A $74,000 Pool Absorbs a $50 Million Aave Trade
Someone was sitting on a $50 million position in Aave — not idle, but earning, parked in yield-bearing aEthUSDT.
On March 12, 2026, that holder decided to move the position into aEthAAVE instead — same protocol, different underlying token. For a large depositor, a collateral swap like this is routine.

The complication: it was executed from a phone, through Aave's own interface, which quietly routed the order through CoW Protocol. CoW's solver found a technically valid path — one that happened to terminate in a SushiSwap pool far too shallow for a trade of this size, yet not so shallow that the system refused to route through it.
The interface displayed one warning, and then a second, each requiring a checkbox confirming the user understood the risk. The boxes were checked.
Twelve seconds and one confirmed transaction later, the position that went in as $50 million came out as 327 AAVE — worth just under $37,000, roughly the price of a used car — while the rest of the ecosystem moved in to divide what was left.
No hack occurred. No contract misbehaved. Every warning fired exactly as it was built to. And a free routing tool built by DefiLlama would have refused to execute this trade at all.
Credit for reporting and analysis: YAM, CoinMarketCap, Decrypt, Ehsan, Stani Kulechov, 0xngmi, CoW DAO, bheau, CoinDesk, The Block, ACI, Nandy, Marc Zeller, EzR3aL, CZ, Lefteris Karapetsas, Omer Goldberg, Aave.
01What the trade was actually supposed to do
This was never meant to be a spot purchase — it was a collateral rotation. The user held aEthUSDT, Aave's yield-bearing wrapper for a USDT deposit, and wanted to convert it into aEthAAVE, the equivalent wrapper for AAVE. Same protocol, same underlying mechanic, just a different asset — the kind of atomic rebalancing Aave's collateral-swap feature is built to handle.
The CoW solver assembled a four-step route: burn the aEthUSDT, withdraw $50.4 million in USDT from Aave, convert it to 17,957 WETH through Uniswap V3's deep USDT/WETH pool (this leg priced normally, without incident), then route that WETH through SushiSwap's AAVE/WETH pool to buy AAVE, deposit the AAVE back into Aave, and hand the resulting aEthAAVE to the user.
SushiSwap AAVE/WETH pool: 0xD75EA151a61d06868E31F8988D28DFE5E9df57B4
Three of the four legs were unremarkable. The fourth ran straight into a pool holding about $74,000 in total value.
At the moment the trade landed, that SushiSwap pool held just 331.63 AAVE and 17.65 WETH — roughly $74,000 combined. The route then attempted to push 17,957 WETH through it: 1,017 times the pool's entire WETH reserve.
An automated market maker does exactly what its formula dictates when overwhelmed like this — it gave up almost its entire AAVE balance in exchange for a fraction of a percent of the WETH sent in. The trade settled for 327.24 AAVE, worth about $36,000 at execution.
The transaction: 0x9fa9feab3c1989a33424728c23e6de07a40a26a98ff7ff5139f3492ce430801f
02Slippage was never the issue
Aave engineer Martin Grabina told Decrypt that the root problem wasn't slippage at all — it was price impact, a distinct concept that most of the initial coverage conflated.
The quote shown in CoW's explorer, before fees or slippage were factored in, already priced $50 million in USDT at fewer than 140 AAVE. The order's slippage tolerance was set automatically at 1.21% — a meaningless safeguard once the underlying route had already baked in a roughly 99% price impact. Slippage protection guards against price movement between quote and execution; it does nothing when the quote itself is already catastrophic.
The order's signed minimum buy amount was 324.94 AAVE, locked in before the trade ever reached settlement. The actual settlement delivered 327.24 AAVE — slightly above that floor. Nothing about execution went wrong; the route was broken from the moment it was constructed, not corrupted somewhere along the way.
03Following the money afterward
The $50 million didn't vanish so much as cascade upward through the stack, in about twelve seconds, with each layer capturing a share roughly proportional to how well-positioned it was to notice what had just happened.
