GoldPesa Hack

Reported loss $115K
Other

What happened

On October 2, 2026, GoldPesa’s GPXHooks contract on Base was exploited for ~$114,900 USD due to a smart contract vulnerability in its liquidity rebalancing accounting, which failed to verify zero currency deltas on a shared, flash-accounted PositionManager during Uniswap v4 hook interactions.

The attacker opened a PoolManager unlock and minted an unsettled WETH/USDC position to create a -$115k USDC phantom debt on the shared manager. By triggering reBalance() via a swap, the hook burned its real liquidity for a +$148.8k USDC credit, but the attacker's phantom debt absorbed the vast majority of it, leaving the hook with only ~$33.9k. The attacker then burned their own position to clear the debt and withdrew $114.9k USDC directly from PoolManager, before converting the proceeds to 96.4k USDT and bridging off Base via Rango Router.

Attack Transaction Hash: 0x5c1febd5…1ad2c9

Attacker Address: 0x4a5FD2e9…46899F

Vulnerable Contract: 0x4519e2b0…CcEaA8

Protocol details

Classification Exchange (DEX)
Protocol Type Exploit/Other
Protocol links @Goldpesatoken

Market Context at Time of Hack

Token Price at Hack $5.91
Token Categories
Decentralized Finance (DeFi) Base Ecosystem

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.