Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
publish · GoldPesa
- Sequence
- #1
- Score
- →
- Cluster
- mainnet-beta
- Slot
- 453403897
- Off-chain at
- 2026-10-04T23:27:17.435Z
- Anchored at
- 2026-10-04T23:27:28.818Z
- Block time
- —
Independent verification
- 1. Database (off-chain)
- FxtwZ4Upu97ifftnbfiSQSVeZe87HKzdDYHcRKPUyXyR
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (15014 chars)
{"actor":"system:backfill","investigation_id":"a1739ade-02c2-4d3c-8080-0ebe7b72b112","kind":"publish","page_slug":"goldpesa","published_at":"2026-10-04T23:27:17.347Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"GoldPesa","sections":[{"content":"GoldPesa is a gold-backed digital currency project positioning each GPX token as equivalent to one gram of gold held in a secure vault, while generating yield for holders — a design intended to address the lack of income generation in traditional gold ownership. The project is operated by Trilogy Precious Metals DMCC, a UAE-based gold trading company holding a precious metals license since 2013, with offices in London and Dubai. The project was founded by Shamik Raja, who holds a background in quantitative science and the precious metals sector. GoldPesa launched on the Base network in October 2025, with liquidity provided via Uniswap v4. The project describes its smart contracts as ownerless, non-upgradable, and immutable, with liquidity permanently locked. The project has referenced audits by CertiK in its promotional materials, though no audit submission was on file for the GPX token on Etherscan at the time of the exploit.","heading":"Project Background","severity":"low","sources":[{"credibility":2,"name":"GoldPesa Launches a Gold-Backed Token with Upside — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/news/goldpesa-launches-gold-backed-token-123900820.html"},{"credibility":2,"name":"GoldPesa Launches a Gold-Backed Token With Upside — BeInCrypto","type":"news_article","url":"https://beincrypto.com/goldpesa-launches-a-gold-backed-token-with-upside/"},{"credibility":2,"name":"GoldPesa — The Most Advanced Form of Money (official site)","type":"official","url":"https://www.goldpesa.com/"}]},{"content":"On October 2, 2026, at approximately 13:05:51 UTC, an attacker exploited a logic error in GoldPesa's GPXHooks contract (address: 0x4519e2b040ff1B64fa03aBe2AeF0BC99D7CcEaA8) on the Base network, resulting in a loss of approximately $114,900 in USDC. The attacker's address is identified as 0x4a5FD2e9357cC87DF4cD6A1808174DBc8646899F, and the exploit contract address on Base is 0xf460163b44b8bfeb05aaf6e651ae513a70475c9e. The exploit transaction hash is 0x5c1febd5047c2a15c37988b6abd5c8b984236dddf6fd24eed96b0f43951ad2c9.\n\nThe root cause was a missing delta-isolation check in the reBalance() function of the GPXHooks contract, which operates via a shared Uniswap v4 PositionManager. According to analyses by Defimon and SlowMist, the PositionManager failed to validate that currency deltas associated with the attacker's position were zero before allowing the rebalance credit to be netted against outstanding obligations from other callers.\n\nThe attack proceeded in the following steps, as described by Defimon and SlowMist: (1) The attacker initiated an unlock on the Uniswap v4 PoolManager. (2) A WETH/USDC position was minted via MINT_POSITION without settling the corresponding funds, creating an open deficit of approximately 114,999.999187 USDC. (3) The attacker executed a swap on the GPX pool, triggering the hourly rebalance condition in GPXHooks. (4) The hook's reBalance() function burned the protocol's legitimate GPX/USDC liquidity position, generating a credit of approximately 148,868.602189 USDC inside the shared PoolManager accounting. (5) Because the PositionManager did not enforce delta isolation between the attacker's state and the hook's burn credit, the attacker's phantom debt was offset against this credit. (6) The attacker burned their own position, canceling the debt, and withdrew approximately 114,999.999186 USDC. (7) The Morpho flash loan of 175,000 USDC was repaid; the remaining funds were converted to USDT and bridged — first to Solana, then onward to BNB Chain.