That setup opened the door for opportunistic MEV bots, which immediately drained the wallet once approvals were live.
MEV, or “maximal extractable value,” refers to the practice of front-running or reordering blockchain transactions to capture profits, or in this case, executing transfers before Coinbase could revoke access.
“There appears to have been an MEV bot lurking in the dark, waiting for users to mistakenly approve to this contract — and then drain all their funds,” the researcher wrote on X. “Well, their dream came true thanks to Coinbase … They made a killing by draining the Coinbase fee receiver account of all the tokens they gathered.”
Looks like @coinbase was recently drained of ~$300,000 after using @0xProject swapper incorrectly.
They approved all the tokens accrued as fees to their router, getting drained immediately by MEV bots 🧵 pic.twitter.com/yWNHl8nupg
— deebeez (@deeberiroz) August 13, 2025
Because the contract can be accessed by anyone, the bots were able to call it (a software term requesting services from another program) to transfer out the approved tokens directly to their own addresses.
While $300,000 is immaterial for Coinbase, the breach shows how even leading exchanges are vulnerable to small but sophisticated forms of automated trading exploitation.
MEV bots have long been a fixture in Ethereum and other blockchain ecosystems, profiting from token launches, NFT mints, and liquidity events by exploiting memepool visibility and transaction reordering.
In this case, the bots simply waited for a high-value wallet — like Coinbase’s fee receiver — to mistakenly grant spending rights to an exposed contract, then executed the drain instantly.