8M SwapNet Exploit as Crypto Hacks Rise appeared first on Live Bitcoin News.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Stunning 96% Surge And 50% Plunge Define Volatile Market Session

Stunning 96% Surge And 50% Plunge Define Volatile Market Session

The post Stunning 96% Surge And 50% Plunge Define Volatile Market Session appeared on BitcoinEthereumNews.com. Crypto Gainers And Losers: Stunning 96% Surge And
Share
BitcoinEthereumNews2026/04/03 09:20
BitGo Holdings (BTGO) Stock Climbs Following Launch of Institutional Stablecoin Platform

BitGo Holdings (BTGO) Stock Climbs Following Launch of Institutional Stablecoin Platform

BitGo Holdings (BTGO) stock climbs as the company launches BitGo Mint, streamlining stablecoin operations for institutional clients. The post BitGo Holdings (BTGO
Share
Blockonomi2026/04/02 21:13
Coinbase adds USDC lending with Morpho on Base

Coinbase adds USDC lending with Morpho on Base

The post Coinbase adds USDC lending with Morpho on Base appeared on BitcoinEthereumNews.com. Coinbase will introduce USDC lending directly within its app, allowing users to earn yields as high as 10.8% through a new onchain integration with Morpho, the company said on Thursday. The feature, which will roll out to customers in the US (excluding New York), Bermuda, and other jurisdictions over the coming weeks, enables users to lend their USDC to borrowers on Base, Coinbase’s layer-2 blockchain. The lending system works by creating a smart contract wallet that connects to the Morpho protocol, with Steakhouse Financial managing onchain vaults that allocate liquidity across multiple markets. This design is meant to optimize returns while preserving user access to funds, which can be withdrawn when liquidity is available. Coinbase emphasized that despite the complexity of decentralized finance (DeFi), the integration will maintain the platform’s familiar interface and security features. USDC, a stablecoin redeemable 1:1 for U.S. dollars, already provides Coinbase users with passive rewards of 4.1% APY, or 4.5% for Coinbase One members. The lending expansion marks a push to increase earnings potential for holders of the asset, which has a circulating supply of more than $73 billion. Subheading updated 9/18/25 at 1:02 p.m. to correct a typo in yield percentage. This article was generated with the assistance of AI and reviewed by editor Jeffrey Albus before publication. Get the news in your inbox. Explore Blockworks newsletters: Source: https://blockworks.co/news/coinbase-usdc-onchain
Share
BitcoinEthereumNews2025/09/19 01:13

Trade GOLD, Share 1,000,000 USDT

Trade GOLD, Share 1,000,000 USDTTrade GOLD, Share 1,000,000 USDT

0 fees, up to 1,000x leverage, deep liquidity