Hacker lost $371K of stolen USDC to MEV bot on Base due to unprotected swap slippage.
DeFi & Yields ·
A hacker who obtained 500K USDC lost 371K of the amount to a maximal extractable value (MEV) bot while executing a swap on Base, according to security monitoring. The loss occurred because the attacker failed to implement slippage protection on the transaction, leaving it vulnerable to sandwich attacks.
MEV bots profit by reordering or inserting transactions in the mempool—the waiting area where transactions sit before blockchain inclusion—to extract value from unprotected swaps. On Base, the hacker's unprotected swap created an exploitable window that an MEV bot capitalized on, extracting most of the stolen funds before they could be moved to safety.
The incident illustrates a broader risk vector in decentralized finance: even actors moving large sums face financial exposure if transaction parameters lack proper safeguards. It remains unclear whether the original theft of the 500K USDC and the subsequent MEV extraction are connected to ongoing investigations.