Incident case file
Sign in to watchPanther Protocol Base Deployment — Reality.eth Governance Drain
4 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatBackground: Panther Protocol's Base deployment used Reality.eth as an optimistic governance oracle to authorize and execute approved proposals. A security safeguard designed specifically to disable the Reality.eth module whenever no active governance proposal existed had not been enabled on this particular Base deployment, unlike Panther's other network deployments. T-X: An attacker submits a governance proposal titled 'zkp-reexploit' to Panther's Base governance system. If executed, the proposal would upgrade every ZKP token proxy contract on Base to a malicious 'drainer' implementation. T0: The attacker posts a 'yes' answer to the corresponding Reality.eth question, backing it with the required 0.5 ETH bond. Per Reality.eth's optimistic dispute-resolution design, any honest party could submit a counter-bonded 'no' answer within a 12-hour timeout window to block the proposal; no such challenge is submitted, and the following 8-hour cooldown period also passes without incident. The Reality.eth oracle finalizes the malicious 'yes' answer as the accepted outcome. T+ (August 6, 2026, block 49625963): Panther's governance module automatically executes the now-approved contract upgrade, and the resulting drainer implementation sweeps 5,124,773.626006184526790998 ZKP plus 0.123291500437368375 ETH from source contract 0x9400161d512C740e1C0C77f3c931D112f068210c to the attacker's wallet, 0x7dB4cFea07042ca13a8E26cC90BbB59982Fe95B6. The localized ZKP token price on Base immediately crashes approximately 78.27%, falling to around $0.000682, while the token's price on aggregated Ethereum and Polygon markets remains comparatively stable near $0.0025. The attacker attempts to liquidate the stolen ZKP through KyberSwap's Meta Aggregation Router v2, executing several swaps (2,124,773.63 ZKP plus three separate lots of 1,000,000 ZKP each) which are batched alongside unrelated third-party trades captured in the same aggregation transaction. Owing to the token's collapsed price, the attacker ultimately realizes only 0.175689831779555614 ETH — approximately $337.12 — a small fraction of the roughly $14,313 face value the stolen tokens carried at the moment of the sweep. Later on August 6 or into August 7: Security monitoring firm Defimon Alerts (operated by Decurity) becomes the first to publicly flag the incident. August 7, 2026, 12:36 PM: Panther Foundation contributor Joris_ZKP formally confirms the incident to the Panther community via the project's Discord server, stating explicitly: 'The Base deployment was not yet in production. No user funds were compromised... The dev team has restored the affected proxy implementations... The attack was possible because protections designed to disable the Reality.eth module when there is no active governance proposal had not been enabled on the Base deployment... Panther DAO has taken measures to address the Reality.eth configuration on Base.' Notably, this incident was not identified by any of nine independent AI research systems separately tasked with surveying the week's crypto-security news; it was discovered only through direct, manual on-chain investigation conducted after the initial multi-AI research pass was complete.
Sources and coverage
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/08/07/panther-protocol-hit-by-governance-attack-5-12m-zkp-drained-on-base/
- Articlebasescan.orghttps://basescan.org/tx/0xead22569665b4749709c069271e21f437bc99869fd94f23a6479c0d110fe332d
- Articlebasescan.orghttps://basescan.org/tx/0x970293aef7884ed8b10f08ab2aade06e6a288ee0717bc57bfb41304250bfac4d
- Articlebasescan.orghttps://basescan.org/token/0x0a776c1c22b8b8e7eab346744daa33722b80fda4
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)