PacaSwap has temporarily shut down key infrastructure after a security exploit drained its SWAP/DAG liquidity pool on August 24. The protocol traced the attack to a vulnerability in its metagraph and says affected liquidity providers will be reimbursed, while the broader Constellation Hypergraph continues operating normally.
In its official security notice, PacaSwap said it detected suspicious activity affecting the pool and moved both the metagraph and bridge into maintenance while engineers develop a patch. The shutdown is intended to contain the affected infrastructure rather than halt the underlying Constellation network, with the team initially saying services would remain unavailable until at least August 25.
Pacaswap was targeted in an attack earlier today.
The attacker exploited a vulnerability in the metagraph to drain the SWAP/DAG pool.
We have identified that vulnerability and are patching it now. The metagraph and the Bridge are down for maintenance until at least tomorrow.…
— PacaSwap² (@PacaSwap) August 25, 2026
Metagraph Vulnerability Forces Bridge and DEX Offline
PacaSwap operates as a metagraph within Constellation’s ecosystem, giving the exchange its own application-specific execution environment rather than relying entirely on conventional smart contracts deployed to another blockchain. The public PacaSwap metagraph repository, maintained under Constellation Labs’ GitHub organization, exposes the software underpinning that architecture. The exploit therefore targeted application-level infrastructure specific to PacaSwap rather than demonstrating a compromise of the Hypergraph itself.
PacaSwap has not yet disclosed the precise code path used by the attacker or published a final estimate of the assets removed. Without a technical post-mortem, the vulnerability should not be characterized more narrowly than the metagraph flaw identified by the project, and there is currently insufficient evidence to attribute the incident to compromised keys, bridge verification or another specific mechanism.
The bridge was also suspended as part of the response, even though PacaSwap has not said that it was independently exploited. Taking both systems offline reduces the number of available paths through which assets could move while engineers assess the damage and deploy the fix. The project said a further status update would follow as remediation progressed.
PacaSwap Says Liquidity Providers Will Be Made Whole
For users, the most significant commitment is PacaSwap’s pledge to cover losses suffered by affected SWAP/DAG liquidity providers. The team says users do not need to submit claims or take any immediate action, and it has specifically warned that no official reimbursement form exists.
That warning is important because security incidents frequently create an opening for impersonation and phishing campaigns. PacaSwap said its team will not contact users through unsolicited direct messages regarding refunds. Any account requesting wallet credentials, seed phrases or reimbursement information should therefore not be treated as part of the announced compensation process.
The public Constellation DAG Explorer independently identifies PacaSwap as a metagraph on the network, providing a non-news reference for its underlying deployment. That distinction reinforces the current scope of the incident: PacaSwap’s own execution and bridge infrastructure were interrupted, while the Hypergraph was reported as unaffected.
The immediate priority is restoring the metagraph and bridge after the vulnerability is patched and reviewed. PacaSwap has committed to reimbursing affected LPs, but the incident cannot be considered fully resolved until the technical cause, total loss and remediation measures are publicly documented.
