GoldPesa Loses $114K in Uniswap V4 Hook Exploit
GoldPesa, a project operating on the Base blockchain, suffered a significant security breach that resulted in the loss of approximately $114,000 in assets. The incident, reported by Defimon Alerts on October 3, 2026, involved the exploitation of a logic error in the project's custom hooks for Uniswap v4. The attack occurred on October 2 and targeted the protocol's own liquidity in the GPX/USDC pool.
The attack leveraged a combination of Uniswap v4's hooks and flash accounting mechanisms. GoldPesa used GPXHooks to automatically rebalance its liquidity positions. Attackers borrowed 175,000 USDC through a flash loan from Morpho, created a WETH/USDC liquidity position without paying the required USDC, and then triggered a rebalance in the GPX pool. This caused GPXHooks to cover the attacker's debt, effectively allowing the attacker to withdraw approximately 115,000 USDC.
According to Oculr's analysis, the attacker then converted the stolen USDC into USDT through a thin Uniswap v3 pool and transferred the funds across multiple blockchains, including Solana and BNB Smart Chain, to obscure the trail. The incident highlights the risks associated with custom hooks in DeFi protocols, as the vulnerability stemmed from GoldPesa's implementation rather than a flaw in Uniswap v4 itself.
As of the time of reporting, GoldPesa had not issued an official statement regarding the incident. The event underscores the importance of rigorous smart contract audits and the potential dangers of complex DeFi mechanisms.