{"investigation":{"slug":"grand-base","entity_name":"Grand Base","trust_score":5,"severity_base":null,"score_modifier":0,"confidence":0.85,"status":"published","content_type":"investigation","summary":"Grand Base was a decentralized real-world asset (RWA) synthetic trading protocol launched on Coinbase's Base layer-2 blockchain in early 2024. On April 15, 2024, the protocol suffered a critical security incident in which its deployer wallet was compromised, allowing an attacker to mint approximately 32.5 million unauthorized GB tokens and drain roughly $2 million in liquidity. The GB token subsequently lost over 99% of its value; no verified recovery or compensation plan has been confirmed, and the project's long-term operational status remains uncertain.","sections":[{"content":"On April 15, 2024, at approximately 03:01 AM UTC, Grand Base experienced a critical exploit on the Base chain. A threat actor obtained access to the protocol's deployer wallet and used administrative minting privileges to create approximately 32.5 million GB tokens without authorization — pushing total supply close to and beyond the stated 50 million token cap. The attacker then executed over 600 swap transactions on the Aerodrome decentralized exchange to convert the minted tokens into ETH, and subsequently bridged those funds from the Base chain to Ethereum mainnet. Final losses were reported at approximately $2 million (615–808 ETH depending on source; estimates varied between $1.7M and $2.5M across outlets). The native GB token collapsed by more than 99% in market value within hours of the exploit becoming public.","heading":"Incident Overview","sources":[{"url":"https://rekt.news/grand-base","name":"rekt.news","type":"other","credibility":3},{"url":"https://beincrypto.com/defi-protocol-grand-base-hacked/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/base-asset-tokenization-protocol-compromised","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/single/grand-base-theft","name":"web3isgoinggreat.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The root cause of the exploit was a private key compromise of Grand Base's deployer wallet address (0x0f8ae8baa610d8877944a3ef85c47c656d02f867). According to the project's CTO, a developer's personal computer was hacked, and the LP wallet — which held administrative control over the token contract and liquidity pool — was accessible from that machine. Upon gaining control of the deployer, the attacker minted unauthorized GB tokens and sold them in rapid succession. Blockchain analytics firm CertiK confirmed unauthorized minting through the deployer contract, while PeckShield separately tracked the conversion and transfer of stolen assets to ETH. Following the swaps on Aerodrome, the attacker bridged the ETH to Ethereum mainnet and distributed funds across six known wallet addresses: 0xf8f598d2480500De1BeDDD746E91F34021293467, 0x13E1aEb0FC5Dbc5a2061874f1435Cfa314860F84, 0xC77C9450625444F371A7d49Def616bde7Cd58e6d, 0xB124546F9f89F178a785D539d299E372B9dc1eC6, 0xd8C21702B74d14b68f2580E28c10Ecc53304c274, and 0x6cc134F6161b39d0496d18A0C5A1d0501d8abaBF. At the time of reporting, approximately 808.57 ETH (roughly $2.49M) was consolidated in an EOA. A CoinGecko analysis noted a critical smart contract design flaw: the contract permitted developers to mint unlimited new tokens with no on-chain restrictions, which made the exploit possible regardless of whether the private key was stolen or misused internally.","heading":"Attack Mechanism and Technical Details","sources":[{"url":"https://rekt.news/grand-base","name":"rekt.news","type":"other","credibility":3},{"url":"https://beincrypto.com/defi-protocol-grand-base-hacked/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://www.quadrigainitiative.com/hackfraudscam/grandbaseprivatekeyleak.php","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://crypto.news/grand-base-minting-sparks-rug-pull-concerns-as-token-plunges-99/","name":"crypto.news","type":"other","credibility":3},{"url":"https://medium.com/neptune-mutual/understanding-the-grand-base-exploit-82a1ead971dc","name":"medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The nature of the incident — unauthorized token minting via a privileged deployer key — prompted significant community speculation about whether the event constituted a rug pull rather than an external hack. Community member @0xkinnif was