Swap security

A familiar swap interface can still request an unfamiliar spender

Verify the transaction even on a familiar domain because a compromised interface can request different permissions or destinations.

A genuine aggregator domain can still serve a harmful request if its front end or dependencies are compromised. Past successful use and a saved bookmark do not prove the next approval matches the intended protocol.

Inspect the request boundary

Compare the input and output contracts, amount, recipient, chain and allowance spender in the wallet with your intended trade. The website’s own summary is not an independent check of data it generated.

0x’s contract documentation shows why contract roles matter: execution entry points and allowance targets can differ. An unexpected address should be verified by role, not accepted because it appears in a swap-related request.

Use independent evidence

Consult official deployment documentation through a known source, check credible incident notices and use supported device review. Clear signing can help expose meaningful fields on the signer, where supported.

A wallet security warning or newly requested broad allowance deserves attention even if the application looked normal yesterday.

If you already interacted

Record the time, domain, transaction hash and signed permission. Check whether the suspicious request was rejected, remained pending or confirmed. The response depends on what was authorized and whether secrets were exposed.

A front-end incident does not automatically mean every underlying contract is compromised. Conversely, a team restoring its website does not automatically revoke permissions granted during the incident. Follow exact affected-contract guidance and verify your own account’s state.

Sources & verification (3)

Source-check date is recorded in the article details. URLs are provided for manual verification. Use Copy to keep this page open.

  1. Contracts | 0x Docs

    Allowance targets differ from execution entry points; 0x warns against allowances to Settler.

    https://docs.0x.org/docs/core-concepts/contracts
  2. Overview - Ledger Developer Portal

    Human-readable transaction review and clear-signing scope.

    https://developers.ledger.com/docs/clear-signing/overview
  3. How to manage security alerts to protect your wallet

    Security warnings for sites, addresses, tokens and transaction or signature risks.

    https://support.metamask.io/configure/wallet/security-alerts/

Continue reading

How to verify the spender before approving an aggregator An aggregator reports a security incident: what should users check?