On October 2, 2026, GoldPesa (GPX) lost roughly $114,900 on Base after an attacker exploited a shared-unlock accounting flaw in GPXHooks, the project's Uniswap v4 hook that manages its protocol-owned liquidity. On-chain monitor Defimon Alerts flagged the single transaction, and a proof-of-concept was published to the DeFiHackLabs repository.
What happened
GPXHooks rebalances GoldPesa's protocol-owned GPX/USDC liquidity inside the hook's beforeSwap() callback once an hour has elapsed since the last rebalance. To do so it calls modifyLiquiditiesWithoutUnlock with a BURN_POSITION followed by TAKE_PAIR. The weakness is that TAKE_PAIR only withdraws the PositionManager's net positive currency delta across whichever PoolManager unlock is currently open — and the hook never verified that its own GPX/USDC deltas were isolated and actually zero before relying on that withdrawal.
The attacker turned that into a drain by seeding a phantom debt. Working inside their own unlock, they minted a WETH/USDC position via MINT_POSITION without settling payment, leaving the shared PositionManager carrying a roughly −114,999 USDC delta. Two small buys on the GPX pool then tripped the hourly rebalance: the hook's BURN_POSITION released a real positive USDC credit, but because TAKE_PAIR nets against the whole open unlock, the credit was swallowed by the attacker's phantom debt and the hook received far less than it should have. The attacker then burned their now debt-free position and pulled 114,999.999186 USDC straight out of the PoolManager, netting about 114,428 USDC after converting to USDT. The vulnerable hook contract was 0x4519e2b040ff1B64fa03aBe2AeF0BC99D7CcEaA8.
Aftermath
GoldPesa did not immediately issue a public post-mortem, and no recovery, white-hat return, or bounty had been announced as of this writing. The stolen USDC was converted on-chain and the funds remained with the exploiter. The loss was confined to GoldPesa's own protocol-owned liquidity; Uniswap v4's core contracts functioned as designed.
Why it matters
GoldPesa is the latest reminder that Uniswap v4 hooks move the accounting risk onto the hook author, not the core protocol — the same lesson as the Bunni rounding drain, where a developer's inverted reasoning about a v4-native liquidity calculation let an attacker withdraw more than they burned. Here the fault was a failure to isolate deltas inside a shared PoolManager unlock, so a crafted phantom debt could cancel a legitimate withdrawal. It also extends a run of early-October 2026 incidents on Base, alongside the FlashLoopAdapter Safe-module drain and the Base wstETH vault whitelist exploit — a cluster that underscores how quickly composable DeFi plumbing on the chain is being probed for accounting and authorization gaps.
Sources & on-chain evidence
- [01]cryptotimes.iohttps://www.cryptotimes.io/2026/10/03/goldpesas-gpxhooks-allegedly-drained-for-114k-in-base-exploit/
- [02]coinfomania.comhttps://coinfomania.com/goldpesatoken-hit-by-114-9k-exploit-loss-as-flaws-revealed/
- [03]github.comhttps://github.com/SunWeb3Sec/DeFiHackLabs/pull/1288
- 0x5c1febd5047c2a15c37988b6abd5c8b984236dddf6fd24eed96b0f43951ad2c9