Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
    3D Liquid Network logo with a hooded hacker shadow and computer code overlays in the background
    Liquid Network Exploit Explained: Unbacked L-BTC and the $320M Peg-Out
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Panther Protocol Hit by Governance Attack, 5.12M ZKP Drained on Base

Panther Protocol's Base deployment was exploited after an attacker used Reality.eth's optimistic governance process to pass a malicious proposal, draining 5.12 million ZKP and 0.12 ETH while no user funds were affected.

Written By Dishita Malvania
Published 2026-08-07·Updated 1 month ago
Make The Crypto Times preferred on GoogleGoogle
Panther Protocol Hit by Governance Attack, 5.12M ZKP Drained on Base

Panther Protocol, the privacy-focused DeFi project behind the ZKP token, has confirmed that its Base network deployment was drained on August 6, 2026, in a textbook governance attack routed through the Reality.eth optimistic oracle. 

Real-time exploit tracker Defimon Alerts, operated by Web3 security firm Decurity, was first to flag the incident publicly.

AI Summary
Show
Panther Protocol’s Base network was drained due to a governance attack facilitated by Reality.eth optimistic oracle
Joris_ZKP, a Panther Foundation contributor, acknowledged the incident, stating no user funds were compromised
Panther’s dev team has restored the affected proxy implementations on Base and taken measures to address the Reality.eth configuration

According to the post, the attacker submitted a governance proposal titled “zkp-reexploit” that would upgrade each ZKP proxy on Base to a drainer implementation, then posted a “yes” answer to the Reality.eth question backed by the required 0.5 ETH bond. 

When no honest party counter-bonded a “no” inside the 12-hour timeout, and the following 8-hour cooldown also passed in silence, the oracle finalized the malicious answer. The Panther governance module then dutifully executed the drain, sweeping roughly 5.12 million ZKP tokens and 0.12 ETH out of the Base contracts.

Panther Foundation contributor Joris_ZKP acknowledged the incident in an August 7 message to the Panther community, saying the team had learned “yesterday” that the Base deployment had been attacked. Importantly, he added that the Base deployment was “not yet in production” and that “no user funds were compromised,” with the loss confined to token supply and a small ETH balance on that specific chain.

How The Attack Actually Worked

Reality.eth is an optimistic oracle used by several DAOs, including Panther, to bring off-chain votes on-chain. Proposals are framed as questions. Answers are posted with an ETH bond, and if nobody counter-bonds the opposite answer inside the challenge window, the last answer wins and the paired governance module executes it. Fast and cheap, but the entire model rests on the assumption that at least one honest watcher is present for every question.

That assumption broke on Base. Panther’s dev team says the protections that automatically disable the Reality.eth module when there is no active DAO proposal, standard on the protocol’s other chains, had never been enabled on the Base deployment. That left a live, hot governance switch sitting on a network the community was not actively monitoring.

The attacker needed three things: a proposal, a 0.5 ETH bond, and silence. All three were available. The 12-hour timeout ran out without a counter-bond, the 8-hour cooldown passed without intervention, and the module then upgraded each ZKP proxy on Base to a drainer implementation, exactly as the proposal specified. The bond was returned to the attacker on finalization, so the effective cost of the exploit was gas.

Panther’s Response

In his community note, Joris_ZKP said the Panther dev team has already restored the affected proxy implementations on Base and that Panther DAO has taken measures to address the Reality.eth configuration on that chain. He added that the equivalent protections on Panther’s other deployments have been reviewed to confirm the same latent gap does not exist elsewhere. A fuller incident report is expected once the internal post-mortem is complete.

The Panther Foundation had not published a separate incident write-up on its official channels at the time of publication. Panther’s main governance flow runs through Snapshot with Reality.eth-based execution modules, and the Base rollout was part of a broader multi-chain expansion for the protocol’s V1 DAO-managed privacy zone.

What On-Chain Data Shows

Defimon’s alert pins the drained value at 5.12 million ZKP, with Panther’s own accounting adding 0.12 ETH lifted from the Base contracts. Priced against ZKP’s pre-incident quote of roughly $0.0025, the token loss carries a nominal value near $17,900, though the realized dollar figure depends entirely on whether any of the drained ZKP ever hits liquid venues. Base-side ZKP liquidity is shallow, and Panther’s mainline ZKP contract on Ethereum sits at 0x909…fa173.

