On August 6, 2026, a phishing attacker stole $501,650 USDC from a wallet on Base, then lost over $371,000 (74%) of the stolen funds to an MEV bot sandwich attack after failing to set slippage protection. Blockchain security firm PeckShield tracked the incident: the attacker's uniswap V4 swap lacked slippage limits,...

Create a landscape editorial hero image for this Studio Global article: What happened when a hacker stole 500,000 USDC from a Base wallet but lost over 75% of it to an MEV bot's sandwich attack, and what does thi. Article summary: On August 6, 2026, a phishing attacker stole approximately **$501,650 USDC** from a wallet on the Base network (Coinbase's Ethereum Layer-2). Hours later, while trying to swap the stolen USDC into ETH, the attacker faile. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
On August 6, 2026, a phishing attacker stole approximately $501,650 USDC from a wallet on the Base network (Coinbase's Ethereum Layer-2) . The theft occurred around 02:29 UTC after the attacker compromised the victim's wallet through a phishing signature, gaining direct access to drain the USDC balance
.
Hours later, the attacker attempted to convert the stolen stablecoins into ETH via a decentralized exchange. That's when the operation fell apart — not because of a protocol exploit, but because the attacker failed to set slippage protection on the swap. An automated MEV bot detected the pending transaction in the public mempool and executed a classic "sandwich attack": it bought ETH just before the attacker's swap (driving the price up), allowed the attacker's purchase to fill at the inflated price, then immediately sold its ETH position for a profit .
The bot extracted approximately $371,000 of the stolen funds, paying roughly 3.5 ETH in gas fees to secure the transaction ordering. The attacker walked away with only about 67 WETH (~$129,000) — a net loss of over 74% of the stolen haul .
A sandwich attack is a form of maximal extractable value (MEV) exploitation that relies on transaction ordering in a public blockchain mempool. Here's how the bot pulled it off :
In this case, the attacker used Uniswap V4 without setting a slippage cap, giving the bot nearly unlimited room to manipulate the execution price across the transaction batch .
The incident serves as a stark reminder that in DeFi, technical sophistication matters at every step — even criminals can lose to better-automated adversaries when they ignore basic transaction hygiene.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
On August 6, 2026, a phishing attacker stole $501,650 USDC from a wallet on Base, then lost over $371,000 (74%) of the stolen funds to an MEV bot sandwich attack after failing to set slippage protection.
On August 6, 2026, a phishing attacker stole $501,650 USDC from a wallet on Base, then lost over $371,000 (74%) of the stolen funds to an MEV bot sandwich attack after failing to set slippage protection. Blockchain security firm PeckShield tracked the incident: the attacker's uniswap V4 swap lacked slippage limits, letting an MEV bot frontrun and backrun the trade, leaving the attacker with only $129,000 in WETH.
The incident underscores that MEV bots exploit any visible vulnerability — even criminal transactions — and that slippage protection, private mempools, and token approval hygiene are essential.