among the first to flag the suspicious minting activity on social media. The Grand Base team maintained that the deployer wallet was compromised by an external attacker via a hacked developer PC, and characterized the incident as a hack rather than an exit scam. However, the absence of any public smart contract audit, the unlimited minting capability embedded in the contract design, and the approximately 6-hour delay between the initial community alerts and the team's public announcement on X (formerly Twitter) drew criticism. No independent audit has been identified that would have caught or prevented the unlimited minting vulnerability prior to launch. These factors collectively sustained community skepticism about the team's characterization of the incident.","heading":"Rug Pull Allegations and Community Concerns","sources":[{"url":"https://crypto.news/grand-base-minting-sparks-rug-pull-concerns-as-token-plunges-99/","name":"crypto.news","type":"other","credibility":3},{"url":"https://rekt.news/grand-base","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/single/grand-base-theft","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://bsc.news/post/grand-base-protocol-reportedly-exploited-for-2-m-exploit-what-we-know","name":"bsc.news","type":"other","credibility":3}],"severity":"medium"},{"content":"No independent smart contract audit has been publicly identified for Grand Base prior to the April 2024 exploit. The Rekt News post-mortem noted that no security audits were found for the protocol at the time of the incident, and that contract documentation had not been updated in approximately six months. The CoinGecko analysis highlighted that the contract's architecture gave developers unrestricted minting authority with no on-chain safeguards — a design choice that, regardless of exploit vector, represents a fundamental security risk for token holders. The Cyvers security team commented that the compromised deployer wallet losing access control underscores the urgency for heightened security protocols in DeFi projects, particularly those handling tokenized real-world assets. The team stated post-incident that a relaunch with audited smart contracts was planned, but no audit report has been publicly confirmed.","heading":"Security Posture and Audit Findings","sources":[{"url":"https://rekt.news/grand-base","name":"rekt.news","type":"other","credibility":3},{"url":"https://beincrypto.com/defi-protocol-grand-base-hacked/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://crypto.news/grand-base-minting-sparks-rug-pull-concerns-as-token-plunges-99/","name":"crypto.news","type":"other","credibility":3}],"severity":"medium"},{"content":"The Grand Base team first disclosed the incident through its official Telegram channel, where an administrator warned users: 'this token contract is NOT safe anymore and you should NOT swap or interact with it, stay safe.' The team's announcement on X followed approximately 6 hours after community members had already raised alarms on social media. The project's CTO provided an explanation attributing the incident to a hacked developer machine. Post-incident, the team stated they had tracked all hacker wallet addresses, were monitoring fund movements, were in contact with centralized exchange (CEX) security teams to freeze any off-ramping attempts, and planned to blacklist attacker addresses including those used through mixers. MEXC exchange was specifically named as a partner in halting trading of exploited tokens. The team indicated plans to relaunch the protocol with audited contracts and provide retroactive token airdrops to affected holders. No verified evidence of a completed relaunch, compensation distribution, or fund recovery has been identified in subsequent reporting.","heading":"Team Response and Communications","sources":[{"url":"https://rekt.news/grand-base","name":"rekt.news","type":"other","credibility":3},{"url":"https://beincrypto.com/defi-protocol-grand-base-hacked/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://crypto.news/grand-base-minting-sparks-rug-pull-concerns-as-token-plunges-99/","name":"crypto.news","type":"other","credibility":3},{"url":"https://www.quadrigainitiative.com/hackfraudscam/grandbaseprivatekeyleak.php","name":"quadrigainitiative.