The post How Opting Out of 0x One-Time Approvals Cost Users $16.8 Million appeared on BitcoinEthereumNews.com. On-chain decentralized exchange (DEX) aggregator,The post How Opting Out of 0x One-Time Approvals Cost Users $16.8 Million appeared on BitcoinEthereumNews.com. On-chain decentralized exchange (DEX) aggregator,

How Opting Out of 0x One-Time Approvals Cost Users $16.8 Million

On-chain decentralized exchange (DEX) aggregator, SwapNet, has suffered a major smart contract exploit that drained nearly $16.8 million in crypto assets.

The incident highlights persistent security risks tied to token approvals and third-party routing contracts in decentralized finance (DeFi).

Sponsored

Sponsored

On-Chain DEX Aggregator SwapNet Suffers $16.8 Million Exploit

PeckShield reported that the attacker targeted SwapNet-linked activity accessible through Matcha Meta, a meta DEX aggregator built by the 0x team.

On the Base network, the attacker swapped approximately $10.5 million in USDC for around 3,655 ETH before bridging the funds to Ethereum, a common tactic used to complicate tracking and recovery efforts.

Matcha Meta articulated that the exposure did not stem from its core infrastructure. Instead, the affected users were those who had opted out of 0x’s One-Time Approval system, a security feature designed to limit ongoing token permissions.

Users who disabled this option granted direct approvals to underlying aggregator contracts, including SwapNet’s router, which ultimately became the attack vector.

The platform confirmed it is coordinating with the SwapNet team, which has temporarily disabled the affected contracts while investigations continue.

Sponsored

Sponsored

As a precaution, Matcha Meta urged users to immediately revoke approvals to individual aggregators outside of 0x’s One-Time Approval framework.

The platform highlighted SwapNet’s router contract (0x616000e384Ef1C2B52f5f3A88D57a3B64F23757e) as the most urgent approval to revoke. Failure to do so could leave wallets exposed even after the exploit has been contained.

DeFi’s Security Trade-Offs: Convenience vs. Safety Amid Rising Smart Contract Exploits

The incident reflects a longstanding trade-off in DeFi between convenience and security. One-Time Approvals require users to approve each transaction individually, reducing persistent attack surfaces. However, it also adds friction for frequent traders.

Sponsored

Sponsored

Unlimited approvals, while faster, grant smart contracts enduring access to user funds. However, this arrangement becomes dangerous when those contracts are compromised.

SwapNet has not yet released a full technical post-mortem or indicated whether affected users will be compensated. This leaves open questions around accountability and recovery.

The lack of immediate clarity is likely to intensify scrutiny around approval practices and aggregator integrations across the DeFi ecosystem.

Another Ethereum Exploit Highlights Risks of Unverified, Closed-Source Contracts

The exploit comes amid a broader pattern of smart contract attacks and security incidents in the crypto market.

Sponsored

Sponsored

On the same day, security auditor Pashov flagged a separate Ethereum mainnet exploit involving roughly 37 WBTC, worth over $3.1 million.

This was linked to a closed-source, unverified contract deployed just 41 days earlier. The contract published only non-human-readable bytecode, preventing public review.

Together, the incidents highlight abundant fertile grounds for attackers in DeFi. These are:

  • Unverified code
  • Persistent approvals, and
  • Complex routing layers.

Despite years of audits and security improvements, DeFi continues to grapple with structural vulnerabilities. This places the burden on developers and users to balance usability with risk management.

Source: https://beincrypto.com/matcha-meta-swapnet-defi-exploit-loss/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

What Does Market Cap Really Mean in Crypto — and Why Australians Care

What Does Market Cap Really Mean in Crypto — and Why Australians Care

Introduction: What Does Market Cap Mean in Cryptocurrency Ridgewell Tradebit is an automated cryptocurrency trading platform that helps users better understand
Share
Techbullion2026/02/09 23:34
The Manchester City Donnarumma Doubters Have Missed Something Huge

The Manchester City Donnarumma Doubters Have Missed Something Huge

The post The Manchester City Donnarumma Doubters Have Missed Something Huge appeared on BitcoinEthereumNews.com. MANCHESTER, ENGLAND – SEPTEMBER 14: Gianluigi Donnarumma of Manchester City celebrates the second City goal during the Premier League match between Manchester City and Manchester United at Etihad Stadium on September 14, 2025 in Manchester, England. (Photo by Visionhaus/Getty Images) Visionhaus/Getty Images For a goalkeeper who’d played an influential role in the club’s first-ever Champions League triumph, it was strange to see Gianluigi Donnarumma so easily discarded. Soccer is a brutal game, but the sudden, drastic demotion of the Italian from Paris Saint-Germain’s lineup for the UEFA Super Cup clash against Tottenham Hotspur before he was sold to Manchester City was shockingly brutal. Coach Luis Enrique isn’t a man who minces his words, so he was blunt when asked about the decision on social media. “I am supported by my club and we are trying to find the best solution,” he told a news conference. “It is a difficult decision. I only have praise for Donnarumma. He is one of the very best goalkeepers out there and an even better man. “But we were looking for a different profile. It’s very difficult to take these types of decisions.” The last line has really stuck, especially since it became clear that Manchester City was Donnarumma’s next destination. Pep Guardiola, under whom the Italian will be playing this season, is known for brutally axing goalkeepers he didn’t feel fit his profile. The most notorious was Joe Hart, who was jettisoned many years ago for very similar reasons to Enrique. So how can it be that the Catalan coach is turning once again to a so-called old-school keeper? Well, the truth, as so often the case, is not quite that simple. As Italian soccer expert James Horncastle pointed out in The Athletic, Enrique’s focus on needing a “different profile” is overblown. Lucas Chevalier,…
Share
BitcoinEthereumNews2025/09/18 07:38
MicroStrategy Bought Another 1.142 BTC: Total 714K BTC

MicroStrategy Bought Another 1.142 BTC: Total 714K BTC

The post MicroStrategy Bought Another 1.142 BTC: Total 714K BTC appeared on BitcoinEthereumNews.com. MicroStrategy Continues BTC Purchases MicroStrategy, the world
Share
BitcoinEthereumNews2026/02/09 23:06