Hours later, the attacker attempted to convert the stolen stablecoins into ETH via a decentralized exchange. That's when the operation fell apart — not because of a protocol exploit, but because the attacker failed to set slippage protection on the swap. An automated MEV bot detected the pending transaction in the public mempool and executed a classic "sandwich attack": it bought ETH just before the attacker's swap (driving the price up), allowed the attacker's purchase to fill at the inflated price, then immediately sold its ETH position for a profit .
The bot extracted approximately $371,000 of the stolen funds, paying roughly 3.5 ETH in gas fees to secure the transaction ordering. The attacker walked away with only about 67 WETH (~$129,000) — a net loss of over 74% of the stolen haul .
A sandwich attack is a form of maximal extractable value (MEV) exploitation that relies on transaction ordering in a public blockchain mempool. Here's how the bot pulled it off :
In this case, the attacker used Uniswap V4 without setting a slippage cap, giving the bot nearly unlimited room to manipulate the execution price across the transaction batch .
The incident serves as a stark reminder that in DeFi, technical sophistication matters at every step — even criminals can lose to better-automated adversaries when they ignore basic transaction hygiene.