YFarmX

Tools Crypto Exploit Tracker exploit-0069

Exploit record

SwapNet

Loss
$17M
Attack vector
Other
Chain
Multichain
Sector
Exchange

What happened

On January 25, 2026, SwapNet was hit for about $17M after attackers abused an arbitrary-call style flaw to weaponise existing token approvals.

This one was grimly practical. Users had already approved router-style contracts, and the vulnerable logic let attackers steer those approvals into unauthorised transferFrom calls. In other words, the protocol became a machine for cashing in permissions users had granted earlier under normal conditions. This was linked to the same broader approval-abuse wave that also hit Aperture.

On-chain references

  • Router Contract0x616000e384Ef1C2B52f5f3A88D57a3B64F23757e

One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026