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The GB token experienced a catastrophic decline of more than 99% in market value following the exploit. Prior to the incident, Grand Base had generated millions of dollars in daily trading volume as an emerging RWA synthetic asset protocol on Base. Post-exploit, the token's price fell to approximately $0.0049. The incident also contributed to a broader trend: data reported by Coinspeaker showed crypto thefts on Coinbase's Base chain rose by 145% in April 2024, with the Grand Base exploit as a notable contributor. The protocol's liquidity pools were effectively emptied. At the time of writing, no credible evidence of sustained trading activity or a functional relaunch of the Grand Base protocol has been identified.","heading":"Market Impact","sources":[{"url":"https://coingape.com/grand-base-token-gb-price-plummets-99-after-2m-hack/amp/","name":"coingape.com","type":"other","credibility":3},{"url":"https://crypto.news/base-hack-defi-network/","name":"crypto.news","type":"other","credibility":3},{"url":"https://www.coinspeaker.com/crypto-thefts-coinbase-base-april/","name":"coinspeaker.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Blockchain investigator ZachXBT flagged Grand Base in connection with the April 2024 exploit. While ZachXBT's primary documented investigations during the same period focused on a separate ring of DeFi rug pulls on Base (including Magnate, Kokomo, and Solfire), Grand Base was noted within the broader context of suspicious activity on the Base chain. The specific content and scope of ZachXBT's Grand Base flag has not been independently verified through a primary public post as of this writing. The flagging is treated as alleged pending direct sourcing of a ZachXBT primary statement specific to Grand Base.","heading":"ZachXBT Flagging","sources":[{"url":"https://www.cryptometer.io/news/zachxbt-exposes-scam-ring-behind-multiple-defi-rug-pulls/","name":"cryptometer.io","type":"other","credibility":3},{"url":"https://coinpaper.com/3930/fraudsters-target-new-victims-with-millions-in-laundered-crypto","name":"coinpaper.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Grand Base was introduced as a decentralized marketplace for spot synthetic real-world assets (RWAs) on Coinbase's Base layer-2 blockchain. The platform allowed users to mint and trade 'gAssets' — ERC-20 tokens pegged to the value of publicly traded companies (Amazon, Apple, Google, Meta, Microsoft) and commodities (Gold, Oil, Uranium) — using USDC as collateral. The protocol launched in Q1 2024 following a testnet phase beginning in late 2023. Its native token, GB, was used for governance and platform participation. The project maintained official presence at grandbase.io, on X (@grandbase_fi), Discord, and Medium. No founders or core team members have been publicly identified by name in available reporting. The protocol's documentation and social media activity were last substantively updated in April 2024 around the time of the exploit.","heading":"Project Background","sources":[{"url":"https://medium.com/@grand.base/introducing-grand-base-925cb2ecc713","name":"medium.com","type":"other","credibility":3},{"url":"https://docs.grandbase.io/","name":"docs.grandbase.io","type":"other","credibility":3},{"url":"https://rekt.news/grand-base","name":"rekt.news","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023-12-08","event":"Grand Base publishes community update on token distribution, delaying team token vesting and revising minting schedule from 10 million to 3.9 million GB tokens.","source":""},{"date":"2024","event":"Grand Base opens testnet on Base chain per roadmap, with full mainnet launch targeted for Q1 2024.","source":"","date_original":"2024-01-01"},{"date":"2024-04-15","event":"At approximately 03:01 AM UTC, the Grand Base deployer wallet is compromised. The attacker mints approximately 32.5 million unauthorized GB tokens and executes over 600 swaps on Aerodrome to convert them to ETH, draining approximately $2 million in liquidity.","source":""},{"date":"2024-04-15","event":"Community member @0xkinnif flags the suspicious minting activity on social media. PeckShield and CertiK issue security alerts. The Grand Base Telegram admin warns users not to interact with the token contract.","source":""},{"date":"2024-04-15","event":"Approximately 6 hours after community alerts, Grand Base posts an announcement on X acknowledging the exploit, attributing it to a hacked developer PC compromising the LP