Incident case file
Sign in to watchBase Wallet Drain via Steakhouse Prime Vault — Attacker Sandwiched by MEV Bot
2 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatT0 (August 6, 2026, 02:29:57 UTC, block 49597025, BaseScan transaction fully verified): Attacker address 0x920d3b63541eAFe13E05dc4f3453904102c39708, operating via exploit/phishing contract 0xbeef0e0834849aCC03f0089F01f4F1Eeb06873C9, drains victim wallet 0x3a5385D8eB0d05B006edFF978BA4b95c51F70B5c of 484,621.998831332675082871 Steakhouse Prime (steakUSDC) Morpho vault shares. The shares are redeemed through the Morpho protocol for 501,940.006236 USDC (approximately $501,650.89), in transaction 0xd2324b49161b53218651eae2852f8684fa68015cfcada94e5c0ad14030fc62ba. T+16 seconds (02:30:13 UTC, block 49597033, second transaction fully verified): The attacker immediately attempts to convert the stolen USDC into WETH via a Uniswap V4 Pool Manager swap (contract 0xF3A4F4094BD2c6C06cA2F61789d8727B8d1e7259) without setting adequate slippage protection, in transaction 0x2e2d82e5667694138ae89330dd9e17dc71ab55f724c4d900f912ea2a94a4b351. An automated MEV (Maximal Extractable Value) bot detects the unprotected transaction sitting in the public mempool and executes a classic sandwich attack around it, capturing the vast majority of the transaction's value. The attacker ultimately receives only 67.92775624932551391 WETH (approximately $129,426.15) — losing roughly 74% (approximately $370,000) of the originally stolen funds to the MEV bot, which incurred only about 3.5 ETH in gas costs to execute the sandwich. Post-incident: Security firm PeckShieldAlert flags the incident publicly 'almost immediately' after it occurs. The original victim posts a public on-chain message identifying the attacker's address and offering a 10% bounty in exchange for voluntary return of the stolen funds. As of August 7, 2026, no funds have been returned to the victim and no arrests or further identification of any party involved (attacker, MEV bot operator, or the original phishing vector used against the victim) have been publicly reported.
Sources and coverage
- Articlecoinpedia.orghttps://coinpedia.org/crypto-live-news/base-attacker-loses-funds-to-mev-bot-after-500000-wallet-drain/
- Articlevaluethemarkets.comhttps://www.valuethemarkets.com/cryptocurrency/news/the-irony-of-a-thief-being-robbed-insights-into-acrypto-heist
- Articlebasescan.orghttps://basescan.org/tx/0xd2324b49161b53218651eae2852f8684fa68015cfcada94e5c0ad14030fc62ba
- Articlebasescan.orghttps://basescan.org/tx/0x2e2d82e5667694138ae89330dd9e17dc71ab55f724c4d900f912ea2a94a4b351
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)