A DeFi user on the Base network lost roughly $501,650 in a phishing attack on August 6, 2026, but the story took a rare twist minutes later. A rushed swap on Uniswap V4 without slippage protection wiped out nearly 74% of the stolen amount and handed most of it to an MEV bot.
The incident was flagged by blockchain security firm PeckShield, which noted that the attacker “stole $500,000 and immediately lost $370,000 of it on his own swap.”
BaseScan data shows the phished funds moved from the victim’s wallet (0x3a5385D8…c51F70B5c) into an attacker-controlled address (0x920d3b63…102c39708) at 02:29:57 AM UTC in block 49597025. The victim’s position was held through the Steakhouse Prime USDC vault on Morpho, where 484,621 vault shares were burned, and 501,940.006 USDC was routed out through a phishing contract at 0xbeef0e08…b06873c9.
Attacker Swaps 501K USDC For Just 67 WETH
Barely 16 seconds after receiving the stolen funds, the attacker sent all 501,940 USDC into a Uniswap V4 WETH/USDC pool on Base in this transaction, executed at 02:30:13 AM UTC in block 49597033.
Because the swap carried no slippage protection and the chosen pool had shallow liquidity, the attacker received only 67.927 WETH, valued at about $129,426.15 at the time. That works out to a loss of roughly $373,000 in a single click, more than 74% of the stolen amount vaporised in seconds.
The abnormal price impact created a wide arbitrage window in the same block, and an MEV bot took the other side, walking away with an estimated $320,000 in profit in this back-run transaction.
Victim Offers 10% Bounty To MEV Bot Operator
Shortly after the loss, the victim sent an on-chain message to the MEV bot operator identifying themself as an “ordinary DeFi user” and requesting a return of the arbitrage profits sourced from the phished funds.
According to the message, the victim wrote, “I have identified the attacker and involved the legal authorities. Regarding these funds, I believe you operate with integrity and would like to negotiate the return of the funds that originated from the phishing attack. In return for your cooperation, I am prepared to offer a 10% bounty.”
The victim also sent a separate message to the attacker’s wallet asking for the remaining funds. As of press time, neither party has responded on-chain.
A Costly Reminder On Slippage And Thin V4 Pools
Uniswap V4’s Pool Manager on Base can host singleton pools where a large market order moves price by orders of magnitude if the router is called without a minAmountOut guard. MEV bots monitoring the mempool routinely back-run such swaps, rebalance the pool, and capture the mispricing.
The pattern of signature-based approval phishing has been documented repeatedly through 2026. Blockaid recently reported that crypto hacks crossed $1.1 billion in H1 2026, while CertiK found that Web3 lost $1.31 billion over the same period, with phishing alone accounting for $366.3 million across 63 incidents.
Users are advised to revoke unused token approvals through tools like Revoke.cash, hold large USDC or WETH balances in hardware wallets, and only trade through interfaces that enforce slippage limits by default.
Also Read: Coldcard Hacker Swaps Bitcoin to ETH via THORChain and Tornado Cash
