Skip to content
btc Bitcoin $77,972 -1.00% eth Ethereum $2,298 -2.90% usdt Tether $1 -0.02% bnb BNB $775 -0.19% xrp XRP $2 -1.45% usdc USDC $1 -0.01% sol Solana $102 -2.27% trx TRON $0 -0.39% steth Lido Staked Ether $2,297 -2.84% doge Dogecoin $0 0.40%

Coinbase loses $300,000 after wallet misstep enables MEV bot drain

Coinbase Loses $300K After Wallet Misstep Enables MEV Bot Drain
SHARE THIS ARTICLE

Coinbase recently suffered an unexpected loss of ~$300,000 because of a misconfiguration involving the 0x protocol’s swapper contract. According to an X post by security researcher “deeberiroz” of Venn Network, the incident occurred when Coinbase mistakenly granted token spending permissions to the swapper. This ideally is a contract intended solely for facilitating trades, and does not hold allowances. 

Coinbase loses $300,000 after wallet misstep enables MEV bot drain

MEV (Maximal Extractable Value) bots were quick to detect this error and immediately drained the wallet before permissions could be revoked. Coinbase’s Chief Security Officer, Philip Martin, confirmed this was an isolated issue tied to a corporate decentralized trading wallet. He assured that no customer funds were impacted in the incident. The firm promptly revoked the approvals and shifted remaining assets into a more secure wallet setup.

What Is the 0x Swapper and how does It work?

The 0x swapper contract is a decentralized exchange (DEX) component designed to facilitate token swaps. It operates without permission, meaning anyone can call it to execute trades. But it should never be granted token allowances. Coinbase’s misconfiguration allowed the contract temporary access to tokens, which MEV bots exploited immediately.

In this case, the bots patiently monitored for a high-value wallet, such as Coinbase’s fee collector. And then accidentally authorize an exposed contract, which MEV bots then exploited due to the compromise, to drain the funds.

Also read: Coinbase relaunches stablecoin funding initiative after five year hiatus, here’s why

MEV bots are notorious for exploiting various on-chain inefficiencies. There are instances of bots reordering or inserting transactions in DEX environments to profit, often paying higher gas fees to jump ahead. Another analysis shows that over $3.88 million in losses have been reported from unfair trade executions, all of these were tied to extractable value strategies.

Coin Headlines covers the latest news in crypto, blockchain, Web3, and markets, bringing you credible and up-to-date information on all the latest developments from around the world.

We focus on real-time news updates, market movements, whale transfers, and macroeconomic trends to keep you informed and engaged. Whether it’s Bitcoin price swings, altcoin updates, meme coin hype, regulatory changes, or major moves from the world of traditional finance, Coin Headlines gives you what you need to know, right when you need it.