📈 Get daily crypto insights that make you smarter about your money

LeetSwap DEX Suffers Access Control Exploit on Base Network Losing Over 340 ETH

The decentralized exchange LeetSwap, operating on Coinbase’s Base network, fell victim to a sophisticated smart contract exploit on August 1, 2023, resulting in the loss of over 340 ETH—valued at approximately $636,000 at the time. The attack exposed critical vulnerabilities in access control mechanisms that continue to plague decentralized finance protocols.

The Exploit Mechanics

The attacker identified and exploited a publicly exposed function named _transferFeesSupportingTaxTokens within LeetSwap’s smart contract infrastructure. This function, which should have been restricted to authorized addresses only, was accessible to any external caller on the network.

The attack sequence followed a methodical pattern. First, the attacker swapped WETH for a targeted token within a LeetSwap liquidity pool. Then, using the exposed fee transfer function, they transferred the token while simultaneously invoking the pool’s sync function. This manipulation artificially inflated the token’s price within the pool. Finally, the attacker swapped the now-overvalued tokens back for WETH, draining the liquidity pool at a significant profit.

This was not an isolated incident targeting a single pool. The attacker systematically repeated this process across multiple LeetSwap liquidity pools, compounding the total losses well beyond the initial 340 ETH figure.

Affected Systems

The exploit specifically targeted LeetSwap’s deployment on the Base network, a Layer 2 scaling solution built by Coinbase on top of Optimism’s OP Stack. At the time, Base was in its early days of public availability, having launched its mainnet to developers just weeks prior. The attack contract was deployed at address 0xea8f89, with the vulnerable contract located at 0x94dac4 on Base.

The broader DeFi ecosystem was already reeling from the Curve Finance exploit that occurred just two days earlier on July 30, 2023, which exploited a Vyper compiler reentrancy vulnerability and resulted in over $24 million in losses. Together, these incidents contributed to a staggering $390 million in total losses across the crypto sector during July 2023 alone, according to De.Fi’s monthly Rekt Report published on August 1.

The Mitigation Strategy

Security researchers from CredShields analyzed the attack and identified several critical mitigation measures. The primary recommendation was implementing proper access control using OpenZeppelin’s “onlyOwner” modifier to restrict sensitive function calls to authorized addresses. Additionally, function visibility should be carefully audited to ensure internal functions are not inadvertently exposed as public.

Comprehensive test coverage is essential to validate all business logic paths and edge cases. Professional smart contract audits from reputable security firms can identify these vulnerabilities before deployment, saving projects from catastrophic losses.

Lessons Learned

The LeetSwap exploit underscores a persistent challenge in DeFi security: access control failures remain one of the most common and devastating vulnerability classes. Despite the availability of well-established patterns and libraries for implementing access restrictions, new projects continue to deploy contracts with improperly secured functions.

The timing of this attack, coming just 48 hours after the Curve Finance exploit, highlights the cascading nature of DeFi security incidents. When attackers identify a successful exploit pattern, they often scan for similar vulnerabilities across other protocols, leading to clusters of attacks within short timeframes.

User Action Required

Users who interacted with LeetSwap on Base should immediately check their wallet transactions for any unauthorized activity. Liquidity providers should withdraw their funds from any affected pools. All DeFi users should exercise heightened caution when interacting with newly launched protocols, particularly those on recently deployed networks like Base was at the time. Always verify that a protocol has undergone professional security audits before committing significant capital.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before engaging with any DeFi protocol.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “LeetSwap DEX Suffers Access Control Exploit on Base Network Losing Over 340 ETH”

  1. a publicly exposed _transferFeesSupportingTaxTokens function… thats not even a bug, thats just negligence. access control 101

    1. modifier_check

      bugswatter_ it wasn’t even a missing modifier, the function was literally public. _transferFeesSupportingTaxTokens should’ve been internal from day one. copy paste dev work

      1. modifier_check copy paste dev work is right. _transferFeesSupportingTaxTokens should have been internal. literally a 30 second fix that cost 340 ETH

        1. modifier_police

          Fatima Z. literally a 30 second fix. changing the function visibility from public to internal. teams deploying on Base without basic access control reviews shouldnt be handling TVL period

          1. modifier_police 30 second fix that cost 636K. the sync manipulation was so simple any auditor would have flagged it in the first pass

          2. _transferFeesSupportingTaxTokens left public on a contract handling TVL. literally a visibility keyword change and 340 ETH disappears

    2. its worse than negligence. they probably copied a template and didnt even think about access modifiers. seen it a dozen times on new L2 launches

    3. access control 101 and a team building on a new L2 skipped it. the rush to deploy on base was real, everyone wanted to be first and security was an afterthought

      1. vault_guard base was weeks old when this happened. teams rushing to deploy on a new L2 with unaudited contracts because apy farming was more important than security. same story every chain launch

        1. base being weeks old isnt an excuse. arbitrum and optimism had early exploits too but none this elementary. copy paste dev work cost 636K

        2. base_launch_tax

          Anders V. rushing to deploy on a new L2 because APY farming was more important than security. same story every chain launch, saw it on arbitrum and optimism too

    1. audited protocols get exploited too though. the issue here is base network being new with fewer mature tooling options for teams to use

      1. fair point on tooling but base was literally weeks old when this happened. teams deploying serious TVL on a chain with no audit infrastructure was the real problem

        1. Tomasz N. Base being weeks old isnt an excuse. Arbitrum and Optimism both had exploits in their early days too but none this dumb. _transferFeesSupportingTaxTokens left public on purpose or by accident, either way its 340 ETH gone

  2. an exposed _transferFeesSupportingTaxTokens function. thats not a hack, thats a resignation letter from your dev team

  3. the attack pattern is actually clever though. inflate via sync then dump. simple but effective on unaudited contracts

    1. the sync manipulation into dump was clean execution on a sloppy contract. base network was too new for teams to have proper tooling

  4. base_native_99

    LeetSwap was the wake up call for base security. after this coinbase started pushing their verified contracts program hard

  5. 340 ETH gone because of an access control bug. this is literally step one of every audit checklist. initialize your contracts properly people

    1. access_ctrl_ the issue was a privileged function left public. OpenZeppelin AccessControl exists for exactly this. no excuse for a DEX handling millions

  6. another day another Base DEX exploit. the chain is cheap for a reason. dev tooling and audit culture on L2s is still 2 years behind mainnet

    1. base_skeptic_ the function was literally named _transferFeesSupportingTaxTokens and nobody thought to add access control. copy paste dev culture on L2s

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,093.00-1.5%ETH$2,398.20-2.5%SOL$99.17-3.8%BNB$683.00-1.1%XRP$1.33-2.9%ADA$0.1953-1.8%DOGE$0.0809-2.2%DOT$0.8683+2.4%AVAX$7.16-1.3%LINK$11.13-2.0%UNI$5.82+10.9%ATOM$1.46-1.1%LTC$49.10+1.0%ARB$0.1101-1.9%NEAR$1.84-5.0%FIL$0.7737+13.1%SUI$0.7147-2.0%BTC$77,093.00-1.5%ETH$2,398.20-2.5%SOL$99.17-3.8%BNB$683.00-1.1%XRP$1.33-2.9%ADA$0.1953-1.8%DOGE$0.0809-2.2%DOT$0.8683+2.4%AVAX$7.16-1.3%LINK$11.13-2.0%UNI$5.82+10.9%ATOM$1.46-1.1%LTC$49.10+1.0%ARB$0.1101-1.9%NEAR$1.84-5.0%FIL$0.7737+13.1%SUI$0.7147-2.0%
Scroll to Top