
0x1Nonce҉
137 posts

0x1Nonce҉
@NonceBender
Blockchain Security Researcher 🔗 | Web3 💻 | Smart Contracts ⚙️ | Trader 📈 (FX & Crypto)



JUST IN: Trader accidentally swaps $50 million $USDT for $36,000 $AAVE on Ethereum.




Poor fellow swapped $50m -> $35k on eth mainnet 😭😭😭 etherscan.io/tx/0x9fa9feab3…








20 days ago a fresh wallet received $50.4M USDT from Binance. Just a bit ago, they swapped the entire amount for 327 AAVE worth ~$36K routed through CoW Protocol via Sushiswap. They paid $154K per AAVE. In the same block, an MEV bot immediately flash borrowed $29M WETH from Morpho, bought AAVE via Bancor @ fair value, and dumped the AAVE into the Sushiswap pool, repayed the flash loan, and pocketed $9.9M.


Earlier today, a user attempted to buy AAVE using $50M USDT through the Aave interface. Given the unusually large size of the single order, the Aave interface, like most trading interfaces, warned the user about extraordinary slippage and required confirmation via a checkbox. The user confirmed the warning on their mobile device and proceeded with the swap, accepting the high slippage, which ultimately resulted in receiving only 324 AAVE in return. The transaction could not be moved forward without the user explicitly accepting the risk through the confirmation checkbox. The CoW Swap routers functioned as intended, and the integration followed standard industry practices. However, while the user was able to proceed with the swap, the final outcome was clearly far from optimal. Events like this do occur in DeFi, but the scale of this transaction was significantly larger than what is typically seen in the space. We sympathize with the user and will try to make a contact with the user and we will return $600K in fees collected from the transaction. The key takeaway is that while DeFi should remain open and permissionless, allowing users to perform transactions freely, there are additional guardrails the industry can build to better protect users. Our team will be investigating ways to improve these safeguards going forward.










