Base attacker loses nearly 74% of 501,940 USDC haul to MEV bot after Uniswap V4 swap

Base attacker loses nearly 74% of 501,940 USDC haul to MEV bot after Uniswap V4 swap

The phishing victim said the attacker had been identified and offered a 10% bounty for a refund, but no funds had been returned as of Aug. 7 after an MEV bot captured about $370,000.

USDC
UNI
WETH

Fact Check
The PeckShieldAlert primary source and multiple independent aggregators (CoinNess, Odaily, RootData, ChainCatcher) all confirm the core claim: ~500K USDC drained from a Base wallet, a swap without slippage protection, an MEV bot sandwich/back-run, and the attacker ending with only ~67 WETH (~$129K), representing roughly a 74-75% loss. The CryptoTimes article supplies and validates the finer details asserted in the claim: the exact 501,940 USDC amount, the funds originating from a Morpho vault, the low-liquidity Uniswap V4 pool, absence of slippage protection, ~$370K/74% loss, the MEV bot capturing ~$320K, and the victim's on-chain 10% bounty offer, with basescan transaction links. The only claim element not independently named elsewhere is the specific 'Steakhouse Prime USDC vault,' though the Morpho vault origin is confirmed. The stated 'nearly 74%' loss is consistent with the ~75% cited by primary sources.
Summary

A DeFi user on Base lost 501,940.006 USDC in a phishing attack on Aug. 6, 2026, when 484,621 Steakhouse Prime USDC vault shares on Morpho were burned and the funds were routed through a phishing contract to an attacker-controlled address. The attacker then tried to swap the stolen USDC into WETH through a shallow Uniswap V4 pool without slippage protection, and the trade returned only 67.927 WETH, worth about $129,426.15, after an MEV bot extracted roughly $370,000 in what PeckShield later described as a sandwich attack. The victim later sent on-chain messages saying the attacker had been identified and offering a 10% bounty for a refund, but no funds had been returned and no arrests had been made as of Aug. 7; the MEV bot operator's identity and the specific phishing vector had not been publicly disclosed.

Terms & Concepts
  • MEV bot: An automated trader that monitors pending blockchain transactions and profits from how they are ordered.
  • slippage protection: A swap setting that stops a trade if the execution price moves beyond a chosen limit.
  • sandwich attack: A tactic where a bot trades before and after a target order to profit from the price impact.