• bitcoinBitcoin (BTC) $ 76,326.00
  • ethereumEthereum (ETH) $ 2,287.81
  • tetherTether (USDT) $ 0.999843
  • xrpXRP (XRP) $ 1.38
  • bnbBNB (BNB) $ 623.70
  • usd-coinUSDC (USDC) $ 0.999864
  • solanaSolana (SOL) $ 83.78
  • tronTRON (TRX) $ 0.323139
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • dogecoinDogecoin (DOGE) $ 0.099338
  • whitebitWhiteBIT Coin (WBT) $ 54.04
  • usdsUSDS (USDS) $ 0.999696
  • hyperliquidHyperliquid (HYPE) $ 40.08
  • leo-tokenLEO Token (LEO) $ 10.36
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • cardanoCardano (ADA) $ 0.246791
  • bitcoin-cashBitcoin Cash (BCH) $ 451.40
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • moneroMonero (XMR) $ 378.40
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • chainlinkChainlink (LINK) $ 9.23
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • canton-networkCanton (CC) $ 0.148692
  • zcashZcash (ZEC) $ 334.84
  • stellarStellar (XLM) $ 0.162074
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • daiDai (DAI) $ 0.999793
  • susdssUSDS (SUSDS) $ 1.08
  • memecoreMemeCore (M) $ 3.36
  • litecoinLitecoin (LTC) $ 55.49
  • avalanche-2Avalanche (AVAX) $ 9.16
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • hedera-hashgraphHedera (HBAR) $ 0.088898
  • ethena-usdeEthena USDe (USDE) $ 0.999025
  • suiSui (SUI) $ 0.923524
  • wethWETH (WETH) $ 2,268.37
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • rainRain (RAIN) $ 0.007452
  • paypal-usdPayPal USD (PYUSD) $ 0.999714
  • usdt0USDT0 (USDT0) $ 0.998824
  • the-open-networkToncoin (TON) $ 1.30
  • crypto-com-chainCronos (CRO) $ 0.069120
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,585.49
  • bittensorBittensor (TAO) $ 257.35
  • global-dollarGlobal Dollar (USDG) $ 0.999798
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.073751
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • pax-goldPAX Gold (PAXG) $ 4,583.96
  • mantleMantle (MNT) $ 0.629624
  • polkadotPolkadot (DOT) $ 1.23
  • uniswapUniswap (UNI) $ 3.25
  • pi-networkPi Network (PI) $ 0.194099
  • skySky (SKY) $ 0.086132
  • falcon-financeFalcon USD (USDF) $ 0.997530
  • nearNEAR Protocol (NEAR) $ 1.35
  • okbOKB (OKB) $ 82.73
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • aster-2Aster (ASTER) $ 0.651827
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • pepePepe (PEPE) $ 0.000004
  • ripple-usdRipple USD (RLUSD) $ 0.999982
  • aaveAave (AAVE) $ 96.57
  • usddUSDD (USDD) $ 0.999818
  • bitget-tokenBitget Token (BGB) $ 1.96
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.12
  • internet-computerInternet Computer (ICP) $ 2.39
  • bfusdBFUSD (BFUSD) $ 0.999296
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • ethereum-classicEthereum Classic (ETC) $ 8.39
  • ondo-financeOndo (ONDO) $ 0.263840
  • morphoMorpho (MORPHO) $ 1.96
  • kucoin-sharesKuCoin (KCS) $ 8.43
  • gatechain-tokenGate (GT) $ 7.30
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • pump-funPump.fun (PUMP) $ 0.001880
  • united-stablesUnited Stables (U) $ 1.00
  • quant-networkQuant (QNT) $ 69.07
  • algorandAlgorand (ALGO) $ 0.112236
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • cosmosCosmos Hub (ATOM) $ 1.96
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.091987
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • blockchain-capitalBlockchain Capital (BCAP) $ 105.75
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.06
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • ethenaEthena (ENA) $ 0.105863
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • render-tokenRender (RENDER) $ 1.74
  • kaspaKaspa (KAS) $ 0.032679
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • nexoNEXO (NEXO) $ 0.890245
  • worldcoin-wldWorldcoin (WLD) $ 0.250894
  • wbnbWrapped BNB (WBNB) $ 759.61
  • stable-2​​Stable (STABLE) $ 0.036423
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • aptosAptos (APT) $ 0.962498
  • arbitrumArbitrum (ARB) $ 0.124428
  • justJUST (JST) $ 0.084603
  • hash-2Provenance Blockchain (HASH) $ 0.012556
  • filecoinFilecoin (FIL) $ 0.917582
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • flare-networksFlare (FLR) $ 0.007590
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.010218
  • jupiter-exchange-solanaJupiter (JUP) $ 0.189085
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • beldexBeldex (BDX) $ 0.079884
  • vechainVeChain (VET) $ 0.007148
  • dexeDeXe (DEXE) $ 13.15
  • ousgOUSG (OUSG) $ 115.07
  • xdce-crowd-saleXDC Network (XDC) $ 0.029718
  • usdtbUSDtb (USDTB) $ 1.00
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • ghoGHO (GHO) $ 0.999199
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • official-trumpOfficial Trump (TRUMP) $ 2.50
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • midnight-3Midnight (NIGHT) $ 0.034362
  • usual-usdUsual USD (USD0) $ 0.998199
  • bonkBonk (BONK) $ 0.000006
  • clbtcclBTC (CLBTC) $ 76,920.00
  • yldsYLDS (YLDS) $ 0.999850
  • true-usdTrueUSD (TUSD) $ 1.00
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.50
  • a7a5A7A5 (A7A5) $ 0.012495
  • siren-2Siren (SIREN) $ 0.672280
  • chilizChiliz (CHZ) $ 0.045483
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.690717
  • edgexedgeX (EDGE) $ 1.30
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.196164
  • tbtctBTC (TBTC) $ 70,942.00
  • dashDash (DASH) $ 34.82
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • euro-coinEURC (EURC) $ 1.17
  • aerodrome-financeAerodrome Finance (AERO) $ 0.457887
  • tezosTezos (XTZ) $ 0.384469
  • adi-tokenADI (ADI) $ 3.98
  • blockstackStacks (STX) $ 0.224381
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998309
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • venice-tokenVenice Token (VVV) $ 8.82
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • manadiaManadia (UMXM) $ 1.93
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • sei-networkSei (SEI) $ 0.059230
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.383023
  • cocaCOCA (COCA) $ 1.30
  • usxUSX (USX) $ 0.999473
  • layerzeroLayerZero (ZRO) $ 1.44
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000066
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • injective-protocolInjective (INJ) $ 3.57
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • ether-fiEther.fi (ETHFI) $ 0.425638
  • sun-tokenSun Token (SUN) $ 0.018326
  • kinesis-goldKinesis Gold (KAU) $ 147.23
  • monadMonad (MON) $ 0.029104
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • curve-dao-tokenCurve DAO (CRV) $ 0.227322
  • spx6900SPX6900 (SPX) $ 0.364232
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • zebec-networkZebec Network (ZBCN) $ 0.003381
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • celestiaCelestia (TIA) $ 0.362749
  • humanityHumanity (H) $ 0.180237
  • gnosisGnosis (GNO) $ 125.00
  • decredDecred (DCR) $ 18.97
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • lido-daoLido DAO (LDO) $ 0.388164
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • hastra-primePRIME (PRIME) $ 1.03
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • bittorrentBitTorrent (BTT) $ 0.00000032
  • bitcoin-svBitcoin SV (BSV) $ 15.45
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • flokiFLOKI (FLOKI) $ 0.000032
  • apenftAINFT (NFT) $ 0.00000031
  • conflux-tokenConflux (CFX) $ 0.058838
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • olympusOlympus (OHM) $ 19.14
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • doublezeroDoubleZero (2Z) $ 0.085664
  • jasmycoinJasmyCoin (JASMY) $ 0.005905
  • usdaiUSDai (USDAI) $ 0.999818
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • ape-and-pepeApe and Pepe (APEPE) $ 0.000001
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06
  • syrupMaple Finance (SYRUP) $ 0.244146

