GoldPesa exploit — $115k lost on Base
GoldPesa lost an estimated $115k on Base (incorrect share accounting), according to the DeFiLlama hacks database. Users and integrators should review exposure and follow the project's official channels.
Vuln-watch · relayed from the DeFiLlama hacks database; see Source & attribution below
Summary
GoldPesa lost an estimated $115k on Base (incorrect share accounting), according to the DeFiLlama hacks database. Users and integrators should review exposure and follow the project's official channels.
Incident
- Protocol: GoldPesa
- Date (UTC): 2026-10-02
- Estimated loss: $115k
- Chain(s): Base
- Technique: Incorrect Share Accounting
- Classification: Token & Share Accounting
- Target: DeFi Protocol
Recommended actions
- Revoke token approvals granted to GoldPesa contracts until the project confirms they are safe
- Integrators: pause or delist affected assets and monitor for attacker fund movements
- Beware of follow-on phishing: ignore unofficial "refund", "recovery", or "claim" links and DMs; use the project's verified channels only
Source & attribution
This 0xCERT advisory relays an incident recorded in the DeFiLlama hacks database (https://defillama.com/hacks). Figures are preliminary estimates and may be revised; refer to the project's own post-mortem for the authoritative record. Report additional details to 0xCERT at https://www.0xcert.com/report.
Indicators of compromise
All IOC feeds →- tx0x5c1febd5047c2a15c37988b6abd5c8b984236dddf6fd24eed96b0f43951ad2c9Exploit transaction · Base
OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.
Published 2026-10-02 · last updated 2026-10-08
curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0153/signed.txt | gpg --verify