Panther Protocol says Base governance attack drained 5.12 million ZKP

Panther Protocol said its Base deployment was drained on August 6, 2026 after an attacker used a governance proposal to upgrade ZKP proxy contracts to a drainer implementation through Reality.eth (optimistic oracle for dispute-based execution). The exploit removed roughly 5.12 million ZKP tokens and 0.12 ETH from Base contracts, according to Defimon Alerts and Panther’s own accounting. Panther Foundation contributor Joris_ZKP told the community on August 7 that the Base deployment was not yet in production and that no user funds were compromised, with losses limited to token supply and a small ETH balance on that chain. Panther said a safety feature that disables the Reality.eth module when no DAO proposal is active had not been enabled on Base, allowing the attacker to post a proposal, back a "yes" answer with a 0.5 ETH bond, and let the 12-hour challenge period and 8-hour cooldown expire without a counter-bond. The team said affected proxy implementations on Base have been restored, the chain’s Reality.eth configuration has been addressed, and other deployments have been reviewed. The episode adds to a wider 2026 pattern in which DAO governance and process design, rather than smart contract code alone, have become a growing source of crypto exploits.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.