The user was left with 327 AAVE, roughly $36,000. Aave's post-mortem later confirmed the protocol collected $110,368 in fees from the transaction and pledged to return them pending verification; CoW DAO separately committed to refunding whatever fees flowed to CoW Protocol from the same trade.
One MEV bot fared considerably better than either protocol. It captured roughly $9.9 million backrunning the AAVE/WETH leg and another $2.6 million backrunning the USDT/WETH leg — about $12.5 million total, extracted within a single block. Importantly, this was a backrun rather than a sandwich attack: on-chain data shows the Sushi pool was untouched when the user's transaction landed at index 1, with the bot arriving at index 2 only after the damage was done. The bot didn't cause the loss — the user would have lost close to the same amount regardless. It simply arrived after the pool had already been drained of any reasonable pricing.
The harvest transaction alone routed roughly 13,087 ETH (about $30 million) to Titan Builder; broader estimates put Titan's total revenue tied to the incident at approximately $34.3 million, most of it from MEV bots paying for priority block positioning.
The harvest transaction: 0x45388b0f9ff46ffe98a3124c22ab1db2b1764ecb3b61234e29e5c9732b7fd4ab — it pulled 17,929 WETH (about $41.3 million) from the pool the broken route had just wrecked, paid 13,087 ETH ($30.2 million) of that to Titan Builder, and kept 4,824 ETH ($11.1 million) as its own take.
Lido, as the block's proposer, received 568 ETH (about $1.2 million) as its share of Titan's payment. The remaining $3.5 million was absorbed by the pool's liquidity providers, passive bystanders to a pool that had just been hit far beyond its depth. BlockSec told CoinDesk that arbitrageurs extracted more than $43 million within that single block in total.
No single actor in that chain broke any rule — the bot found and took an opportunity, the builder built the block it was paid to build, and the LPs simply happened to be exposed. The user supplied the capital; everyone downstream captured a piece of it.
04A safeguard that didn't survive a rebuild
There's a second story underneath the trade itself. The Aave interface that processed this order was not the one that existed a few months earlier. In December 2025, Aave Labs replaced its ParaSwap-based swap integration with a new implementation built on CoW Protocol, announced at the time as the first flash-loan product designed for intent-based infrastructure.
One thing that didn't carry over in that rebuild was a hard cap on slippage. Marc Zeller, founder of the Aave Chan Initiative — who, along with the ACI, had already announced his departure from Aave on March 3 — pointed this out within hours of the incident: the previous frontend enforced a roughly 30% slippage limit. As he put it, the removal came "for the low price of 8 figures of fees diverted, -60% on the token and a killed DAO. Users can now enjoy the big DeFi energy of 99% slippage."
There's no evidence the removal was intentional. What's clear is that a protection present in the old system was simply absent from the new one, and that the engineers responsible for the original safeguard weren't part of the transition. ACI member Nandy summarized the concern: shipping a replacement without confirming that existing safety coverage carried over is a real problem, particularly when the people who built the original mechanism were available to consult.
The contrast came from an unexpected source. 0xngmi, founder of DefiLlama, posted a screenshot showing LlamaSwap attempting the identical trade — its buttons simply locked, and the swap was blocked outright. A free, community-maintained tool enforced tighter guardrails than Aave's own official frontend. Marc Zeller retweeted the screenshot with a single line: "Just use defillama" — a pointed echo of his older catchphrase, "Just use Aave."
05A governance fight already in progress
The CoW-powered integration wasn't just a technical rollout — it sat at the center of a governance dispute that had been simmering since its December launch. Within a week of that rollout, on-chain analysis showed swap fees from the new integration flowing to an address controlled by Aave Labs rather than the DAO treasury.
Orbit-Delegate EzR3aL's on-chain review put a floor on the diverted revenue at $10 million per year across just two networks, with the real figure likely higher. Aave Labs disputed this in the governance forum, arguing the interface is a privately funded and maintained product, separate from the DAO. Marc Zeller described it as "the stealth privatization of approximately 10% of Aave DAO's potential revenue." A subsequent Snapshot vote on brand asset ownership was voted down, 55% against.

