Tools Crypto Exploit Tracker exploit-0069
Exploit record
SwapNet
- Loss
- $17M
- Attack vector
- Other
- Chain
- Multichain
- Sector
- Exchange
What happened
On January 25, 2026, SwapNet was hit for about $17M after attackers abused an arbitrary-call style flaw to weaponise existing token approvals.
This one was grimly practical. Users had already approved router-style contracts, and the vulnerable logic let attackers steer those approvals into unauthorised transferFrom calls. In other words, the protocol became a machine for cashing in permissions users had granted earlier under normal conditions. This was linked to the same broader approval-abuse wave that also hit Aperture.
On-chain references
- Router Contract
0x616000e384Ef1C2B52f5f3A88D57a3B64F23757e
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026