Panther Protocol's Base Network Drained in Governance Attack via Reality.eth Oracle
On August 6, 2026, Panther Protocol's Base network deployment was drained in a textbook governance attack. The attacker submitted a proposal titled 'zkp-reexploit' that would upgrade each ZKP proxy on Base to a drainer implementation.
The Reality.eth optimistic oracle played a crucial role in the attack. Proposals are framed as questions, and answers are posted with an ETH bond. If nobody counter-bonds the opposite answer within the 12-hour timeout, the last answer wins and the paired governance module executes it.
However, Panther's Base deployment lacked a critical protection that automatically disables the Reality.eth module when there is no active DAO proposal. This left a live, hot governance switch sitting on an unmonitored network.
The attacker needed only three things: a proposal, a 0.5 ETH bond, and silence. The 12-hour timeout ran out without a counter-bond, the 8-hour cooldown passed without intervention, and the module then upgraded each ZKP proxy on Base to a drainer implementation, draining roughly 5.12 million ZKP tokens and 0.12 ETH.