Skip to main content
AVOID.NET
← GoldPesa1 decision on this page

Audit log

Every state-changing event for GoldPesa: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-10-04 23:27:17Z
    Score: ? → ? (no score change)
    anchoranchored
    chain
    ●mainnet-betaslot 453,403,897
    sig
    3S68as4qMGHy…2EAUj6b7explorer ↗
    hash
    FxtwZ4Upu97i…RKPUyXyRsha256 → base58
    verifying row…full verify ↗
    canonical bytes (15014 B) ▸
    {"actor":"system:backfill","investigation_id":"a1739ade-02c2-4d3c-8080-0ebe7b72b112","kind":"publish","page_slug":"goldpesa","published_at":"2026-10-04T23:27:17.347Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"GoldPesa","sections":[{"content":"GoldPesa is a gold-backed digital currency project positioning each GPX token as equivalent to one gram of gold held in a secure vault, while generating yield for holders — a design intended to address the lack of income generation in traditional gold ownership. The project is operated by Trilogy Precious Metals DMCC, a UAE-based gold trading company holding a precious metals license since 2013, with offices in London and Dubai. The project was founded by Shamik Raja, who holds a background in quantitative science and the precious metals sector. GoldPesa launched on the Base network in October 2025, with liquidity provided via Uniswap v4. The project describes its smart contracts as ownerless, non-upgradable, and immutable, with liquidity permanently locked. The project has referenced audits by CertiK in its promotional materials, though no audit submission was on file for the GPX token on Etherscan at the time of the exploit.","heading":"Project Background","severity":"low","sources":[{"credibility":2,"name":"GoldPesa Launches a Gold-Backed Token with Upside — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/news/goldpesa-launches-gold-backed-token-123900820.html"},{"credibility":2,"name":"GoldPesa Launches a Gold-Backed Token With Upside — BeInCrypto","type":"news_article","url":"https://beincrypto.com/goldpesa-launches-a-gold-backed-token-with-upside/"},{"credibility":2,"name":"GoldPesa — The Most Advanced Form of Money (official site)","type":"official","url":"https://www.goldpesa.com/"}]},{"content":"On October 2, 2026, at approximately 13:05:51 UTC, an attacker exploited a logic error in GoldPesa's GPXHooks contract (address: 0x4519e2b040ff1B64fa03aBe2AeF0BC99D7CcEaA8) on the Base network, resulting in a loss of approximately $114,900 in USDC. The attacker's address is identified as 0x4a5FD2e9357cC87DF4cD6A1808174DBc8646899F, and the exploit contract address on Base is 0xf460163b44b8bfeb05aaf6e651ae513a70475c9e. The exploit transaction hash is 0x5c1febd5047c2a15c37988b6abd5c8b984236dddf6fd24eed96b0f43951ad2c9.\n\nThe root cause was a missing delta-isolation check in the reBalance() function of the GPXHooks contract, which operates via a shared Uniswap v4 PositionManager. According to analyses by Defimon and SlowMist, the PositionManager failed to validate that currency deltas associated with the attacker's position were zero before allowing the rebalance credit to be netted against outstanding obligations from other callers.\n\nThe attack proceeded in the following steps, as described by Defimon and SlowMist: (1) The attacker initiated an unlock on the Uniswap v4 PoolManager. (2) A WETH/USDC position was minted via MINT_POSITION without settling the corresponding funds, creating an open deficit of approximately 114,999.999187 USDC. (3) The attacker executed a swap on the GPX pool, triggering the hourly rebalance condition in GPXHooks. (4) The hook's reBalance() function burned the protocol's legitimate GPX/USDC liquidity position, generating a credit of approximately 148,868.602189 USDC inside the shared PoolManager accounting. (5) Because the PositionManager did not enforce delta isolation between the attacker's state and the hook's burn credit, the attacker's phantom debt was offset against this credit. (6) The attacker burned their own position, canceling the debt, and withdrew approximately 114,999.999186 USDC. (7) The Morpho flash loan of 175,000 USDC was repaid; the remaining funds were converted to USDT and bridged — first to Solana, then onward to BNB Chain.