T
iTokenly

Matcha Meta / SwapNet router exploit hack — January 2026

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJanuary 25, 2026
Target typeDecentralised exchange
Loss$13,300,000Published estimates range $13,300,000 to $13,430,000Price at time of incident
MethodContract logic errorAn arbitrary external call in SwapNet's router contract let an attacker supply calldata that the contract executed on its own behalf, using it to transfer any tokens for which a user had granted the router a standing (unlimited) ERC-20 allowance. CertiK described it as 'arbitrary call in [the] 0xswapnet contract that let attacker to transfer funds approved to it'. Only users who had manually disabled Matcha Meta's default One-Time Approval setting were exposed.
ChainsBase, Ethereum
OutcomeUnresolved

What happened

On 25 January 2026 an attacker exploited a flaw in a router contract operated by SwapNet, one of the exchange aggregators wired into Matcha Meta, the meta-aggregator built by 0x. DL News reported the attack at approximately 5:10pm London time, with the incident public by 9:47pm the same day. The contract contained an arbitrary external call: an attacker could supply calldata that the contract then executed on its own behalf, and use it to move any tokens for which a user had granted SwapNet a standing allowance.

Matcha Meta routes trades through a One-Time Approval system by default, which limits each approval to a single swap and routes through 0x's AllowanceHolder contract. Only users who had manually turned that setting off, granting SwapNet's router an open-ended allowance, were exposed. 0x said the flaw was not in its own AllowanceHolder or Settler contracts. Matcha Meta removed SwapNet as an available aggregator, disabled the ability to opt out of One-Time Approvals, and told users to revoke approvals to SwapNet's router.

The size of the loss was disputed. PeckShield's initial alert put it at $16.8 million, a figure later shown to include $3.4 million from an unrelated Aperture Finance incident. CertiK estimated about $13.3 million, and Matcha Meta's own post-mortem figure was $13.43 million; DL News, reporting on the day, gave an early rounded $13.5 million.

The Block reported that 20 Matcha Meta users were affected, all of them people who had manually disabled One-Time Approval, and that a single account accounted for almost the entire sum, losing approximately $13.34 million. The funds were taken mostly in USDC on Base, swapped into ether and bridged to Ethereum. No recovery or reimbursement has been reported and the attacker has not been identified.

Sources

  1. The BlockSecondary · retrieved 2026-08-01
  2. CointelegraphSecondary · retrieved 2026-08-01
  3. DL NewsSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Matcha Meta / SwapNet router exploit hack — January 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/matcha-meta-swapnet
https://itokenly.com/hacks/matcha-meta-swapnet

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.