Matcha Meta SwapNet Security Breach Drains $16.8 Million

A vulnerability in SwapNet’s router contract on Base was exploited, allowing an attacker to transfer approved funds and drain an estimated $13.3M–$16.8M. The attacker swapped ~10.5M USDC for ~3,655 ETH and began bridging proceeds to Ethereum. CertiK identified an arbitrary call that enabled the transfers; Matcha Meta said the issue was in SwapNet (not its own infrastructure) and warned users to revoke one-time token approvals. SlowMist notes smart contract vulnerabilities remain a major source of 2025 crypto incidents.
AI Analysis
An arbitrary call bug in SwapNet’s router on Base was exploited to transfer approved funds and steal an estimated $13.3M–$16.8M; the attacker swapped ~10.5M USDC for ~3,655 ETH and started bridging to Ethereum. Matcha Meta confirmed the issue was with SwapNet and advised revoking approvals; SlowMist reports smart contract vulnerabilities account for many 2025 incidents.