← Radar

Incident case file

Sign in to watch

Panther Protocol Base Deployment — Reality.eth Governance Drain

Incident date 2026-08-05Last updated Aug 14, 2026

4 views

ResolvedBaseGovernance attack (optimistic oracle)Cluster: PANTHER-GOV-2026-08

Estimated loss

$14.3K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

100%

Facts and investigation

Ledger

Attacker

0x7dB4cFea07042ca13a8E26cC90BbB59982Fe95B6 (on-chain verified)

Funds moved to

5,124,773.626006184526790998 ZKP + 0.123291500437368375 ETH swept from contract 0x9400161d512C740e1C0C77f3c931D112f068210c to attacker 0x7dB4cFea07042ca13a8E26cC90BbB59982Fe95B6 (transaction 0xead22569665b4749709c069271e21f437bc99869fd94f23a6479c0d110fe332d, block 49625963, fully verified). The attacker swapped ZKP in multiple lots via KyberSwap Meta Aggregation Router v2 (transaction 0x970293aef7884ed8b10f08ab2aade06e6a288ee0717bc57bfb41304250bfac4d, fully verified), realizing only 0.1756898317

Linked

Panther's ZKP token contract on Base: 0x0a776c1c22b8b8e7eab346744daa33722b80fda4 (confirmed on BaseScan as 'Panther Protocol: ZKP Token'). Panther's mainline ZKP contract on Ethereum (0x909e34d3f6124c324ac83dcca84b74398a6fa173) and its Polygon deployment were unaffected by this incident. The malicious Reality.eth governance proposal, titled 'zkp-reexploit,' was backed by a 0.5 ETH bond; no honest party submitted a counter-bond within the required 12-hour challenge window plus 8-hour cooldown per

Chronology

1 beat
  1. Background: Panther Protocol's Base deployment used Reality.eth as an optimistic governance oracle to authorize and execute approved proposals. A security safeguard designed specifically to disable the Reality.eth module whenever no active governance proposal existed had not been enabled on this particular Base deployment, unlike Panther's other network deployments. T-X: An attacker submits a governance proposal titled 'zkp-reexploit' to Panther's Base governance system. If executed, the proposal would upgrade every ZKP token proxy contract on Base to a malicious 'drainer' implementation. T0: The attacker posts a 'yes' answer to the corresponding Reality.eth question, backing it with the required 0.5 ETH bond. Per Reality.eth's optimistic dispute-resolution design, any honest party could submit a counter-bonded 'no' answer within a 12-hour timeout window to block the proposal; no such challenge is submitted, and the following 8-hour cooldown period also passes without incident. The Reality.eth oracle finalizes the malicious 'yes' answer as the accepted outcome. T+ (August 6, 2026, block 49625963): Panther's governance module automatically executes the now-approved contract upgrade, and the resulting drainer implementation sweeps 5,124,773.626006184526790998 ZKP plus 0.123291500437368375 ETH from source contract 0x9400161d512C740e1C0C77f3c931D112f068210c to the attacker's wallet, 0x7dB4cFea07042ca13a8E26cC90BbB59982Fe95B6. The localized ZKP token price on Base immediately crashes approximately 78.27%, falling to around $0.000682, while the token's price on aggregated Ethereum and Polygon markets remains comparatively stable near $0.0025. The attacker attempts to liquidate the stolen ZKP through KyberSwap's Meta Aggregation Router v2, executing several swaps (2,124,773.63 ZKP plus three separate lots of 1,000,000 ZKP each) which are batched alongside unrelated third-party trades captured in the same aggregation transaction. Owing to the token's collapsed price, the attacker ultimately realizes only 0.175689831779555614 ETH — approximately $337.12 — a small fraction of the roughly $14,313 face value the stolen tokens carried at the moment of the sweep. Later on August 6 or into August 7: Security monitoring firm Defimon Alerts (operated by Decurity) becomes the first to publicly flag the incident. August 7, 2026, 12:36 PM: Panther Foundation contributor Joris_ZKP formally confirms the incident to the Panther community via the project's Discord server, stating explicitly: 'The Base deployment was not yet in production. No user funds were compromised... The dev team has restored the affected proxy implementations... The attack was possible because protections designed to disable the Reality.eth module when there is no active governance proposal had not been enabled on the Base deployment... Panther DAO has taken measures to address the Reality.eth configuration on Base.' Notably, this incident was not identified by any of nine independent AI research systems separately tasked with surveying the week's crypto-security news; it was discovered only through direct, manual on-chain investigation conducted after the initial multi-AI research pass was complete.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)