Panther Protocol Price at the time of writing 19:22 IST
Price at the time of writing 19:22 IST Source: CoinGecko

The chart shared alongside the Defimon post shows the localized ZKP quote crashing 78.27% to around $0.000682, though on aggregators tracking the primary Ethereum and Polygon pools, ZKP was still marked around the $0.0025 range with a 24-hour volume near $70,000 and a market cap around $1.49 million against a circulating supply of roughly 430 million tokens. ZKP trades about 99% below its all-time high of $0.4387 hit in March 2022.

Governance Attacks Are Now A Trend, Not An Exception

The Panther incident is the latest in a growing 2026 pattern where the attack surface is not the smart contract’s math but the DAO’s process. On July 6, Solana memecoin governance body BonkDAO lost approximately $20 million in BONK after a malicious proposal quietly passed through a token-weighted vote on Realms, as covered by The Crypto Times. 

In June, Ethereum-based Token of Power (TOP) was drained of roughly $1.58 million after an attacker used a thin-supply governance token to grab more than 50% of voting power on Aragon, mint 10 billion new TOP tokens in one transaction, and dump them into a Balancer V1 pool, per coverage.

What sets the Panther case apart is that the attacker did not need voting power, capital, or social engineering. They needed nobody to be watching. Optimistic governance oracles like Reality.eth are only as safe as their weakest deployment, and the Base version of Panther was, by the team’s own admission, shipped without the module-disable safety net that would have blocked the proposal from ever finalizing.

The pattern also lines up with the wider 2026 security picture. Blockaid’s H1 2026 report tracked 212 on-chain exploits and over $1.1 billion in losses in the first six months of the year, with governance and process failures accounting for a rising share of the incident count even where the dollar totals sit below headline mega-breaches like Drift Protocol’s $285 million key compromise and KelpDAO’s $292 million bridge drain.

Defimon’s own product pitch, which it repeated at the end of the Panther alert, doubles as a comment on the incident: real-time feeds now push protocol-specific attack signals to teams within seconds, with the WebSocket variant priced at $200 a month, but coverage only helps a team that has a live incident-response pipeline hooked into it. Panther, on Base, did not.

For now, ZKP holders on Panther’s mainline Ethereum and Polygon deployments are unaffected, and the drained supply on Base sits with an attacker who has already exposed themselves on-chain. The bigger question, one Panther’s promised incident report will need to answer, is why the missing protection was missing in the first place, and whether the same latent gap has already been ruled out on every other chain the protocol has ever touched.

Also Read: Base Hacker Steals $500K USDC but Loses 74% in Costly Uniswap V4 Swap

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:CoinbaseCrypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

FTX Estate Moves $75M in Ethereum to Wintermute After Market Rebound
FTX Estate Moves $75M in Ethereum to Wintermute After Market Rebound
CFTC Flags Manipulation Risk in Kalshi-Style "Mention" Prediction Markets, Issues New Advisory
CFTC Flags Manipulation Risk in Kalshi-Style “Mention” Prediction Markets, Issues New Advisory
Cardano Price Jumps 26% in a Week as ADA Reclaims $0.25
Cardano Price Jumps 26% in a Week as ADA Reclaims $0.25
Canada’s Six Major Banks Explore Tokenized CAD Deposit System
Peter Schiff Questions Catalysts Behind Bitcoin Rally, Citing Saylor
Peter Schiff Questions Catalysts Behind Bitcoin Rally, Citing Saylor

Find Us on Socials

You may also like

Smartphone displaying the Coinbase logo in front of a blurred Coinbase background.

Coinbase Developer Platform Launches Crypto-Backed USDC Borrow API

Sonic Cancels All Manual S Token Mints and Orders Independent Audit

Sonic Cancels All Manual S Token Mints and Orders Independent Audit

A hat-wearing figure at a laptop in front of a Coldcard wall logo.

52.37 BTC From Coldcard Exploit Moved Into Wyoming Recovery Trust for Victim Return

Trueo to Move Prediction Market From Base to Ethereum as Vitalik Buterin Comments

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information