Kucoin MEV Bot Steals $370K from Phishing Victim on Base Chain
Article Content
- •A phishing attack resulted in a $500,000 loss for a user on the Base chain.
- •MEV bots exploited the transaction, siphoning off $370,000 during the conversion process.
- •The victim is actively seeking restitution by contacting the attacker and MEV bot.
On August 7, 2026, a user on the Base chain lost 500,000 USDC due to a phishing attack. The attacker attempted to convert the stolen funds to WETH but used a script without slippage protection, leading to a transaction through a low liquidity Uniswap V4 pool. This resulted in only 67.9 ETH being received, valued at $129,000, while $370,000 was siphoned off by MEV bots. The MEV bot front-ran the transaction by paying just 0.03 USDC and incurred a gas fee of 3.5 ETH. The victim has since sent on-chain messages to both the attacker and the MEV address, claiming to have identified the attacker and offering a 10% bounty for a refund.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Uniswap in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…