V4 Swap Router by z0r0z Hack

Reported loss $42K
Ethereum
Fixed-Calldata-Offset Authorization Bypass

What happened

On March 3, 2026, the V4 Swap Router by z0r0z on Ethereum was exploited for approximately $42K. The attacker bypassed the router's payer authorization check with valid but non-standard ABI encoding and redirected swap output from a previously approved victim.

Technical root cause

The swap() authorization check used inline assembly to compare calldataload(164) with msg.sender, assuming a fixed location for the payer inside a dynamic bytes argument. ABI encoding permits the bytes tail to move, so an attacker could place their own address at the checked offset while encoding a victim as the actual payer in the relocated payload.

How it happened

  1. The attacker selected a user who had already approved the router, moved the dynamic-bytes offset to insert padding, and placed the attacker's address at the hardcoded check location.
  2. The actual bytes payload then encoded the approved victim as payer and the attacker's address as receiver, allowing the swap output to be redirected.

Protocol details

Classification Access Control / ABI Validation
Protocol Type Exploit/Access control

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.