\n\nThis incident has been characterized by security researchers as illustrating a novel class of Uniswap v4 hook vulnerability arising from composability risks in shared PositionManager accounting. GoldPesa's smart contracts are described as immutable and non-upgradable, which means the vulnerable contract cannot be patched without a full migration.","heading":"October 2026 GPXHooks Smart Contract Exploit","severity":"high","sources":[{"credibility":2,"name":"GoldPesa's GPXHooks Allegedly Drained for $114K in Base Exploit — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/10/03/goldpesas-gpxhooks-allegedly-drained-for-114k-in-base-exploit/"},{"credibility":2,"name":"Goldpesatoken Hit by $114.9K Exploit Loss as Flaws Revealed — CoinFomania","type":"news_article","url":"https://coinfomania.com/goldpesatoken-hit-by-114-9k-exploit-loss-as-flaws-revealed/"},{"credibility":2,"name":"Goldpesatoken Hit by $114.9K Exploit Loss as Flaws Revealed — CryptoNews.net","type":"news_article","url":"https://cryptonews.net/news/security/33535214/"},{"credibility":2,"name":"SlowMist TI Alert — @Goldpesatoken Loss ~$114.9k (via KuCoin Insight)","type":"research","url":"https://www.kucoin.com/news/insight/USDC/6ac14c3d38a2640007926b18"},{"credibility":2,"name":"Defimon — Exploit Contract on Base: 0xf460163b44b8bfeb05aaf6e651ae513a70475c9e","type":"on_chain","url":"https://defimon.xyz/exploit/base/0xf460163b44b8bfeb05aaf6e651ae513a70475c9e"},{"credibility":2,"name":"Goldpesatoken Loses $114.9K in Exploit as Security Flaws Exposed — CommStrader","type":"news_article","url":"https://commstrader.com/business/crypto/goldpesatoken-loses-114-9k-in-exploit-as-security-flaws-exposed/"}]},{"content":"Security researchers categorize this incident as an instance of a broader class of Uniswap v4 hook vulnerability. Uniswap v4 introduces a hook architecture that allows protocols to inject custom logic at various points in the swap lifecycle. GoldPesa's GPXHooks contract used the beforeSwap callback to trigger periodic liquidity rebalancing. The shared PositionManager contract maintains a flash-accounting ledger of currency deltas across all interacting callers within a single PoolManager unlock. The vulnerability arose because reBalance() did not enforce a zero-delta check on the PositionManager before or after its operations — a precondition that would have ensured the hook's credit could not be absorbed by a co-caller's open liabilities. This allowed a malicious caller to cause the hook's earned credit to net against the attacker's own unpaid position within the same atomic transaction. The Hacken research blog has noted that hook contracts interacting with shared infrastructure in Uniswap v4 carry inherent composability risks, particularly when delta accounting is not isolated per caller.","heading":"Vulnerability Classification: Uniswap v4 Hook Delta Isolation","severity":"high","sources":[{"credibility":2,"name":"Auditing Uniswap V4 Hooks: Risks, Exploits, and Secure Implementation — Hacken","type":"research","url":"https://hacken.io/discover/auditing-uniswap-v4-hooks/"},{"credibility":2,"name":"GoldPesa's GPXHooks Allegedly Drained for $114K in Base Exploit — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/10/03/goldpesas-gpxhooks-allegedly-drained-for-114k-in-base-exploit/"}]},{"content":"Following the extraction of approximately 114,999.999186 USDC from the GoldPesa liquidity pool, the Morpho flash loan of 175,000 USDC