CryptoReal
CASE FILE — Apr 15, 2024

Leaked Deployer Key Lets Attacker Mint and Dump $2M in GB Tokens on Base

Grand Base, a real-world-asset (RWA) protocol built on Base, suffered a roughly $2 million exploit after the private key to its deployer wallet was compromised.

A protocol administrator first disclosed the breach in the Grand Base Telegram channel, telling users the token contract could no longer be considered safe and urging them to stop all swaps or interactions with it and to withdraw funds from any related liquidity pools immediately. PeckShield was the first to flag the exploit publicly. Roughly six hours later, Grand Base's team posted a follow-up on X stating they had traced the attacker's wallets and were coordinating with centralized exchanges to try to freeze any funds the attacker attempted to move.

This is not Base's first security incident. Shortly after launch in August, the memecoin BALD left holders with losses of $23 million in what was widely characterized as a rug pull. Less than two weeks later, RocketSwap was compromised for $869,000, reportedly after its server's private keys were obtained through a bruteforce attack. Since those early incidents, however, Base's total value locked has grown to roughly $1.5 billion, currently placing it sixth among all chains by that metric. Credit for exploit details: Grand Base, De.Fi, PeckShield.

Mechanism of the exploit

In the early hours of April 15, at approximately 3:00 AM UTC, GB — the token issued by Grand Base — underwent a sharp price collapse, falling more than 90%. The cause was a security breach of the project's deployer wallet, which the attacker used to mint and sell approximately 32.5 million GB tokens. This was a substantial addition relative to the token's previous maximum supply cap of 50 million GB.

The minting was carried out across two transactions:

Transaction 1: https://basescan.org/tx/0xe8b0af9a2c7a3482958792d620328aa780097788fc18e1b7e1328a4a459132d0

Transaction 2: https://basescan.org/tx/0x74237dfd7ac0e251311c71ff2c2536b146eeb68c465d47325bdd4517f34a7259

The attacker then executed a series of swaps to convert the minted tokens into ETH, using this address: https://basescan.org/address/0xcfe5f1bae0da05ffe9c9c73411b8ec1a286350fc

Sums referenced in this case file

The resulting ETH on Base was subsequently bridged to Ethereum mainnet in two transfers:

Transfer 1: https://basescan.org/tx/0x519acbeb333fd43dead8bc66faa4d419d310d6bf8011a056ce279d26845da70d

Transfer 2: https://basescan.org/tx/0x66334af4901b7d4e5e536c17fee41431aee3bde03c6da823d4d9dd5adc43aa92

The stolen funds currently sit in two wallets:

Wallet 1: https://debank.com/profile/0xd8c21702b74d14b68f2580e28c10ecc53304c274

Wallet 2: https://debank.com/profile/0xb124546f9f89f178a785d539d299e372b9dc1ec6

Root cause: a compromised developer machine

Grand Base's CTO provided additional detail via a Telegram post, explaining that a developer's PC had been hacked. That PC had access to the LP wallet, which controlled both the token contract and the liquidity pool and also held minting authority — authority the attacker used to create new tokens before dumping them on the market.

The CTO maintained that the underlying dapp code itself remains secure and can safely be forked, stating the team has thorough knowledge of every line of the codebase. Even so, the GB token will need to be relaunched as a result of the exploit. Separately, the project's documentation — which states that contract details will be published soon — reportedly has not been updated in roughly six months, and the team's contracts do not appear to have undergone any security audit.

Response and communication concerns

Grand Base did notify its Telegram community about the exploit relatively promptly, but the wait of roughly six hours before an announcement was made on X raises questions about the team's communication practices during a security incident — particularly given how much trust in a project can hinge on transparency when something goes wrong. The absence of any published audit or up-to-date contract documentation adds to concerns about the protocol's security posture going forward. Whether Grand Base tightens its practices after this incident, or repeats the same gaps, will likely shape how much confidence users place in the project going forward.

Grand Base
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.