Matcha Meta disclosed a security issue tied to its SwapNet integration after suspicious activity on Base led to a rapid outflow of funds. Blockchain security firms tracked stablecoins moving out of the affected contracts within a short window. PeckShield estimated that about $16.8 million was drained, including roughly $10.5 million in USDC swapped for nearly 3,655 ETH. The attacker then started moving the assets toward Ethereum through bridging routes.
Loss estimates were not identical across firms. CertiK placed the figure lower, saying around $13.3 million in USDC on Base was affected. It attributed the exploit to an arbitrary call vulnerability in the SwapNet contract, a flaw that let the attacker transfer funds that users had previously approved. That detail shifted attention from the headline number to the structure of DeFi permissions and how long-lived approvals can become an attack path.
Exposure was limited to wallets using direct approvals
Matcha Meta did not say that every affected asset belonged to users, but it did narrow the exposed group. According to the project, only users who had turned off One-Time Approval and granted direct allowances to individual aggregator contracts were at risk. Wallets that relied on one-time approvals were not affected. A small setting made a large difference. The incident showed that users interacting with the same trading flow can face very different outcomes depending on how permissions are configured.
The team also said it reviewed the incident with the 0x protocol developers and later stated on X that the exploit did not involve 0x’s AllowanceHolder or Settler contracts. That clarification confined the issue to the SwapNet integration rather than the broader 0x contract stack.
Matcha Meta removes the direct allowance option
The breach has reopened scrutiny of approval models across DeFi applications. Matcha Meta said users who enable direct allowances take on the risks tied to each aggregator contract they approve. The platform has since removed that option, meaning users can no longer set those direct approvals through the product. It is a product-level change, but the tradeoff is clear: convenience-heavy settings can increase the damage when a contract fails.
The team also pointed to the defensive value of one-time approval models. Because permission is limited to a single transaction, the amount exposed during an exploit can be materially reduced instead of leaving a standing token allowance open for abuse. That design choice has become central to the discussion after the incident.
Hack losses stay elevated across the crypto sector
The event landed at a time when security pressure across the crypto market remains high. Chainalysis reported that cryptocurrency theft in 2025 exceeded $3.41 billion, up from $3.38 billion previously. One hack linked to Bybit alone reached $1.5 billion, accounting for 44% of total losses. Actors linked to North Korea were responsible for the largest share, with stolen assets totaling $2.02 billion.
As of publication, Matcha Meta had not issued further updates. The confirmed facts remain centered on the loss estimates, the exploit path, and the subset of users exposed by their approval settings.

