Matcha Meta suffered a $16.8 million exploit after attackers abused a vulnerability in SwapNet, an integrated liquidity provider. The flaw allowed unauthorized token transfers from users who had granted persistent contract approvals, while those using one-time approvals were unaffected. The attacker swapped stolen funds into ETH and bridged assets across networks, complicating recovery. Matcha Meta disabled SwapNet, removed direct allowance options, and urged users to revoke token approvals.