Base's ETHTrustFund Vanishes With $2.1M After Months of Silence
Another exit scam has hit Base, Coinbase's L2 network — this time courtesy of a project that branded itself, somewhat ironically, ETHTrustFund.
The name promised trust and an ETH-backed fund; what it delivered was a $2.1 million rug pull that left depositors holding nothing. Users had sent ETH directly into the project's treasury, unknowingly financing what would become an exit scam.

The developer behind the project, known only by the handle Peng, spent months cultivating investor confidence and pulling in capital, then went silent for roughly three months before draining the treasury. In hindsight, the setup looks less like a community fund and more like a personal one for its creator.
Credit for surfacing the incident goes to Ogle, Octoshi, and Cointelegraph.
At its peak, ETHTrustFund (ticker ETF) held a treasury worth more than $2 million and marketed itself as an OHM-style rebasing project running on Base. Investors were led to believe the founder was an experienced developer building something legitimate on the new chain.
From the outside, the token's trajectory already looked shaky: after a pump shortly following its March launch, it had fallen more than 90% within a week. Months of stagnant, low-activity trading followed — until the treasury was finally emptied.
Ogle, a crypto investigator from glue.net, was the first to publicly call out the project as a rug pull this past weekend and subsequently filed a report with Chainabuse. Around the same time, the project abruptly relocated its treasury funds to a new wallet.
Community figure Octoshi separately documented a series of suspicious fund transfers alongside the project's sudden dormancy. By that point, Peng had deleted his personal Telegram and Twitter accounts as well as the project's official Telegram, and stopped responding to any messages.
Tracing the stolen funds
The attacker converted all held $BRETT tokens into ETH, then bridged the proceeds from the Base treasury to a fresh wallet on Ethereum mainnet.
- ETHTrustFund deployer address: 0xF259F01C40C211D63Ab75A6d2B108B364EFaB780
- Treasury address: 0xbfDB66a6783a6Dc757f539139c68BED75EB491c8
- Bad actor's address: 0x374f4BD39aD211e67e0f8Cb8Ebf1b4F6Ac3059aD
Theft transactions:
- 3.2 million BRETT, worth roughly $453,000, was stolen on July 20 (transaction).
- Approximately 9.5 hours later, 477 ETH — around $1.65 million — was stolen on July 21 (transaction).
From there, the bad actor moved 200 ETH into Railgun (transaction), then routed another 200 ETH to Tornado Cash across two separate transactions (tx 1, tx 2). A further 56.9 ETH was subsequently funneled back into Railgun (transaction).

As affected users tried to figure out who to hold accountable, Peng had already disappeared. Social accounts were deleted, the project website went offline, and even the project's documentation — briefly still accessible — was eventually taken down too. Every indicator points to a standard rug pull / exit scam playbook, with Base serving as an unwitting venue.
Before disappearing, ETHTrustFund had marketed itself as a DAO built on OHM's rebasing model, issuing on-chain bonds and offering a rebase mechanism to stakers. Its own materials claimed it was the "Highest Return Yielding ETF On Earth," promising that the fund would eventually "debase," or burn, its own tokens to boost the value of what remained — with all deposited assets supposedly generating yield along the way.
In the end, that entire structure appears to have been cover for a scheme benefiting only its creator. Octoshi has asked anyone affected to reach out to him on X, noting his DMs remain open for anyone needing help or wanting to share information.
ETHTrustFund is not the first project on Base to end this way: BALD rugged for $23 million shortly after Base's launch, and three weeks after that, Magnate Finance rugged for $6.5 million.
As Base keeps drawing in new projects and capital, it's increasingly earning a reputation for something else entirely — a pattern of scams playing out at speed across the network. From BALD to ETHTrustFund, the chain is building a track record as a favored hunting ground for opportunists, even as Coinbase continues to promote it as a pillar of DeFi's future. With investigators like Ogle actively tracking the perpetrator, there's at least a chance the scammer gets caught before the next one shows up — though in a landscape this crowded with bad actors, it may just be one round in an ongoing game of whack-a-mole.
Get new scam files the moment we publish them — usually 2–3 emails a week.