News View Non-AMP

Matcha Meta SwapNet Security Breach Drains $16.8 Million

Published by
Rizwan Ansari

Blockchain security platform PeckShieldAlert has flagged a major security breach involving SwapNet, affecting users who interact through Matcha Meta. Meanwhile, attackers exploited token approvals to drain $16.8 millions in crypto. 

PeckShieldAlert data reveal how disabled safety settings exposed users to unexpected losses.

How the SwapNet Hack Happened

According to PeckShieldAlert, the hack did not happen due to a flaw in Matcha Meta itself, but because of how some users managed token approvals.

Matcha Meta offers a One-Time Approval feature, which limits token access to a single transaction. However, users who turned off this feature and instead gave direct, long-term allowances to individual aggregator contracts exposed themselves to higher risk.

Attackers took advantage of these permanent approvals linked to SwapNet. Once access was granted, the hacker could move funds freely without needing further user confirmation. This is how wallets were drained without users actively signing new transactions.

On-Chain Activity Confirms Fund Movement

Blockchain data shows that the attacker focused heavily on the Base network. Around $10.5 million worth of USDC was swapped for roughly 3,655 ETH. Shortly after, the attacker began bridging the funds from Base to Ethereum, a common tactic used to reduce traceability.

Additional transaction records reveal large USDC transfers exceeding $13 million, along with Uniswap V3 liquidity interactions. Altogether, PeckShieldAlert estimates that approximately $16.8 million in crypto was stolen.

Matcha Meta and SwapNet’s Response

Matcha Meta quickly acknowledged the incident and confirmed it is working closely with the SwapNet team. As an immediate step, SwapNet temporarily disabled its contracts to prevent further exploitation.

To protect users going forward, Matcha Meta removed the option to set direct aggregator allowances, ensuring this type of exposure cannot happen again. The platform also urged users to revoke all existing approvals outside of 0x’s One-Time Approval contracts, especially those linked to SwapNet’s router contract.

Investigations are ongoing, and both teams have promised continuous updates as they work to understand the full impact and monitor the stolen funds.

Rizwan Ansari

Rizwan is an experienced Crypto journalist with almost half a decade of experience covering everything related to the growing crypto industry — from price analysis to blockchain disruption. During this period, he’s authored more than 3,000 news articles for Coinpedia News.

Recent Posts

Aptos vs. Sui vs. Filecoin—Which Altcoin Has Real Upside in Q2 2026?

Aptos, Sui & Filecoin: all the prices are trading within the lower bands and are…

April 1, 2026

Bitcoin Stuck Between $60K and $70K—Why BTC Price Isn’t Ready to Break Out

The Bitcoin price continues to trade within a defined $60,000–$70,000 range, but this lack of…

April 1, 2026

Pepeto Could Deliver What ADA Protocol 11 Will Take Years to Match – Here Is How

Cardano just confirmed its Protocol 11 hard fork for April 2026, a governance overhaul that…

April 1, 2026

MORPHO Price Jumps 15% on pyUSD Vault Launch, But Resistance Looms

The MORPHO price today popped 15% intraday, and yeah it didn’t come out of nowhere.…

April 1, 2026

ALGO Price Jumps 30% Intraday, But Is It Just Noise?

The ALGO price just pulled off a flashy 30% intraday move but zoom out for…

April 1, 2026

Uniswap (UNI) Price Prediction 2026, 2027 – 2030: Will Uniswap Reach $50?

Story Highlights The live price of the UniSwap crypto token is . Price predictions for…

April 1, 2026