Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Nothing Is 100% Safe in Crypto Bitcoin’s Coldcard Exploit and Growing Security Crisis 
    Nothing Is 100% Safe in Crypto: Bitcoin’s Coldcard Exploit and Growing Security Crisis 
    From BitMEX to Leap Wallet 100+ Crypto Projects Have Shut Down in H1 2026
    From BitMEX to Leap Wallet: 100+ Crypto Projects Have Shut Down in H1 2026
    July Crypto Stock Breakdown Why MSTR, BMNR Held Gains as IREN, WULF, RIOT, ABTC Dropped
    July Crypto Stock Breakdown: Why MSTR, BMNR Held Gains as IREN, WULF, RIOT, ABTC Dropped
    What Happens If the CLARITY Act Does Not Pass?
    What Happens If the CLARITY Act Does Not Pass?
    The Trump Crypto Presidency Power, Policy, and $1.4 Billion
    The Donald Trump Crypto Presidency: Power, Policy, and $2.3 Billion
  • Opinion
    OpinionShow More
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Bitcoin Treasury Blueprint What Stress Testing on Strategy Inc.’s MSTR-STRC Reveals
    The Bitcoin Treasury Blueprint: What Stress Testing on Strategy Inc.’s MSTR-STRC Reveals
    Why Wall Street is Divided Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    Why Wall Street is Divided: Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Panther Protocol Hit by Governance Attack, 5.12M ZKP Drained on Base

Panther Protocol's Base deployment was exploited after an attacker used Reality.eth's optimistic governance process to pass a malicious proposal, draining 5.12 million ZKP and 0.12 ETH while no user funds were affected.

Written By Dishita Malvania
Published 1 hour ago
Make The Crypto Times preferred on GoogleGoogle
Panther Protocol Hit by Governance Attack, 5.12M ZKP Drained on Base

Panther Protocol, the privacy-focused DeFi project behind the ZKP token, has confirmed that its Base network deployment was drained on August 6, 2026, in a textbook governance attack routed through the Reality.eth optimistic oracle. 

Real-time exploit tracker Defimon Alerts, operated by Web3 security firm Decurity, was first to flag the incident publicly.

According to the post, the attacker submitted a governance proposal titled “zkp-reexploit” that would upgrade each ZKP proxy on Base to a drainer implementation, then posted a “yes” answer to the Reality.eth question backed by the required 0.5 ETH bond. 

When no honest party counter-bonded a “no” inside the 12-hour timeout, and the following 8-hour cooldown also passed in silence, the oracle finalized the malicious answer. The Panther governance module then dutifully executed the drain, sweeping roughly 5.12 million ZKP tokens and 0.12 ETH out of the Base contracts.

Panther Foundation contributor Joris_ZKP acknowledged the incident in an August 7 message to the Panther community, saying the team had learned “yesterday” that the Base deployment had been attacked. Importantly, he added that the Base deployment was “not yet in production” and that “no user funds were compromised,” with the loss confined to token supply and a small ETH balance on that specific chain.

How The Attack Actually Worked

Reality.eth is an optimistic oracle used by several DAOs, including Panther, to bring off-chain votes on-chain. Proposals are framed as questions. Answers are posted with an ETH bond, and if nobody counter-bonds the opposite answer inside the challenge window, the last answer wins and the paired governance module executes it. Fast and cheap, but the entire model rests on the assumption that at least one honest watcher is present for every question.

That assumption broke on Base. Panther’s dev team says the protections that automatically disable the Reality.eth module when there is no active DAO proposal, standard on the protocol’s other chains, had never been enabled on the Base deployment. That left a live, hot governance switch sitting on a network the community was not actively monitoring.

The attacker needed three things: a proposal, a 0.5 ETH bond, and silence. All three were available. The 12-hour timeout ran out without a counter-bond, the 8-hour cooldown passed without intervention, and the module then upgraded each ZKP proxy on Base to a drainer implementation, exactly as the proposal specified. The bond was returned to the attacker on finalization, so the effective cost of the exploit was gas.

Panther’s Response

In his community note, Joris_ZKP said the Panther dev team has already restored the affected proxy implementations on Base and that Panther DAO has taken measures to address the Reality.eth configuration on that chain. He added that the equivalent protections on Panther’s other deployments have been reviewed to confirm the same latent gap does not exist elsewhere. A fuller incident report is expected once the internal post-mortem is complete.

The Panther Foundation had not published a separate incident write-up on its official channels at the time of publication. Panther’s main governance flow runs through Snapshot with Reality.eth-based execution modules, and the Base rollout was part of a broader multi-chain expansion for the protocol’s V1 DAO-managed privacy zone.