\n\nThis incident has been characterized by security researchers as illustrating a novel class of Uniswap v4 hook vulnerability arising from composability risks in shared PositionManager accounting. GoldPesa's smart contracts are described as immutable and non-upgradable, which means the vulnerable contract cannot be patched without a full migration.","heading":"October 2026 GPXHooks Smart Contract Exploit","severity":"high","sources":[{"credibility":2,"name":"GoldPesa's GPXHooks Allegedly Drained for $114K in Base Exploit — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/10/03/goldpesas-gpxhooks-allegedly-drained-for-114k-in-base-exploit/"},{"credibility":2,"name":"Goldpesatoken Hit by $114.9K Exploit Loss as Flaws Revealed — CoinFomania","type":"news_article","url":"https://coinfomania.com/goldpesatoken-hit-by-114-9k-exploit-loss-as-flaws-revealed/"},{"credibility":2,"name":"Goldpesatoken Hit by $114.9K Exploit Loss as Flaws Revealed — CryptoNews.net","type":"news_article","url":"https://cryptonews.net/news/security/33535214/"},{"credibility":2,"name":"SlowMist TI Alert — @Goldpesatoken Loss ~$114.9k (via KuCoin Insight)","type":"research","url":"https://www.kucoin.com/news/insight/USDC/6ac14c3d38a2640007926b18"},{"credibility":2,"name":"Defimon — Exploit Contract on Base: 0xf460163b44b8bfeb05aaf6e651ae513a70475c9e","type":"on_chain","url":"https://defimon.xyz/exploit/base/0xf460163b44b8bfeb05aaf6e651ae513a70475c9e"},{"credibility":2,"name":"Goldpesatoken Loses $114.9K in Exploit as Security Flaws Exposed — CommStrader","type":"news_article","url":"https://commstrader.com/business/crypto/goldpesatoken-loses-114-9k-in-exploit-as-security-flaws-exposed/"}]},{"content":"Security researchers categorize this incident as an instance of a broader class of Uniswap v4 hook vulnerability. Uniswap v4 introduces a hook architecture that allows protocols to inject custom logic at various points in the swap lifecycle. GoldPesa's GPXHooks contract used the beforeSwap callback to trigger periodic liquidity rebalancing. The shared PositionManager contract maintains a flash-accounting ledger of currency deltas across all interacting callers within a single PoolManager unlock. The vulnerability arose because reBalance() did not enforce a zero-delta check on the PositionManager before or after its operations — a precondition that would have ensured the hook's credit could not be absorbed by a co-caller's open liabilities. This allowed a malicious caller to cause the hook's earned credit to net against the attacker's own unpaid position within the same atomic transaction. The Hacken research blog has noted that hook contracts interacting with shared infrastructure in Uniswap v4 carry inherent composability risks, particularly when delta accounting is not isolated per caller.","heading":"Vulnerability Classification: Uniswap v4 Hook Delta Isolation","severity":"high","sources":[{"credibility":2,"name":"Auditing Uniswap V4 Hooks: Risks, Exploits, and Secure Implementation — Hacken","type":"research","url":"https://hacken.io/discover/auditing-uniswap-v4-hooks/"},{"credibility":2,"name":"GoldPesa's GPXHooks Allegedly Drained for $114K in Base Exploit — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/10/03/goldpesas-gpxhooks-allegedly-drained-for-114k-in-base-exploit/"}]},{"content":"Following the extraction of approximately 114,999.999186 USDC from the GoldPesa