A thief who stole approximately $500,000 in USDC from Base lost $371,000 of the haul to a maximal extractable value sandwich attack within hours of the theft, retaining only $129,000, according to security monitoring data.
The attacker executed the initial theft on August 6 at 02:29 UTC, extracting $501,650 USDC from a wallet. Within 48 hours, an MEV bot intercepted the attacker's subsequent transaction, executing a sandwich attack that drained the majority of the stolen funds before the original transaction settled. The bot captured the value differential, leaving the attacker with approximately $129,000 in WETH.
MEV sandwich attacks work by placing transactions ahead of and behind a target transaction in the same block, allowing operators to extract value from the price impact the target transaction creates. On Base and other Ethereum rollups, MEV bots monitor the mempool for large, profitable transactions and execute these attacks at microsecond speeds. In this case, the sandwich bot identified the attacker's attempt to move or convert the stolen USDC and capitalized on the resulting price slippage.

Security firms including PeckShield have tracked cases where theft proceeds evaporate after on-chain movement, whether through front-running, sandwich attacks, or liquidation cascades triggered by large positions. The pattern has occurred repeatedly in 2026.
Base, Coinbase's Layer 2 scaling solution, has processed billions in transaction volume since its mainnet launch and hosts numerous DeFi protocols and token bridges. The network uses Optimism's OP Stack architecture and inherits Ethereum's security model while maintaining lower transaction costs. MEV extraction on Base operates similarly to the mainnet but at reduced absolute costs due to lower gas prices.
The attacker recovered $129,000 of the original $500,650 theft, a net loss of 74 percent to MEV extraction within two days. The speed and scale of the loss, $371,000 captured by a single sandwich attack, show how MEV bots identify and execute against large, unoptimized transactions on public blockchains. Thieves who do not obscure transaction patterns or use MEV-resistant routing face near-certain interception when moving substantial sums.