SwapNet loses $13.4 million after input validation flaw enables asset drain

0 39

SwapNet loses $13.4 million after input validation flaw enables asset drain

Blockchain security firm BlockSec has released a technical analysis of the attacks that hit two decentralized finance protocols, resulting in losses of more than $17 million.

SwapNet, a DEX aggregator, suffered losses of over $13.4 million across Ethereum, Arbitrum, Base, and Binance Smart Chain, while Aperture Finance, which manages concentrated liquidity positions, lost an estimated $3.67 million in a concurrent but unrelated incident.

“The victim contracts expose an arbitrary-call capability due to insufficient input validation, allowing attackers to abuse existing token approvals and invoke transferFrom to drain assets,” BlockSec stated in a summary of its analysis on X.

The security firm stated, “These incidents serve as a reminder that flexibility in contract design must be carefully balanced with strict call constraints, especially in closed-source systems where external review is limited.”

What was behind SwapNet’s vulnerability?

In the SwapNet case, the vulnerability came from the function 0x87395540(), which lacked proper validation on critical inputs.

By replacing expected router or pool addresses with token addresses such as USDC, attackers tricked the victim contract into treating tokens as valid execution targets.

This led to low-level calls being executed with attacker-controlled calldata, enabling the victim contract to perform calls that allowed the attacker to siphon all approved assets.

The vulnerability impacted users of Matcha Meta, a DeFi exchange meta-aggregator, who had disabled the platform’s “One-Time Approval” setting and granted infinite approval directly to SwapNet contracts.

The largest single loss came from one user who lost around $13.34 million. In total, 20 users were affected. The attack began on Base at block 41289829, prompting SwapNet to pause contracts on Base 45 minutes after the initial exploit was detected. It also paused contracts on other chains shortly after; however, during that window, an additional 13 users were affected across three chains.

Similar weakness hit Aperture Finance

Aperture Finance, which manages Uniswap V3 liquidity positions on behalf of users, fell victim to the same class of vulnerability in its function 0x67b34120().

When this function was invoked, an internal function 0x1d33() executed low-level calls using calldata supplied by users without enforcing strict constraints on the call target or function selector.

This enabled attackers to construct malicious calldata that siphoned ERC-20 tokens and also approved Uniswap V3 position NFTs.

Users who had authorized approvals for “Instant Liquidity Management” features were the ones at risk from this attack.

In one representative attack on Ethereum, the attacker created a contract that invoked the vulnerable function with just 100 wei of ETH. After wrapping the native tokens into WETH, the malicious call to WBTC.transferFrom() was executed, allowing the attacker to drain approved tokens while passing a balance check by specifying their own swap output value.

What changes are the affected platforms making?

The incidents have prompted both protocols to reassess their approach to security. First, both protocols asked their users to revoke approvals using tools such as Revoke.cash.

Matcha Meta stated that it has disabled the toggle that allows users to turn off One-Time Approval. It has also removed SwapNet from its platform until further notice, while stating that “Erring on the side of customizability over security is not a posture we will allow moving forward.”

Aperture Finance stated that it has disabled all affected web application functionalities. On its recovery efforts, it stated, “We are working closely with top-tier forensic security firms and are coordinating with law enforcement to trace funds,” while adding that it is also establishing channels to negotiate the return of funds as well.

Source

Leave A Reply

Your email address will not be published.