Matcha Meta users hit in $13.4 million SwapNet contract exploit

Quick Take

  • A $13.4 million smart contract exploit in SwapNet affected 20 Matcha Meta users who had previously approved SwapNet contracts after disabling the platform’s default One-Time Approval setting.
  • Matcha Meta and 0x said their own smart contracts were not compromised, and users who retained One-Time Approval were not exposed.
Advertisement

Decentralized exchange aggregator Matcha Meta said a subset of its users were impacted by a smart contract exploit affecting SwapNet, after attackers drained approximately $13.4 million in crypto from contracts that had been directly approved by users.

In a post-mortem published Monday, Matcha Meta confirmed the incident stemmed from vulnerabilities in SwapNet’s smart contracts. The confirmed losses affected 20 users who had manually disabled Matcha Meta’s default One-Time Approval feature and instead granted direct token allowances to SwapNet contracts.

Matcha Meta said the vast majority of its users were unaffected, adding that users who kept the default One-Time Approval setting enabled — which routes transactions through developer 0x’s AllowanceHolder contract — were not exposed.

Earlier estimates of the exploit’s scope varied among blockchain security firms. CertiK initially estimated losses of around $13.3 million and said the incident likely stemmed from an arbitrary call vulnerability in the SwapNet contract that allowed unauthorized transfers of approved funds.

PeckShield estimated losses of up to $16.8 million based on preliminary onchain activity. However, Matcha Meta said that figure overstated the damage because it included a separate and unrelated $3.4 million incident involving Aperture Finance.

According to the post-mortem, the confirmed losses from the SwapNet exploit totaled $13.43 million, including one user who lost approximately $13.34 million. Onchain data showed the attacker swapping assets on Base before bridging funds to Ethereum ETH.

SwapNet paused its contracts on Base roughly 45 minutes after the initial exploit, with contracts on other chains disabled shortly thereafter. Matcha Meta said it has since removed SwapNet as an available aggregator, disabled the ability for users to turn off One-Time Approval, and implemented additional safeguards to prevent similar exposure going forward.

After reviewing the incident with the 0x protocol team, Matcha Meta confirmed the exploit was not related to 0x’s AllowanceHolder or Settler contracts, which remain secure.

Matcha Meta said it is working with security firms and industry partners to collect data and trace the stolen funds.

The incident comes as hacking activity continues to weigh on the crypto industry. Cryptocurrency theft totaled more than $3.41 billion in 2025, up from $3.38 billion the prior year, according to Chainalysis. A single $1.5 billion hack of Bybit accounted for 44% of the annual total losses, while North Korea-linked actors were the most prolific threat group, stealing a record $2.02 billion over the year.

Updated with verified figures and additional post-mortem details from Matcha.


Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.

© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.