V4 Swap Router by z0r0z Hack
What happened
On March 3, 2026, the V4 Swap Router by z0r0z on Ethereum was exploited for approximately $42K. The attacker bypassed the router's payer authorization check with valid but non-standard ABI encoding and redirected swap output from a previously approved victim.
The swap() authorization check used inline assembly to compare calldataload(164) with msg.sender, assuming a fixed location for the payer inside a dynamic bytes argument. ABI encoding permits the bytes tail to move, so an attacker could place their own address at the checked offset while encoding a victim as the actual payer in the relocated payload.
How it happened
- The attacker selected a user who had already approved the router, moved the dynamic-bytes offset to insert padding, and placed the attacker's address at the hardcoded check location.
- The actual bytes payload then encoded the approved victim as payer and the attacker's address as receiver, allowing the swap output to be redirected.
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.