Contract vulnerability on Base allowed ~4 WETH extraction; project offering bounty and return negotiation.
Security & Exploits ยท
A contract vulnerability on Base allowed approximately 4 WETH to be extracted across blocks 44039167โ44055571, according to an on-chain message sent to the address that conducted the extraction. The affected contract, located at 0xD1950a138328B52Da4fE73DbdB167a83f2c83DB9, contained a configuration bug that enabled the unauthorized removal of funds.
The project behind the vulnerable contract has responded by reaching out to the address responsible for the extraction, offering both a bug bounty and the possibility of negotiating a return of the extracted tokens. This approach suggests the project is treating the incident as a potential white-hat disclosure rather than pursuing legal or technical countermeasures.
It remains unclear whether the extractor will accept the bounty offer, return any portion of the funds, or engage further with the project. No details have been disclosed about the specific nature of the configuration bug, the timeline for resolution, or the bounty amount being proposed.