The staffing picture compounded the risk. BGD Labs, the core contributor responsible for much of the original swap infrastructure, announced in February that its contract would end in April and it would not continue. In early March, Zeller and the ACI announced their own exit as well, effective this coming July: "ACI will wind down over four months. We will continue governance activity, implement outstanding Skyward commitments, and focus on infrastructure handoff and transition." The people who had built the 30% slippage cap were already heading for the exit, and nobody had verified that the new system preserved it. On March 12, 2026, that oversight cost someone $50 million.
06How each party responded
Stani Kulechov responded first: the interface had flagged the extraordinary slippage, required a confirmation checkbox, and the user had confirmed it on mobile — "the transaction could not be moved forward without the user explicitly accepting the risk." He confirmed Aave would return the fees it had collected, called the outcome "clearly far from optimal," and said the team would look into stronger guardrails.
Two days later, Aave's formal post-mortem followed through: it confirmed the $110,368 in collected fees and announced "Aave Shield," a 25% price-impact hard block enabled by default, which users would now have to manually disable in settings before executing a high-risk trade of this kind.
CoW Protocol issued its own response: warnings had been shown clearly, and the user had explicitly opted in after seeing them. No DEX, aggregator, or pool in existence could have filled an order this size at a reasonable price; blocking the trade outright would have removed user choice, which matters in situations like a market crash or a depeg. CoW confirmed its fees would also be refunded.
CoW's fuller post-mortem, two days after that, added more detail: a stale, hardcoded gas ceiling had rejected better-priced solver quotes (though the specific route it excluded would have reverted anyway, and the ceiling — a known infrastructure risk on complex routes — has since been fixed); a winning solver won two consecutive auctions but failed to settle either one on-chain before abandoning the order; and the transaction, though submitted via private RPC, showed signs of leaking into the public mempool, a point CoW said remained under investigation. Together, these failures left the worst available route as the only one still standing. CoW also noted that even the best available quotes would still have implied a roughly 90% loss on a $50 million fill-or-kill order in an illiquid pair — there was no path to a capital-preserving execution. As CoW put it: "Technically correct is not the ceiling we should be building toward."
CZ weighed in briefly: "Sad to see this. Liquidity is the best user protection." Lefteris Karapetsas ran an informal community poll asking who was at fault — user, frontend, or protocol. Of 657 votes, about 41% blamed the user, 44% the frontend, and 15% the protocol. No consensus emerged; every layer had a defensible position.
The timing added an odd coincidence. Just two days before this incident, on March 10, a misconfiguration in Aave's CAPO oracle had priced wstETH roughly 2.85% below market, triggering $27.78 million (10,938 wstETH) in wrongful liquidations across 34 accounts. Chaos Labs pledged full reimbursement for that incident, with no bad debt and all affected users made whole. Two unrelated failures, two apologies, two refund commitments, in the same week.
07The takeaway
Every party involved responded, and every response was defensible on its own terms. The warning had appeared. The checkbox existed. The contracts executed precisely as coded. The fees are being returned. And yet none of that changed the outcome: a $50 million position became $36,000, because a safety limit that existed in an older version of the interface wasn't verified to exist in the newer one, and a thin pool was technically — if not sensibly — reachable by the router.
The old fable has the scorpion ask the frog for a ride across the river, and when the frog hesitates, the scorpion argues that stinging him would drown them both. Here, the equivalent reassurance was a technically valid CoW route — and the "sting" wasn't malicious, just built into how the system worked. The result was the same: both ended up worse off, except in this version the frog lost $50 million and the block builder walked away with $34.3 million.
Nothing here required a bug or a theft. It required only that a guardrail quietly disappear during a routine upgrade, and that nobody check whether it had.
Get new scam files the moment we publish them — usually 2–3 emails a week.