liquidity pool, the Morpho flash loan of 175,000 USDC was repaid. The attacker's net profit — approximately $114,900 — was converted to USDT and bridged from Base to the Solana network, and subsequently onward to the BNB Chain. This cross-chain movement complicates recovery prospects. Defimon documented the fund movements and identified the attacker's address on Base as 0x4a5FD2e9357cC87DF4cD6A1808174DBc8646899F. No freeze or recovery of funds had been reported as of the date of this investigation.","heading":"Fund Flow and Post-Exploit Tracing","severity":"high","sources":[{"credibility":2,"name":"GoldPesa's GPXHooks Allegedly Drained for $114K in Base Exploit — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/10/03/goldpesas-gpxhooks-allegedly-drained-for-114k-in-base-exploit/"},{"credibility":2,"name":"Defimon — Exploit Contract on Base: 0xf460163b44b8bfeb05aaf6e651ae513a70475c9e","type":"on_chain","url":"https://defimon.xyz/exploit/base/0xf460163b44b8bfeb05aaf6e651ae513a70475c9e"}]},{"content":"As of October 3, 2026, no official response from GoldPesa or its parent company Trilogy Precious Metals DMCC had been published. The Crypto Times reported that it had reached out to GoldPesa for comment and would update its story upon receiving a response. No post-incident disclosure, post-mortem, or user communication from the GoldPesa team had been identified in public channels at the time of this investigation. The project's smart contracts are described as immutable and non-upgradable; the viability of any technical remediation path is therefore constrained. Post-exploit trading volume for GPX reportedly dropped to zero, indicating significant market impact.","heading":"GoldPesa Team Response","severity":"medium","sources":[{"credibility":2,"name":"GoldPesa's GPXHooks Allegedly Drained for $114K in Base Exploit — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/10/03/goldpesas-gpxhooks-allegedly-drained-for-114k-in-base-exploit/"},{"credibility":2,"name":"Goldpesatoken Hit by $114.9K Exploit Loss as Flaws Revealed — CoinFomania","type":"news_article","url":"https://coinfomania.com/goldpesatoken-hit-by-114-9k-exploit-loss-as-flaws-revealed/"}]},{"content":"GoldPesa's published technical documentation and promotional materials describe its smart contracts as ownerless, immutable, and non-upgradable — properties marketed as security guarantees that prevent insider interference. In the context of the October 2026 exploit, this design also precludes any in-place patch of the vulnerable reBalance() logic in GPXHooks. Any remediation would require a full contract migration and redeployment — a process that introduces its own risks and would require user coordination. As of the date of this investigation, no such migration plan had been announced by the team.","heading":"Smart Contract Immutability and Remediation Risk","severity":"medium","sources":[{"credibility":2,"name":"The GoldPesa Token (GPX) — GitBook documentation","type":"official","url":"https://goldpesa-1.gitbook.io/goldpesa/executive-summary/the-goldpesa-token-gpx"},{"credibility":2,"name":"GoldPesa — The Most Advanced Form of Money (official site)","type":"official","url":"https://www.goldpesa.com/"}]}],"sources_used":[{"credibility":2,"name":"GoldPesa's GPXHooks Allegedly Drained for $114K in Base Exploit — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/10/03/goldpesas-gpxhooks-allegedly-drained-for-114k-in-base-exploit/"},{"credibility":2,"name":"Goldpesatoken Hit by $114.9K Exploit Loss as Flaws Revealed — CoinFomania","type":"news_article","url":"https://coinfomania.com/goldpesatoken-hit-by-114-9k-exploit-loss-as-flaws-revealed/"},{"credibility":2,"name":"Goldpesatoken Hit by $114.9K Exploit Loss as Flaws Revealed — CryptoNews.net","type":"news_article","url":"https://cryptonews.net/news/security/33535214/"},{"credibility":2,"name":"Goldpesatoken Loses $114.9K in Exploit as Security Flaws Exposed — CommStrader","type":"news_article","url":"https://commstrader.com/business/crypto/goldpesatoken-loses-114-9k-in-exploit-as-security-flaws-exposed/"},{"credibility":2,"name":"SlowMist TI Alert — @Goldpesatoken Loss ~$114.9k (via KuCoin Insight)","type":"research","url":"https://www.kucoin.com/news/insight/USDC/6ac14c3d38a2640007926b18"},{"credibility":2,"name":"Defimon — Exploit Contract on Base: 0xf460163b44b8bfeb05aaf6e651ae513a70475c9e","type":"on_chain","url":"https://defimon.xyz/exploit/base/0xf460163b44b8bfeb05aaf6e651ae513a70475c9e"},{"credibility":2,"name":"GoldPesa Launches a Gold-Backed Token with Upside — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/news/goldpesa-launches-gold-backed-token-123900820.html"},{"credibility":2,"name":"GoldPesa Launches a Gold-Backed Token With Upside — BeInCrypto","type":"news_article","url":"https://beincrypto.com/goldpesa-launches-a-gold-backed-token-with-upside/"},{"credibility":2,"name":"GoldPesa — The Most Advanced Form of Money (official site)","type":"official","url":"https://www.goldpesa.com/"},{"credibility":2,"name":"The GoldPesa Token (GPX) — GitBook documentation","type":"official","url":"https://goldpesa-1.gitbook.io/goldpesa/executive-summary/the-goldpesa-token-gpx"},{"credibility":2,"name":"Auditing Uniswap V4 Hooks: Risks, Exploits, and Secure Implementation — Hacken","type":"research","url":"https://hacken.io/discover/auditing-uniswap-v4-hooks/"}],"summary":"GoldPesa is a gold-backed cryptocurrency project operating on the Base network, founded by Shamik Raja and operated by Trilogy Precious Metals DMCC (UAE). On October 2, 2026, an attacker exploited a logic error in the protocol's GPXHooks smart contract — a Uniswap v4 hook governing liquidity rebalancing — draining approximately $114,900 in USDC, which was subsequently bridged across Solana and BNB Chain. No official response from the GoldPesa team had been published as of the date of this investigation.","timeline":[{"date":"2013-01-01","event":"Trilogy Precious Metals DMCC, the parent company of GoldPesa, established in the UAE with a precious metals trading license.","source":"BeInCrypto / Yahoo Finance","source_url":"https://finance.yahoo.com/news/goldpesa-launches-gold-backed-token-123900820.html"},{"date":"2025-10-17","event":"GoldPesa launches on the Base network with GPX tokens available on Uniswap v4, with liquidity managed by the GPXHooks contract.","source":"Web search / GoldPesa official","source_url":"https://www.goldpesa.com/"},{"date":"2026-10-02","event":"Attacker (0x4a5FD2e9357cC87DF4cD6A1808174DBc8646899F) exploits GPXHooks on Base at 13:05:51 UTC. Approximately $114,900 in USDC extracted via a logic error in reBalance(). Funds subsequently bridged via Solana to BNB Chain.","source":"The Crypto Times / SlowMist / Defimon","source_url":"https://www.cryptotimes.io/2026/10/03/goldpesas-gpxhooks-allegedly-drained-for-114k-in-base-exploit/"},{"date":"2026-10-03","event":"Defimon Alerts posts on X identifying the exploit as a logic error in GoldPesa's Uniswap v4 hook rebalancing process. SlowMist issues a threat intelligence alert. Multiple crypto news outlets report on the incident.","source":"The Crypto Times / CoinFomania / CryptoNews.net","source_url":"https://www.cryptotimes.io/2026/10/03/goldpesas-gpxhooks-allegedly-drained-for-114k-in-base-exploit/"},{"date":"2026-10-03","event":"Post-exploit GPX trading volume reportedly collapses to zero. No official statement from GoldPesa or Trilogy Precious Metals DMCC published as of this date.","source":"CoinFomania / CommStrader","source_url":"https://coinfomania.com/goldpesatoken-hit-by-114-9k-exploit-loss-as-flaws-revealed/"}]},"v":1}