Coinbase lost $300,000 due to an MEV attack and a wallet misconfiguration.

Coinbase lost about $300,000 due to incorrectly configured interaction with the exchange contract of the decentralized platform 0x. According to security researcher from Venn Network under the nickname deeberiroz, the exchange’s corporate wallet approved token transfers to a contract not intended to receive such permissions.

The 0x exchange contract can be called without restrictions, making it a convenient target for bots tracking erroneous operations. According to the data, after issuing token approvals, including Amp, MyOneProtocol, DEXTools, and Swell Network, MEV bots withdrew funds from the exchange account intended for collecting fees.

Coinbase’s Chief Security Officer Philip Martin confirmed the incident and stated that the loss of funds was related to a change in the configuration of the corporate wallet. He emphasized that customer funds were not affected and that the situation is an isolated incident.

The researcher noted that a similar scheme had previously led to incidents during the Zora airdrop on the Base network. At that time, bots exploited user errors to unauthorizedly withdraw coins.

Coinbase has already revoked permissions for problematic tokens and transferred assets to a new corporate wallet. This will help prevent similar attacks from happening again.

The incident, according to some experts, has once again drawn attention to the risks associated with automatic interactions of smart contracts and the vulnerability to MEV-bot attacks in the DeFi ecosystem.

Let us remind you that we wrote that Flashbots specialists called MEV bots a scaling problem for blockchains.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
  • Pin
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)