GoldPesa Hack
What happened
On October 2, 2026, GoldPesa’s GPXHooks contract on Base was exploited for ~$114,900 USD due to a smart contract vulnerability in its liquidity rebalancing accounting, which failed to verify zero currency deltas on a shared, flash-accounted PositionManager during Uniswap v4 hook interactions.
The attacker opened a PoolManager unlock and minted an unsettled WETH/USDC position to create a -$115k USDC phantom debt on the shared manager. By triggering reBalance() via a swap, the hook burned its real liquidity for a +$148.8k USDC credit, but the attacker's phantom debt absorbed the vast majority of it, leaving the hook with only ~$33.9k. The attacker then burned their own position to clear the debt and withdrew $114.9k USDC directly from PoolManager, before converting the proceeds to 96.4k USDT and bridging off Base via Rango Router.
Attack Transaction Hash: 0x5c1febd5…1ad2c9
Attacker Address: 0x4a5FD2e9…46899F
Vulnerable Contract: 0x4519e2b0…CcEaA8
Protocol details
Evidence
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.