Decentralized exchange aggregator Matcha Meta has disclosed a security incident linked to one of its liquidity providers, SwapNet, after a smart-contract vulnerability was exploited to drain up to $16.8 million in crypto assets on the Base blockchain.
Matcha Meta said on Sunday that the breach did not originate from its own infrastructure but from SwapNet’s router contract. The platform warned users who had previously approved tokens for that contract to revoke all permissions immediately, citing the risk of further losses if approvals remained active.
Earlier coverage: New SEC filings sharpen debate over self-custody and DeFi rules as market structure talks intensify
Loss estimates vary, but scope remains significant
Blockchain security firms offered differing estimates of the losses. CertiK said approximately $13.3 million was stolen, while PeckShield reported losses of at least $16.8 million.
PeckShield said the attacker drained funds on Base, swapping roughly $10.5 million in USDC for about 3,655 ETH before beginning to bridge the assets to Ethereum. The firm urged affected users to revoke all approvals tied to SwapNet-related contracts.
CertiK attributed the exploit to an “arbitrary call” vulnerability in the SwapNet contract, which allowed the attacker to move funds that had previously been approved by users.
Matcha Meta said the exposure was limited to SwapNet integrations and reiterated that its own contracts were not compromised. Cointelegraph reached out to Matcha Meta for details on the root cause, potential user reimbursements and future security measures, but had not received a response at the time of publication.
Another reminder of smart-contract risk
The incident follows a string of high-profile smart-contract failures in recent weeks. Earlier this month, the offline computation protocol Truebit suffered a separate exploit that resulted in roughly $26 million in losses and a near-total collapse in the value of its native token.
Security researchers continue to warn that smart contracts remain the primary attack surface in crypto. According to a year-end report from SlowMist, smart-contract vulnerabilities accounted for 30.5% of all crypto exploits in
2025, across 56 recorded incidents. Account takeovers, including compromised social media credentials, ranked second at 24%.
AI changes the pace of exploit discovery
Researchers also point to artificial intelligence as a growing factor in how vulnerabilities are found. In December, commercially available generative AI tools identified an estimated $4.6 million worth of exploitable flaws in existing smart contracts, highlighting how attackers — and defenders — are gaining new capabilities.
As the Matcha Meta incident shows, even indirect exposure through third-party integrations can carry material risk, reinforcing calls for tighter approval management and more rigorous smart-contract auditing across DeFi.
