• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M
How Automated Bots Exploited Coinbase for $300,000

How Automated Bots Exploited Coinbase for $300,000

user avatar

by Giorgi Kostiuk

2 days ago


Coinbase confirmed it lost approximately $300,000 in tokens due to automated trading bots exploiting a misconfiguration in a corporate wallet.

Incident Overview

Coinbase lost $300,000 when MEV bots exploited a misconfigured corporate wallet that inadvertently approved tokens for the 0x swapper contract. The exchange's chief security officer confirmed that no customer funds were affected and termed it an isolated incident.

Technical Details of the Exploit

Philip Martin, Coinbase's chief security officer, acknowledged the loss via a post on X, describing it as 'an isolated issue' stemming from changes made to one of the company's corporate decentralized exchange wallets. Security researcher 'deeberiroz' from Venn Network first identified the exploit, explaining that Coinbase had incorrectly approved tokens to the swapper contract, a permissionless tool designed for executing trades. This configuration error created an opening for opportunistic MEV bots constantly monitoring blockchain networks for such vulnerabilities.

Broader Implications for Exchange Security

The permissionless nature of the 0x swapper contract allowed any party to call it and transfer approved tokens directly to their own addresses. While the $300,000 loss represents minimal financial impact for Coinbase, the incident highlights how major cryptocurrency exchanges remain susceptible to sophisticated automated trading exploits. 'Even well-established platforms can fall victim to relatively small but technically advanced forms of blockchain manipulation.'

The Coinbase incident underscores the technical complexities exchanges face when integrating with decentralized finance protocols. While the financial impact remained limited and no customer funds were compromised, the exploit reveals how automated bots continuously scan for configuration errors to capitalize on even brief windows of opportunity.

0

Rewards

chest
chest
chest
chest

More rewards

Discover enhanced rewards on our social media.

Other news

BlockDAG Sets New Standards with $1.206M Auction

chest

BlockDAG captures attention with a $1.206 million auction as SHIB faces selling pressure in the market.

user avatarGiorgi Kostiuk

SEC Initiates Project Crypto: A Path to Modernizing the U.S. Cryptocurrency Market

chest

The launch of Project Crypto by the SEC aims to reduce legal uncertainty and establish the U.S. as a hub for cryptocurrency innovations.

user avatarGiorgi Kostiuk

Gemini Seeks Nasdaq Listing with IPO Filing under Ticker GEMI

chest

Gemini, led by the Winklevoss twins, files for an IPO to list on Nasdaq under ticker GEMI amid positive U.S. regulatory trends.

user avatarGiorgi Kostiuk

Ronin, the Ethereum sidechain for Axie Infinity, is transitioning to Layer 2

chest

Ronin, created for Axie Infinity, has announced its transition to Layer 2, promising improved network performance and security.

user avatarGiorgi Kostiuk

Supply Reduction: OKX Burns 279 Million OKB

chest

OKX announced the burning of 279 million OKB tokens, leading to a 200% price surge.

user avatarGiorgi Kostiuk

Avenir Group Makes Largest Bitcoin ETF Investment from Asia

chest

Hong Kong's Avenir Group reports $1.3 billion in Bitcoin ETFs, bolstering institutional interest in digital assets.

user avatarGiorgi Kostiuk

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.