SwapNet exploit highlights smart contract risks as crypto theft tops $3.41B, driven by cross-chain moves and weak approvals. Decentralized exchange aggregator MatchaSwapNet exploit highlights smart contract risks as crypto theft tops $3.41B, driven by cross-chain moves and weak approvals. Decentralized exchange aggregator Matcha

Matcha Meta Removes Direct Allowances After $16.8M SwapNet Exploit as Crypto Hacks Rise

4 min read

SwapNet exploit highlights smart contract risks as crypto theft tops $3.41B, driven by cross-chain moves and weak approvals.

Decentralized exchange aggregator Matcha Meta has reported a security incident tied to its SwapNet integration. According to several onchain watchers, malicious actors have pulled out crypto assets worth about $16.8 million after an attack that targeted the platform’s smart contract weakness. 

SwapNet Integration Exploit Triggers Security Incident at Matcha Meta

In a Monday notice, Matcha Meta explained that it was a victim of a security breach the previous day. As contained in the disclosure, attackers moved digital assets from an external aggregator linked to Matcha Meta’s interface, SwapNet. 

The platform disclosed that it spotted the suspicious movements after noticing large, unauthorized transfers from SwapNet’s router contract. In the statement, MM confirmed that it had contacted the SwapNet team to temporarily disable its contracts.

As per reports from blockchain security firm PeckShield, losses from the breach are pegged at roughly $16.8 million. Analysis showed the attacker swapped about $10.5 million in USDC on Base for around 3,655 ETH. Afterwards, the funds were bridged to Ethereum. 

Meanwhile, CertiK earlier placed the loss closer to $13.3 million in USDC on Base. CertiK linked the attack to an “arbitrary call” vulnerability in the SwapNet contract, which allowed previously approved funds to be transferred to the contract.

Matcha Meta has not confirmed whether user funds were fully lost. An initial statement said exposure was limited to users who had disabled One-Time Approvals and instead set direct allowances on specific aggregator contracts. The protocol added that accounts using One-Time Approval were not affected.

But following a review with the protocol team at 0x, Matcha Meta clarified that the issue did not involve 0x’s AllowanceHolder or Settler contracts.

The team clarified that users who disable One-Time Approval and rely on direct allowances assume additional risk tied to each aggregator. Matcha Meta added that it has removed the option to set direct allowances on aggregators to prevent similar incidents.

Smart Contract Flaws and Cross-Chain Laundering Fuel Rising Crypto Hacks

With the increasing growth of the crypto market, security breaches continue to pressure projects and platforms in the sector. According to Chainalysis, crypto-related theft exceeded $3.41 billion in 2025, slightly higher than the previous year. 

A large share of illicit activity involved rapid asset movement across chains and services designed to obscure transaction trails.

Interestingly, research by Elliptic shows that many laundering operations now rely on coin-swapping services. Such services often operate through standalone websites or Telegram channels, enabling attackers to quickly move stolen funds. 

Similar risks surfaced last year when decentralized exchange aggregator CoWSwap reported a breach. During the onchain raid, about $180,000 in DAI was withdrawn via the GPv2Settlement smart contract.

As observed by market watchers, smart contract flaws remain a leading cause of losses. SlowMist reported that contract vulnerabilities accounted for just over 30% of crypto exploits in 2025. 

Image Source: SlowMist

Additionally, experts have pointed to advances in AI technology as another factor driving active exploitation. Artificial intelligence helps drive vulnerability discovery and active exploitation.

A single $1.5 billion hack of Bybit represented 44% of all losses in the past year. Meanwhile, North Korea-linked groups stole a record $2.02 billion.

Since the turn of the year, crypto-focused platforms have seen a surge in attacks. DeFi protocol Makina Finance lost about $4.13 million after hackers drained its DUSD/USDC pool on Curve. Shortly after, Layer-1 network Saga paused its SagaEVM chain following an exploit that moved nearly $7 million in assets to Ethereum.

Image by Clint Patterson from Unsplash

The post Matcha Meta Removes Direct Allowances After $16.8M SwapNet Exploit as Crypto Hacks Rise appeared first on Live Bitcoin News.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

DBS, Franklin Templeton, and Ripple partner to launch trading and lending solutions powered by tokenized money market funds and more

DBS, Franklin Templeton, and Ripple partner to launch trading and lending solutions powered by tokenized money market funds and more

PANews reported on September 18 that according to Cointelegraph, DBS Bank, Franklin Templeton and Ripple have partnered to launch trading and lending solutions supported by tokenized money market funds and RLUSD stablecoins.
Share
PANews2025/09/18 10:04
The Manchester City Donnarumma Doubters Have Missed Something Huge

The Manchester City Donnarumma Doubters Have Missed Something Huge

The post The Manchester City Donnarumma Doubters Have Missed Something Huge appeared on BitcoinEthereumNews.com. MANCHESTER, ENGLAND – SEPTEMBER 14: Gianluigi Donnarumma of Manchester City celebrates the second City goal during the Premier League match between Manchester City and Manchester United at Etihad Stadium on September 14, 2025 in Manchester, England. (Photo by Visionhaus/Getty Images) Visionhaus/Getty Images For a goalkeeper who’d played an influential role in the club’s first-ever Champions League triumph, it was strange to see Gianluigi Donnarumma so easily discarded. Soccer is a brutal game, but the sudden, drastic demotion of the Italian from Paris Saint-Germain’s lineup for the UEFA Super Cup clash against Tottenham Hotspur before he was sold to Manchester City was shockingly brutal. Coach Luis Enrique isn’t a man who minces his words, so he was blunt when asked about the decision on social media. “I am supported by my club and we are trying to find the best solution,” he told a news conference. “It is a difficult decision. I only have praise for Donnarumma. He is one of the very best goalkeepers out there and an even better man. “But we were looking for a different profile. It’s very difficult to take these types of decisions.” The last line has really stuck, especially since it became clear that Manchester City was Donnarumma’s next destination. Pep Guardiola, under whom the Italian will be playing this season, is known for brutally axing goalkeepers he didn’t feel fit his profile. The most notorious was Joe Hart, who was jettisoned many years ago for very similar reasons to Enrique. So how can it be that the Catalan coach is turning once again to a so-called old-school keeper? Well, the truth, as so often the case, is not quite that simple. As Italian soccer expert James Horncastle pointed out in The Athletic, Enrique’s focus on needing a “different profile” is overblown. Lucas Chevalier,…
Share
BitcoinEthereumNews2025/09/18 07:38
Marathon Digital BTC Transfers Highlight Miner Stress

Marathon Digital BTC Transfers Highlight Miner Stress

The post Marathon Digital BTC Transfers Highlight Miner Stress appeared on BitcoinEthereumNews.com. In a tense week for crypto markets, marathon digital has drawn
Share
BitcoinEthereumNews2026/02/06 15:16