
A phishing thief on Base lost 74% of a $501K USDC haul when an MEV bot sandwich-attacked the swap. The victim offered a 10% bounty. No funds returned.
Alpha Score of 37 reflects weak overall profile with poor momentum, weak value, poor quality, strong sentiment.
A phishing attacker on Coinbase's Base network drained roughly $501,650 in USDC from a victim's wallet on August 6, then lost most of the stolen funds to a maximal extractable value (MEV) bot within minutes of the heist.
The attacker moved the USDC to a wallet they controlled at around 02:29 UTC and attempted to convert the stablecoin into wrapped ETH through a Uniswap V4 swap. Converting stolen stablecoins into a more liquid asset is standard practice for crypto thieves, since it makes the funds harder to freeze and easier to move.
The swap went through without slippage protection, a price limit that blocks a trade if the execution price deviates too far from the expected rate. An MEV bot spotted the unprotected transaction sitting in the mempool and executed a sandwich attack, placing one trade before the attacker's swap to drive the price up and another immediately after to capture the difference.
The attacker received about 67.9 ETH from the swap, worth roughly $129,000 at the time. That works out to a 74% haircut on the stolen haul. The MEV bot spent approximately 3.5 ETH in gas fees to run the sandwich and kept around $370,000 in profit.
Blockchain security firm PeckShield flagged the attack and the subsequent MEV extraction within hours, drawing wider attention to the incident. The victim has been sending publicly visible on-chain messages to both the attacker and the MEV bot operator, asserting that the victim had identified the perpetrator. The victim also offered a 10% bounty for the return of the stolen funds. As of August 7, no funds had been returned and no arrests had been made.
The identity of the MEV bot operator remains undisclosed. The specific phishing vector used in the attack has not been publicly identified either, leaving open questions about whether it involved a fake website, a compromised dApp interface, or a social engineering scheme.
The irony is that the attacker, sophisticated enough to pull off a phishing operation, skipped the tools that would have prevented the sandwich entirely. Private transaction submission services and DEX aggregators with built-in MEV protection are standard options for anyone moving large sums on-chain.
The theft took place on Base, Coinbase's Ethereum Layer-2 network, which has seen sharp growth in trading activity. The incident offers a stark example of how MEV bots operate as an automated tax on careless transactions, even when the transaction itself is criminal.
The attacker now holds roughly $130,000 in ETH, the MEV bot operator holds around $370,000 in profit, and the victim is out half a million dollars.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.