The post How Opting Out of 0x One-Time Approvals Cost Users $16.8 Million appeared on BitcoinEthereumNews.com. On-chain decentralized exchange (DEX) aggregator,The post How Opting Out of 0x One-Time Approvals Cost Users $16.8 Million appeared on BitcoinEthereumNews.com. On-chain decentralized exchange (DEX) aggregator,

How Opting Out of 0x One-Time Approvals Cost Users $16.8 Million

On-chain decentralized exchange (DEX) aggregator, SwapNet, has suffered a major smart contract exploit that drained nearly $16.8 million in crypto assets.

The incident highlights persistent security risks tied to token approvals and third-party routing contracts in decentralized finance (DeFi).

Sponsored

Sponsored

On-Chain DEX Aggregator SwapNet Suffers $16.8 Million Exploit

PeckShield reported that the attacker targeted SwapNet-linked activity accessible through Matcha Meta, a meta DEX aggregator built by the 0x team.

On the Base network, the attacker swapped approximately $10.5 million in USDC for around 3,655 ETH before bridging the funds to Ethereum, a common tactic used to complicate tracking and recovery efforts.

Matcha Meta articulated that the exposure did not stem from its core infrastructure. Instead, the affected users were those who had opted out of 0x’s One-Time Approval system, a security feature designed to limit ongoing token permissions.

Users who disabled this option granted direct approvals to underlying aggregator contracts, including SwapNet’s router, which ultimately became the attack vector.

The platform confirmed it is coordinating with the SwapNet team, which has temporarily disabled the affected contracts while investigations continue.

Sponsored

Sponsored

As a precaution, Matcha Meta urged users to immediately revoke approvals to individual aggregators outside of 0x’s One-Time Approval framework.

The platform highlighted SwapNet’s router contract (0x616000e384Ef1C2B52f5f3A88D57a3B64F23757e) as the most urgent approval to revoke. Failure to do so could leave wallets exposed even after the exploit has been contained.

DeFi’s Security Trade-Offs: Convenience vs. Safety Amid Rising Smart Contract Exploits

The incident reflects a longstanding trade-off in DeFi between convenience and security. One-Time Approvals require users to approve each transaction individually, reducing persistent attack surfaces. However, it also adds friction for frequent traders.

Sponsored

Sponsored

Unlimited approvals, while faster, grant smart contracts enduring access to user funds. However, this arrangement becomes dangerous when those contracts are compromised.

SwapNet has not yet released a full technical post-mortem or indicated whether affected users will be compensated. This leaves open questions around accountability and recovery.

The lack of immediate clarity is likely to intensify scrutiny around approval practices and aggregator integrations across the DeFi ecosystem.

Another Ethereum Exploit Highlights Risks of Unverified, Closed-Source Contracts

The exploit comes amid a broader pattern of smart contract attacks and security incidents in the crypto market.

Sponsored

Sponsored

On the same day, security auditor Pashov flagged a separate Ethereum mainnet exploit involving roughly 37 WBTC, worth over $3.1 million.

This was linked to a closed-source, unverified contract deployed just 41 days earlier. The contract published only non-human-readable bytecode, preventing public review.

Together, the incidents highlight abundant fertile grounds for attackers in DeFi. These are:

  • Unverified code
  • Persistent approvals, and
  • Complex routing layers.

Despite years of audits and security improvements, DeFi continues to grapple with structural vulnerabilities. This places the burden on developers and users to balance usability with risk management.

Source: https://beincrypto.com/matcha-meta-swapnet-defi-exploit-loss/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Palmeiras Defeats River Plate In Epic Copa Libertadores Clash

Palmeiras Defeats River Plate In Epic Copa Libertadores Clash

The post Palmeiras Defeats River Plate In Epic Copa Libertadores Clash appeared on BitcoinEthereumNews.com. BUENOS AIRES, ARGENTINA – SEPTEMBER 17: Gustavo Gomez of Palmeiras scores the team’s first goal during the Copa CONMEBOL Libertadores 2025 Quarter-final first-leg match between River Plate and Palmeiras at Estadio Más Monumental Antonio Vespucio Liberti on September 17, 2025 in Buenos Aires, Argentina. (Photo by Marcelo Endelli/Getty Images) Getty Images Palmeiras defeated River Plate 2-1 in Buenos Aires on Wednesday night. The Brazilian side will host the second leg of the Copa Libertadores quarter-final in São Paulo next week. Clash Of South American Giants This is the biggest clash in the Copa Libertadores quarter-finals. Palmeiras has won three Copa Libertadores titles, including back-to-back trophies in 2020 and 2021, and River Plate has won the trophy four times, with the last victory coming against rivals Boca Juniors in the 2018 final. Palmeiras’ forward #09 Vitor Roque (L) and River Plate’s Chilean defender #17 Paulo Diaz (R) fight for the ball during the Copa Libertadores quarterfinal first leg football match between Argentina’s River Plate and Brazil’s Palmeiras at the MAS Monumental Stadium in Buenos Aires on September 17, 2025. (Photo by Juan MABROMATA / AFP) (Photo by JUAN MABROMATA/AFP via Getty Images) AFP via Getty Images Both teams have huge fan bases in their respective nations and both are currently competing for their domestic league as well as the continental title. River Plate hosted the first leg at the incredible Estadio Monumental, which hosted the 1978 World Cup final and is now the biggest stadium in South America. Fast Start Takes Palmeiras To Victory Gustavo Gómez opened the scoring for visitors Palmeiras after just six minutes of play. The team in green silenced a sea of red and white with a sucker-punch of a goal from a set-play. New signing from Fulham Andreas Pereira provided the assist and the defender headed…
Share
BitcoinEthereumNews2025/09/18 23:50
Tether Targeting 150 New Hires in Major Expansion Push; LiquidChain Presale Gains Momentum

Tether Targeting 150 New Hires in Major Expansion Push; LiquidChain Presale Gains Momentum

What to Know: Tether’s Strategic Pivot: The stablecoin issuer is doubling its workforce to ~300, ditching its ultra-lean structure to tackle compliance and AI/mining
Share
NewsBTC2026/02/09 16:02
Crypto Regulations in Australia 2025

Crypto Regulations in Australia 2025

The post Crypto Regulations in Australia 2025 appeared first on Coinpedia Fintech News Australia is one of the most favorable regions to operate crypto-related activities. It has enacted a series of rules to mandate strict compliance with consumer protection and investors’ rights. It is a crypto-friendly country with a supportive stance towards innovation in blockchain technology and cryptocurrency. As of 2025, Australia is enhancing transparency to prohibit misleading …
Share
CoinPedia2025/09/19 14:20