ChainBleedv0.1 · open intel
← back to feed·ETHEXTERNAL-CALL2026-01-26 · 4mo ago
Incident · SLOWMIST

SwapNet

Contract Vulnerability
Estimated loss
$16.80M
VERDICT —UNRATED
Verdict pending. Auto-ingested incidents are reviewed before a public verdict is rendered.
▰ METHOD
EXTERNAL CALL
EXTERNAL-CALLBYTECODE CATCHABLEAI SCANNABLE
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

Forensic narrative

According to PeckShield, Matcha Meta reported that SwapNet suffered a security breach, with losses reaching $16.8 million. The attacker swapped approximately 10.5 million USDC for around 3,655 ETH on Base, and has begun bridging the funds to Ethereum. BlockSec’s analysis indicates that the affected contract is not open-sourced and appears to contain an arbitrary call vulnerability. The attacker abused existing token approval mechanisms to execute transferFrom operations and steal assets. The cumulative losses are estimated at $13.37 million on Base, $3.53 million on Ethereum, $125,000 on Arbitrum, and $15,000 on BSC. Attack method (per SlowMist): Contract Vulnerability. Reported loss: $ 16,800,000.

Primary source
https://x.com/PeckShieldAlert/status/2015608261119217671
Sourced from
slowmist
Technical record
chain
ethereum
protocol
SwapNet
bug_class
external-call
date_occurred
2026-01-26
loss_usd
$16,800,000
source_id
sm:swapnet::2026-01-26
Related — same bug class· external-call
2026-04-27
1mo ago
ZetaChain
Contract Vulnerability
external-call
$334.0K
UNRATED
2026-01-06
5mo ago
ETH
Fusion by IPOR
Contract Vulnerability
external-call
$336.0K
UNRATED
2025-09-27
8mo ago
Hyperdrive
Contract Vulnerability
external-call
$782.0K
UNRATED
2024-08-28
1y ago
Aave
Contract Vulnerability
external-call
$56.0K
UNRATED
2024-07-23
1y ago
Spectra
Contract Vulnerability
external-call
$550.0K
UNRATED
2024-04-23
2y ago
Magpie Protocol
Contract Vulnerability
external-call
$129.0K
UNRATED
ChainBleed — live web3 threat intelligence