GoldPesa's Uniswap v4 hook exploited for $114K via logic error in position rebalancing and shared PoolManager unlock debt netting.
Security & Exploits ·
GoldPesa's Uniswap v4 hook implementation on Base suffered a $114K loss on October 2, 2026, through a logic error in its position rebalancing mechanism. The GPXHooks contract rebalances protocol-owned GPX/USDC liquidity during swaps, executing once per hour via a call to PositionManager.modifyLiquiditiesWithoutUnlock that collects the PositionManager's net credit. An attacker exploited the fact that this collected amount is shared across all callers within the same PoolManager unlock cycle.
The attacker borrowed 175K USDC from Morpho, then minted a WETH/USDC position through the PositionManager without paying for it, leaving approximately 115K USDC in unpaid debt. By triggering a swap on the GPX pool, the attacker forced the rebalance to execute. When the hook burned its position for 148.9K USDC, the TAKE_PAIR operation netted that amount against the attacker's outstanding debt, resulting in the hook receiving only 33.9K USDC—effectively subsidizing the attacker's position. The attacker then burned its own position for 115K USDC, repaid the Morpho loan, and converted profits to USDT before bridging the stolen funds through Solana to BSC to obscure the trail.
The vulnerability stems from insufficient isolation of debt obligations across concurrent unlock contexts, allowing one user's credit to absorb another's liability. Whether additional safeguards or position tracking improvements are planned remains unclear.