What On-Chain Data Shows

Defimon’s alert pins the drained value at 5.12 million ZKP, with Panther’s own accounting adding 0.12 ETH lifted from the Base contracts. Priced against ZKP’s pre-incident quote of roughly $0.0025, the token loss carries a nominal value near $17,900, though the realized dollar figure depends entirely on whether any of the drained ZKP ever hits liquid venues. Base-side ZKP liquidity is shallow, and Panther’s mainline ZKP contract on Ethereum sits at 0x909…fa173.

Panther Protocol Price at the time of writing 19:22 IST
Price at the time of writing 19:22 IST Source: CoinGecko

The chart shared alongside the Defimon post shows the localized ZKP quote crashing 78.27% to around $0.000682, though on aggregators tracking the primary Ethereum and Polygon pools, ZKP was still marked around the $0.0025 range with a 24-hour volume near $70,000 and a market cap around $1.49 million against a circulating supply of roughly 430 million tokens. ZKP trades about 99% below its all-time high of $0.4387 hit in March 2022.

Governance Attacks Are Now A Trend, Not An Exception

The Panther incident is the latest in a growing 2026 pattern where the attack surface is not the smart contract’s math but the DAO’s process. On July 6, Solana memecoin governance body BonkDAO lost approximately $20 million in BONK after a malicious proposal quietly passed through a token-weighted vote on Realms, as covered by The Crypto Times. 

In June, Ethereum-based Token of Power (TOP) was drained of roughly $1.58 million after an attacker used a thin-supply governance token to grab more than 50% of voting power on Aragon, mint 10 billion new TOP tokens in one transaction, and dump them into a Balancer V1 pool, per coverage.

What sets the Panther case apart is that the attacker did not need voting power, capital, or social engineering. They needed nobody to be watching. Optimistic governance oracles like Reality.eth are only as safe as their weakest deployment, and the Base version of Panther was, by the team’s own admission, shipped without the module-disable safety net that would have blocked the proposal from ever finalizing.

The pattern also lines up with the wider 2026 security picture. Blockaid’s H1 2026 report tracked 212 on-chain exploits and over $1.1 billion in losses in the first six months of the year, with governance and process failures accounting for a rising share of the incident count even where the dollar totals sit below headline mega-breaches like Drift Protocol’s $285 million key compromise and KelpDAO’s $292 million bridge drain.

Defimon’s own product pitch, which it repeated at the end of the Panther alert, doubles as a comment on the incident: real-time feeds now push protocol-specific attack signals to teams within seconds, with the WebSocket variant priced at $200 a month, but coverage only helps a team that has a live incident-response pipeline hooked into it. Panther, on Base, did not.

For now, ZKP holders on Panther’s mainline Ethereum and Polygon deployments are unaffected, and the drained supply on Base sits with an attacker who has already exposed themselves on-chain. The bigger question, one Panther’s promised incident report will need to answer, is why the missing protection was missing in the first place, and whether the same latent gap has already been ruled out on every other chain the protocol has ever touched.

Also Read: Base Hacker Steals $500K USDC but Loses 74% in Costly Uniswap V4 Swap

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

Hyperliquid Policy Center Urges CFTC to Continue Phased Review of Perpetual Futures
Hyperliquid Policy Center Urges CFTC to Continue Phased Review of Perpetual Futures
Buterin: Pseudonymity Dead Despite Signal Change
Buterin: Pseudonymity Dead Despite Signal Change
ZEC Price Outperforms Bitcoin 17x in Relative Terms Amid Tightening Supply
ZEC Price Outperforms Bitcoin 17x in Relative Terms Amid Tightening Supply
Bitcoin Mining Squeeze Nearly 23% of Major Miners Are Operating at Loss
Bitcoin Mining Squeeze: Nearly 23% of Mainstream Miners Are Operating at Loss
Privacy-First Coldcard Maker Suspends Data Deletion as Legal Proceedings Loom
Privacy-First Coldcard Maker Suspends Data Deletion as Legal Proceedings Loom

Find Us on Socials

You may also like

Hyperliquid Active Traders Hit ATH While Volume Declines

Hyperliquid Active Traders Hit ATH While Volume Declines

Base Hacker Steals $500K USDC but Loses 74% in Costly Uniswap V4 Swap

Base Hacker Steals $500K USDC but Loses 74% in Costly Uniswap V4 Swap

Uniswap Launches Pools.trade Token Launchpad on Robinhood Chain

Uniswap Launches Pools.trade Token Launchpad on Robinhood Chain

Cloudflare Launches Wallets Completing Its Stablecoin Payment Rails for AI Agents

Cloudflare Launches Wallets Completing Its Stablecoin Payment Rails for AI Agents

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information