There’s a certain poetic justice when a thief gets robbed. An attacker who drained roughly $501,650 in USDC from a victim’s wallet on the Base chain ended up keeping only about $129,000 of it, after a maximal extractable value (MEV) bot sandwich-attacked the swap transaction and pocketed approximately $370,000 in profit.
The phishing attack occurred around 02:29 UTC on August 6, with the stolen funds moving to an attacker-controlled address within moments. What happened next turned a straightforward heist into one of the more entertaining on-chain dramas in recent memory.
How the attacker outsmarted a victim but not a bot
After securing the $501,650 in USDC, the attacker attempted to convert the stablecoin haul into wrapped ETH through a Uniswap V4 swap. This is standard operating procedure for crypto thieves: move stolen funds into a more liquid, harder-to-freeze asset as quickly as possible.
The problem? The attacker apparently executed the swap without setting proper slippage protection. Slippage controls are essentially price limits that prevent a trade from going through if the execution price deviates too far from expectations.
An MEV bot spotted the unprotected swap sitting in the mempool and executed a sandwich attack: it placed one transaction immediately before the attacker’s swap (driving the price up) and another transaction immediately after (capturing the inflated difference).
The result was brutal. The attacker received only about 67.9 ETH from the swap, valued at roughly $129,000. That’s a 74% haircut on a half-million-dollar theft. The MEV bot, meanwhile, spent approximately 3.5 ETH in gas fees to execute the sandwich and walked away with the lion’s share of the stolen funds.
The victim fights back on-chain
In an unusual move, the victim began sending on-chain messages to both the attacker and the MEV bot operator. These blockchain-based messages, which are publicly visible to anyone monitoring the addresses, asserted that the victim had identified the perpetrator.
The victim also offered a 10% bounty for the return of the stolen funds. On-chain security firm PeckShield flagged the attack and the subsequent MEV extraction within hours, bringing wider attention to the incident. As of August 7, no funds had been returned, and no arrests had been made.
The identity of the MEV bot operator remains undisclosed. The specific phishing vector used in this attack has also not been publicly disclosed, leaving open questions about whether it involved a fake website, a compromised dApp interface, or a social engineering scheme.
Base’s growing pains
The incident occurred on Base, Coinbase’s Ethereum Layer-2 network, which has seen significant growth in trading activity. The irony here is that the attacker, presumably sophisticated enough to execute a phishing operation, failed to use any of the available tools to mitigate MEV exposure, including private transaction submission services and DEX aggregators with built-in MEV protection.
For now, the attacker sits with roughly $130,000 in ETH, the MEV bot operator holds around $370,000 in profit, and the victim is out half a million dollars and sending messages into the blockchain void.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
12









English (US) ·