wallet.","source":""},{"date":"2024-04-15","event":"Stolen ETH is bridged from Base chain to Ethereum mainnet and distributed across six known attacker wallet addresses. Approximately 808.57 ETH (~$2.49M) is consolidated in an EOA.","source":""},{"date":"2024-04-15","event":"Grand Base states it is in contact with CEX security teams including MEXC to freeze attacker funds and prevent off-ramping. A relaunch with audited contracts and retroactive airdrops is promised.","source":""},{"date":"2024-04-15","event":"GB token loses over 99% of its value, falling to approximately $0.0049. Protocol liquidity pools are effectively emptied.","source":""}],"sources_used":[{"url":"https://rekt.news/grand-base","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260518000456/https://rekt.news/grand-base","credibility":3,"archive_timestamp":"2026-05-18T00:04:56+00:00"},{"url":"https://beincrypto.com/defi-protocol-grand-base-hacked/","name":"beincrypto.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cointelegraph.com/news/base-asset-tokenization-protocol-compromised","name":"cointelegraph.com","type":"other","archive_url":"https://web.archive.org/web/20260829130119/https://cointelegraph.com/news/base-asset-tokenization-protocol-compromised","credibility":3,"archive_timestamp":"2026-08-29T13:01:19+00:00"},{"url":"https://www.web3isgoinggreat.com/single/grand-base-theft","name":"web3isgoinggreat.com","type":"other","archive_url":"https://web.archive.org/web/20260830011247/https://www.web3isgoinggreat.com/single/grand-base-theft","credibility":3,"archive_timestamp":"2026-08-30T01:12:47+00:00"},{"url":"https://www.quadrigainitiative.com/hackfraudscam/grandbaseprivatekeyleak.php","name":"quadrigainitiative.com","type":"other","archive_url":"https://web.archive.org/web/20260829152936/https://www.quadrigainitiative.com/hackfraudscam/grandbaseprivatekeyleak.php","credibility":3,"archive_timestamp":"2026-08-29T15:29:36+00:00"},{"url":"https://crypto.news/grand-base-minting-sparks-rug-pull-concerns-as-token-plunges-99/","name":"crypto.news","type":"other","archive_url":"http://web.archive.org/web/20251008031103/https://crypto.news/grand-base-minting-sparks-rug-pull-concerns-as-token-plunges-99/","credibility":3,"archive_timestamp":"2025-10-08T03:11:03+00:00"},{"url":"https://medium.com/neptune-mutual/understanding-the-grand-base-exploit-82a1ead971dc","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://bsc.news/post/grand-base-protocol-reportedly-exploited-for-2-m-exploit-what-we-know","name":"bsc.news","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://coingape.com/grand-base-token-gb-price-plummets-99-after-2m-hack/amp/","name":"coingape.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://crypto.news/base-hack-defi-network/","name":"crypto.news","type":"other","archive_url":"http://web.archive.org/web/20250912185241/https://crypto.news/base-hack-defi-network/","credibility":3,"archive_timestamp":"2025-09-12T18:52:41+00:00"},{"url":"https://www.coinspeaker.com/crypto-thefts-coinbase-base-april/","name":"coinspeaker.com","type":"other","archive_url":"http://web.archive.org/web/20260514195441/https://www.coinspeaker.com/crypto-thefts-coinbase-base-april/","credibility":3,"archive_timestamp":"2026-05-14T19:54:41+00:00"},{"url":"https://www.cryptometer.io/news/zachxbt-exposes-scam-ring-behind-multiple-defi-rug-pulls/","name":"cryptometer.io","type":"other","archive_url":"http://web.archive.org/web/20251116062204/https://www.cryptometer.io/news/zachxbt-exposes-scam-ring-behind-multiple-defi-rug-pulls/","credibility":3,"archive_timestamp":"2025-11-16T06:22:04+00:00"},{"url":"https://coinpaper.com/3930/fraudsters-target-new-victims-with-millions-in-laundered-crypto","name":"coinpaper.com","type":"other","archive_url":"http://web.archive.org/web/20260417053016/https://coinpaper.com/3930/fraudsters-target-new-victims-with-millions-in-laundered-crypto","credibility":3,"archive_timestamp":"2026-04-17T05:30:16+00:00"},{"url":"https://medium.com/@grand.base/introducing-grand-base-925cb2ecc713","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://docs.grandbase.io/","name":"docs.grandbase.io","type":"other","archive_url":"http://web.archive.org/web/20260517085657/http://docs.grandbase.io/","credibility":3,"archive_timestamp":"2026-05-17T08:56:57+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:33.52436+00:00","updated_at":"2026-08-30T01:16:27.664902+00:00"}}