Critical Permit2 reentrancy vulnerability identified across 11 DERC20 token deployments on Base, with extortion demand for 58 XMR and threat of mass exploit.
Security & Exploits ·
A critical reentrancy vulnerability in Permit2 token approvals has been flagged across 11 DERC20 token deployments on Base, including THESIS, DEAL, HALO, BRAIN, and others. An onchain message identified the flaw as enabling infinite allowance overrides and total liquidity drainage through reentrancy in the _update() hook. The vulnerability researcher has threatened mass exploitation across all eleven pools and public disclosure unless 58.00 XMR is sent to a specified address, accompanied by a Session contact handle for negotiation.
The exploit mechanism centers on Permit2's approval mechanism in combination with a reentrancy vulnerability in the token update function. A proof-of-concept is claimed to have been compiled, and the researcher asserts that the vulnerability pattern is identical across all affected deployments, suggesting a shared template vulnerability rather than isolated instances.
The immediate question is whether the vulnerability claims have been independently verified by the affected projects or security auditors. No public confirmation of the reentrancy vector's validity, the legitimacy of the exploit threat, or any response from the token projects has emerged in the available record.