← Radar

Incident case file

Sign in to watch

Base Wallet Drain via Steakhouse Prime Vault — Attacker Sandwiched by MEV Bot

Incident date 2026-08-05Last updated Aug 14, 2026

2 views

ClosedBasePhishing / wallet compromiseCluster: BASE-DRAIN-2026-08

Estimated loss

$501.7K

Victims identified

1
Victim group joining is coming soon.

Investigation

90%

Facts and investigation

Ledger

Attacker

0x920d3b63541eAFe13E05dc4f3453904102c39708 (on-chain verified)

Funds moved to

501,940.006236 USDC drained from victim's Morpho vault position, sent to attacker 0x920d3b63541eAFe13E05dc4f3453904102c39708. The attacker attempted to convert proceeds to WETH via Uniswap V4 Pool Manager (0xF3A4F4094BD2c6C06cA2F61789d8727B8d1e7259) without slippage protection and was immediately sandwiched by an MEV bot — receiving only 67.92775624932551391 WETH (~$129,426.15), losing approximately $370,000 (roughly 74% of the stolen funds) to the MEV bot's sandwich attack. The MEV bot spent

Linked

Victim wallet: 0x3a5385D8eB0d05B006edFF978BA4b95c51F70B5c, holder of Steakhouse Prime (steakUSDC) Morpho vault shares. Phishing/exploit contract: 0xbeef0e0834849aCC03f0089F01f4F1Eeb06873C9. The drain was executed by burning/redeeming 484,621.998831332675082871 steakUSDC vault shares via the Morpho protocol. The victim publicly offered a 10% bounty on-chain for the return of funds; no return was confirmed as of August 7, 2026.

Chronology

1 beat
  1. T0 (August 6, 2026, 02:29:57 UTC, block 49597025, BaseScan transaction fully verified): Attacker address 0x920d3b63541eAFe13E05dc4f3453904102c39708, operating via exploit/phishing contract 0xbeef0e0834849aCC03f0089F01f4F1Eeb06873C9, drains victim wallet 0x3a5385D8eB0d05B006edFF978BA4b95c51F70B5c of 484,621.998831332675082871 Steakhouse Prime (steakUSDC) Morpho vault shares. The shares are redeemed through the Morpho protocol for 501,940.006236 USDC (approximately $501,650.89), in transaction 0xd2324b49161b53218651eae2852f8684fa68015cfcada94e5c0ad14030fc62ba. T+16 seconds (02:30:13 UTC, block 49597033, second transaction fully verified): The attacker immediately attempts to convert the stolen USDC into WETH via a Uniswap V4 Pool Manager swap (contract 0xF3A4F4094BD2c6C06cA2F61789d8727B8d1e7259) without setting adequate slippage protection, in transaction 0x2e2d82e5667694138ae89330dd9e17dc71ab55f724c4d900f912ea2a94a4b351. An automated MEV (Maximal Extractable Value) bot detects the unprotected transaction sitting in the public mempool and executes a classic sandwich attack around it, capturing the vast majority of the transaction's value. The attacker ultimately receives only 67.92775624932551391 WETH (approximately $129,426.15) — losing roughly 74% (approximately $370,000) of the originally stolen funds to the MEV bot, which incurred only about 3.5 ETH in gas costs to execute the sandwich. Post-incident: Security firm PeckShieldAlert flags the incident publicly 'almost immediately' after it occurs. The original victim posts a public on-chain message identifying the attacker's address and offering a 10% bounty in exchange for voluntary return of the stolen funds. As of August 7, 2026, no funds have been returned to the victim and no arrests or further identification of any party involved (attacker, MEV bot operator, or the original phishing vector used against the victim) have been publicly reported.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)