GoldPesa's GPXHooks Contract on Base Allegedly Exploited for $114,000
GoldPesa's GPXHooks contract on Base was allegedly exploited for about $114,000, according to Defimon Alerts, a security monitoring account. The attacker reportedly borrowed 175,000 USDC from Morpho before creating an unpaid WETH/USDC position. Defimon said the attacker triggered GoldPesa's liquidity rebalance, causing funds from the protocol's position to offset the attacker's outstanding debt.
The incident occurred on October 2, 2026, at 1:05:51 PM UTC, and the transaction hash is 0x5c1febd5047c2a15c37988b6abd5c8b984236dddf6fd24eed96b0f43951ad2c9. Defimon identified GoldPesa's GPXHooks contract as the vulnerable contract involved in the incident. The monitoring account said the attacker used a borrowed USDC position and triggered the hook's rebalance function, allowing funds from GoldPesa's liquidity position to offset the unpaid position.
The GPXHooks contract's rebalancing process interacted with outstanding balances in the PositionManager, causing the issue, according to Defimon. The attacker then burned the position to withdraw roughly 115,000 USDC, repaid the Morpho loan, and converted the remaining funds into USDT. The USDT was subsequently bridged to Solana and then BNB Chain.