was repaid. The attacker's net profit — approximately $114,900 — was converted to USDT and bridged from Base to the Solana network, and subsequently onward to the BNB Chain. This cross-chain movement complicates recovery prospects. Defimon documented the fund movements and identified the attacker's address on Base as 0x4a5FD2e9357cC87DF4cD6A1808174DBc8646899F. No freeze or recovery of funds had been reported as of the date of this investigation.","heading":"Fund Flow and Post-Exploit Tracing","severity":"high","sources":[{"credibility":2,"name":"GoldPesa's GPXHooks Allegedly Drained for $114K in Base Exploit — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/10/03/goldpesas-gpxhooks-allegedly-drained-for-114k-in-base-exploit/"},{"credibility":2,"name":"Defimon — Exploit Contract on Base: 0xf460163b44b8bfeb05aaf6e651ae513a70475c9e","type":"on_chain","url":"https://defimon.xyz/exploit/base/0xf460163b44b8bfeb05aaf6e651ae513a70475c9e"}]},{"content":"As of October 3, 2026, no official response from GoldPesa or its parent company Trilogy Precious Metals DMCC had been published. The Crypto Times reported that it had reached out to GoldPesa for comment and would update its story upon receiving a response. No post-incident disclosure, post-mortem, or user communication from the GoldPesa team had been identified in public channels at the time of this investigation. The project's smart contracts are described as immutable and non-upgradable; the viability of any technical remediation path is therefore constrained. Post-exploit trading volume for GPX reportedly dropped to zero, indicating significant market impact.","heading":"GoldPesa Team Response","severity":"medium","sources":[{"credibility":2,"name":"GoldPesa's GPXHooks Allegedly Drained for $114K in Base Exploit — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/10/03/goldpesas-gpxhooks-allegedly-drained-for-114k-in-base-exploit/"},{"credibility":2,"name":"Goldpesatoken Hit by $114.9K Exploit Loss as Flaws Revealed — CoinFomania","type":"news_article","url":"https://coinfomania.com/goldpesatoken-hit-by-114-9k-exploit-loss-as-flaws-revealed/"}]},{"content":"GoldPesa's published technical documentation and promotional materials describe its smart contracts as ownerless, immutable, and non-upgradable — properties marketed as security guarantees that prevent insider interference. In the context of the October 2026 exploit, this design also precludes any in-place patch of the vulnerable reBalance() logic in GPXHooks. Any remediation would require a full contract migration and redeployment — a process that introduces its own risks and would require user coordination. As of the date of this investigation, no such migration plan had been announced by the team.","heading":"Smart Contract Immutability and Remediation Risk","severity":"medium","sources":[{"credibility":2,"name":"The GoldPesa Token (GPX) — GitBook documentation","type":"official","url":"https://goldpesa-1.gitbook.io/goldpesa/executive-summary/the-goldpesa-token-gpx"},{"credibility":2,"name":"GoldPesa — The Most Advanced Form of Money (official site)","type":"official","url":"https://www.goldpesa.com/"}]}],"sources_used":[{"credibility":2,"name":"GoldPesa's GPXHooks Allegedly Drained for $114K in Base Exploit — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/10/03/goldpesas-gpxhooks-allegedly-drained-for-114k-in-base-exploit/"},{"credibility":2,"name":"Goldpesatoken Hit by $114.9K Exploit Loss as Flaws Revealed — CoinFomania","type":"news_article","url":"https://coinfomania.com/goldpesatoken-hit-by-114-9k-exploit-loss-as-flaws-revealed/"},{"credibility":2,"name":"Goldpesatoken Hit by $114.9K Exploit Loss as Flaws Revealed — CryptoNews.net","type":"news_article","url":"https://cryptonews.net/news/security/33535214/"},{"credibility":2,"name":"Goldpesatoken Loses $114.9K