Key Highlights
- GoldPesa’s GPXHooks contract on Base was allegedly exploited for about $114,000, according to security monitoring account Defimon Alerts.
- The attacker reportedly borrowed 175,000 USDC from Morpho before creating an unpaid WETH/USDC position.
- Defimon said the attacker triggered GoldPesa’s liquidity rebalance, causing funds from the protocol’s position to offset the attacker’s outstanding debt.
GoldPesa’s GPXHooks contract on Base was allegedly exploited after an attacker used a flaw in its liquidity-rebalancing process, according to DeFi security monitoring account Defimon Alerts.
In an October 3 post on X, Defimon described the incident as a logic error involving GoldPesa’s Uniswap v4 hook and its liquidity-rebalancing process.
The monitoring account said the attacker used a borrowed USDC position and triggered the hook’s rebalance function, allowing funds from GoldPesa’s liquidity position to offset the unpaid position.
The Crypto Times has reached out to GoldPesa for comments on the exploit and will update the story if a response is received.
How the GoldPesa exploit worked
According to Defimon, the attacker first borrowed 175,000 USDC from Morpho.
The attacker then created a WETH/USDC liquidity position through the PositionManager while leaving roughly 115,000 USDC in outstanding obligations, according to Defimon.
The attacker then interacted with the GPX pool, triggering the GPXHooks contract’s rebalancing process, Defimon said.
Defimon said the hook burned its own liquidity position and received about 148,900 USDC. However, because the PositionManager nets outstanding balances during the same PoolManager transaction, the hook’s funds were used to offset the attacker’s unpaid position.
As a result, the hook allegedly received only about 33,900 USDC, with the remaining funds effectively covering the attacker’s outstanding position.
Defimon summarized the mechanism by saying that, in effect, the hook paid for the attacker’s position.

Transaction linked to the GoldPesa GPXHooks exploit | Source: BaseScan
Funds moved across multiple networks
Defimon said the attacker then burned the position to withdraw roughly 115,000 USDC, repaid the Morpho loan and converted the remaining funds into USDT.
The monitoring account said the USDT was subsequently bridged to Solana and then BNB Chain. Defimon identified a BNB Chain address where it said the funds were later moved.
The transaction identified by Defimon was confirmed on Base on October 2, 2026, at 1:05:51 PM UTC, according to the attached BaseScan transaction record.
The transaction hash is:
0x5c1febd5047c2a15c37988b6abd5c8b984236dddf6fd24eed96b0f43951ad2c9
Defimon also identified an address it attributed to the attacker.
GPXHooks contract linked to the exploit
Defimon identified GoldPesa’s GPXHooks contract as the vulnerable contract involved in the incident.
BaseScan identifies the contract as GPXHooks and shows functions including beforeSwap, afterSwap, liquidity-management functions and an unlockCallback used during PoolManager operations. The contract source also includes a Rebalanced event associated with its liquidity-rebalancing process.
The GPXHooks contract address identified by Defimon is:
0x4519e2b040ff1B64fa03aBe2AeF0BC99D7CcEaA8
According to Defimon, the issue stemmed from the way the hook’s rebalance process interacted with outstanding balances in the PositionManager.
Other recent exploits on Base
The incident follows other exploits involving projects on Base.
On August 27, 2026, Moonwell lost nearly $8.7 million in an exploit involving manipulation of the MAMO token’s price. The earlier report noted that the attack did not involve a direct breach of Moonwell’s smart contracts. Instead, the attack exploited thin liquidity in the MAMO market and the protocol’s reliance on price oracles that could be influenced by trading activity.
More recently, on October 2, 2026, a separate exploit involving the FlashLoopAdapter drained about $305,000 from two Aave-linked Safes. The incident involved a custom Safe module used for Aave V3 leveraged positions and an access-control flaw that allowed collateral to be withdrawn from two affected wallets.
These incidents involved different attack mechanisms and are not reported as being connected to the GoldPesa exploit. Defimon’s October 3 post did not include a statement from GoldPesa on the alleged exploit.
Also Read: NEAR Intents Ends Exploit Probe After $3.8 Million Is Returned
