Coinbase's Own Fee Wallet Loses $550K to a Misdirected Token Approval
A corporate wallet belonging to Coinbase was systematically emptied of roughly $550,000 in tokens on August 13, after it granted open-ended ERC-20 spending approvals to the wrong contract in 0x Protocol's ecosystem — a configuration that 0x's own documentation explicitly warns against.
01What happened

The wallet in question collected affiliate-fee revenue generated through 0x Protocol's trading aggregation, a routine part of Coinbase's operations. At some point, during changes to how the company's "corporate DEX wallet" was set up, whoever configured it granted broad token approvals to 0x's Mainnet Settler contract — rather than to Permit2 or AllowanceHolder, the options 0x recommends for exactly this reason. Settler is built to be permissionless, meaning anyone can invoke it; that composability is a feature for legitimate DeFi activity, but it becomes a liability the moment a wallet hands it real spending rights.
Those approvals landed on-chain at 17:09 UTC on August 13, in what has been identified as the first approval transaction. Monitoring bots noticed almost immediately. Security researcher deebeez was among the first to flag the activity, watching a wide range of tokens drain out of Coinbase's wallet in real time.
The wallet involved has been identified as:
Coinbase Fee Wallet: 0x382ffce2287252f930e1c8dc9328dac5bf282ba1
There was no vulnerability to patch and no code exploited — a permissionless contract simply did what it was built to do once it was mistakenly given authority over the wallet's holdings.
02How the extraction worked
According to forensic analysis published by Blockscope, the operation followed a consistent three-step pattern repeated across roughly 168 distinct ERC-20 tokens:
- Pull:
transferFrom()calls drew directly on the approvals Coinbase's wallet had granted. - Swap: Each token was routed through decentralized exchange liquidity — Blockscope counted roughly 180 separate pools involved, most of them on Uniswap v3.
- Consolidate: Proceeds were converted to wETH and then to plain ETH.
Tokens caught up in the sweep included USDT, PyUSD, AMP, MYRIA, DEXTools-related tokens, Swell, and numerous stablecoins and altcoins. Throughout the roughly four-hour operation, the party responsible paid priority fees to block builders to keep transactions processing smoothly — the hallmark of a deliberate, well-prepared operation rather than an opportunistic grab.
Two addresses have been tied to the extraction:
Exploiting wallet: 0x17f79e70ae89c6e32a9244d3d57b7aa648246468
Bot address: 0xac13439d598cd1a60c14c965ed0fa7c46cb0d89d
Blockscope's research further notes that the exploiting wallet's initial funding traced back to a contract already flagged as a scam — one blocked by several centralized platforms, linked to Tornado Cash, blacklisted by Tether, and appearing on the OFAC sanctions list. The ETH collected from the operation has reportedly remained untouched since.
03Coinbase's response and the real number
Coinbase's Chief Security Officer, Philip Martin, confirmed the incident a few hours after it began, describing it as an isolated issue tied to changes in one of the company's corporate DEX wallets. He stressed that no customer funds were involved, and said the team was revoking the relevant allowances and migrating to a new wallet.
Initial public reporting, including figures circulating on social media and in crypto news outlets, put the loss at roughly $300,000. Blockscope's more detailed on-chain reconstruction subsequently put the actual figure closer to $550,000.
For its part, 0x Protocol reiterated its existing guidance following the incident: approvals should never be set directly on the Settler contract, and should instead go through Permit2 or AllowanceHolder.
04Not the first time
This is not the first instance of a wallet being drained through improper use of 0x's Mainnet Settler. In April, Zora suffered a $128,000 loss tied to the same underlying contract. In that case, attackers chained together public calls to Settler with Zora's claim logic to redirect payouts, exploiting how the two systems composed together rather than a direct approval error. Every contract involved behaved exactly as coded — the flaw was in how independently safe pieces interacted.

The mechanics differed — Zora's exposure came from unintended composability between contracts, while Coinbase's came from a direct grant of spending authority — but the underlying lesson is identical: in permissionless DeFi, who is allowed to spend on a wallet's behalf matters as much as the security of the code itself.
05Broader pattern at Coinbase
The approval mishap is a relatively small piece of a larger pattern of user-fund losses tied to Coinbase. Researcher ZachXBT has documented roughly $300 million in annual losses suffered by Coinbase users to social-engineering scams. Over a two-month stretch, an estimated $65 million was lost to organized phishing operations impersonating Coinbase support call centers — using spoofed phone numbers, leaked personal data, fraudulent emails carrying fake case IDs, and cloned websites convincing enough to fool most users. Victims have described moving funds to what they believed were secure wallets, only for those wallets to belong to the scammers themselves.
According to reporting on the scale of these losses, Coinbase has at times characterized user complaints about these schemes as misinformation, maintaining that its fraud-prevention systems were functioning as intended even as flagged theft addresses continued processing stolen funds for extended periods. The company has also stated its fraud prevention efforts have saved tens of millions of dollars, even as additional reporting points to hundreds of millions lost to the same recurring attack patterns. A related account of these phishing operations is available in a separate rekt.news piece.
06Why it matters
Coinbase has positioned itself as a security-first, institutional-grade gateway into crypto — a publicly traded, heavily regulated exchange marketed to pension funds and corporate treasuries as the safe, professional choice. The August 13 incident shows that even the company's own internal operations failed to follow guidance that has been publicly documented by 0x Protocol since well before this event, and that had already caused a loss at another project months earlier.
Set against a backdrop of hundreds of millions of dollars lost by Coinbase customers to comparatively low-tech social engineering, a $550,000 internal wallet mistake is a small dollar figure but a telling data point: for an exchange whose entire pitch rests on operational discipline, this episode suggests that discipline has gaps at multiple levels, from configuration hygiene to user protection.
Get new scam files the moment we publish them — usually 2–3 emails a week.