in Exploit as Security Flaws Exposed — CommStrader","type":"news_article","url":"https://commstrader.com/business/crypto/goldpesatoken-loses-114-9k-in-exploit-as-security-flaws-exposed/"},{"credibility":2,"name":"SlowMist TI Alert — @Goldpesatoken Loss ~$114.9k (via KuCoin Insight)","type":"research","url":"https://www.kucoin.com/news/insight/USDC/6ac14c3d38a2640007926b18"},{"credibility":2,"name":"Defimon — Exploit Contract on Base: 0xf460163b44b8bfeb05aaf6e651ae513a70475c9e","type":"on_chain","url":"https://defimon.xyz/exploit/base/0xf460163b44b8bfeb05aaf6e651ae513a70475c9e"},{"credibility":2,"name":"GoldPesa Launches a Gold-Backed Token with Upside — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/news/goldpesa-launches-gold-backed-token-123900820.html"},{"credibility":2,"name":"GoldPesa Launches a Gold-Backed Token With Upside — BeInCrypto","type":"news_article","url":"https://beincrypto.com/goldpesa-launches-a-gold-backed-token-with-upside/"},{"credibility":2,"name":"GoldPesa — The Most Advanced Form of Money (official site)","type":"official","url":"https://www.goldpesa.com/"},{"credibility":2,"name":"The GoldPesa Token (GPX) — GitBook documentation","type":"official","url":"https://goldpesa-1.gitbook.io/goldpesa/executive-summary/the-goldpesa-token-gpx"},{"credibility":2,"name":"Auditing Uniswap V4 Hooks: Risks, Exploits, and Secure Implementation — Hacken","type":"research","url":"https://hacken.io/discover/auditing-uniswap-v4-hooks/"}],"summary":"GoldPesa is a gold-backed cryptocurrency project operating on the Base network, founded by Shamik Raja and operated by Trilogy Precious Metals DMCC (UAE). On October 2, 2026, an attacker exploited a logic error in the protocol's GPXHooks smart contract — a Uniswap v4 hook governing liquidity rebalancing — draining approximately $114,900 in USDC, which was subsequently bridged across Solana and BNB Chain. No official response from the GoldPesa team had been published as of the date of this investigation.","timeline":[{"date":"2013-01-01","event":"Trilogy Precious Metals DMCC, the parent company of GoldPesa, established in the UAE with a precious metals trading license.","source":"BeInCrypto / Yahoo Finance","source_url":"https://finance.yahoo.com/news/goldpesa-launches-gold-backed-token-123900820.html"},{"date":"2025-10-17","event":"GoldPesa launches on the Base network with GPX tokens available on Uniswap v4, with liquidity managed by the GPXHooks contract.","source":"Web search / GoldPesa official","source_url":"https://www.goldpesa.com/"},{"date":"2026-10-02","event":"Attacker (0x4a5FD2e9357cC87DF4cD6A1808174DBc8646899F) exploits GPXHooks on Base at 13:05:51 UTC. Approximately $114,900 in USDC extracted via a logic error in reBalance(). Funds subsequently bridged via Solana to BNB Chain.","source":"The Crypto Times / SlowMist / Defimon","source_url":"https://www.cryptotimes.io/2026/10/03/goldpesas-gpxhooks-allegedly-drained-for-114k-in-base-exploit/"},{"date":"2026-10-03","event":"Defimon Alerts posts on X identifying the exploit as a logic error in GoldPesa's Uniswap v4 hook rebalancing process. SlowMist issues a threat intelligence alert. Multiple crypto news outlets report on the incident.","source":"The Crypto Times / CoinFomania / CryptoNews.net","source_url":"https://www.cryptotimes.io/2026/10/03/goldpesas-gpxhooks-allegedly-drained-for-114k-in-base-exploit/"},{"date":"2026-10-03","event":"Post-exploit GPX trading volume reportedly collapses to zero. No official statement from GoldPesa or Trilogy Precious Metals DMCC published as of this date.","source":"CoinFomania / CommStrader","source_url":"https://coinfomania.com/goldpesatoken-hit-by-114-9k-exploit-loss-as-flaws-revealed/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 50e014dc-efda-482f-b470-c72c3aaa7158
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.