SwapNet Hack
Check if your address is affected.
Matcha Meta is a trading app that compares prices across several DEX aggregators, one of which was SwapNet. By default, Matcha routes approvals through a contract from 0x that only lets an aggregator use them for a single trade. Users could turn this setting off and give SwapNet's contracts a direct, often unlimited approval instead. On 25 January 2026, an attacker abused a flaw in SwapNet's contracts that let anyone make them move tokens that had been approved to them.
The first theft happened on Base, and the attacker went on to drain wallets on other chains too, taking about $13.4M in total. SwapNet paused its contracts on Base about 45 minutes after the first attack and on the other chains shortly after. The attacker swapped the stolen tokens and bridged the proceeds to Ethereum. Matcha removed SwapNet, took away the option to turn off one-time approvals and said it was working with security firms to trace the funds. Some early reports put losses at $16.8M, but that figure included an unrelated incident at Aperture Finance.
Matcha said its own contracts and those of 0x were not affected, and users who kept the default one-time approval were never at risk. SwapNet paused its contracts rather than fixing them, and it can switch them back on at any time. Anyone who approved SwapNet's contracts directly, on any chain, should still revoke those approvals. This includes approvals for an exact amount that were never used, since those can be abused too.
Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.
Next time, revoke it automatically
Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.
See how Auto-Revoking works →