T0 Trade DEX exploited via cross-chain pricing bug on Base; admin requests return of proceeds via bounty agreement.
Security & Exploits ·
T0 Trade, which operates a DEX contract on Base, disclosed an exploit stemming from a cross-chain pricing bug that went live on September 11, 2026. The malfunction caused the protocol to publish incorrect quotes on Base, which were then targeted by trades routed through a specific contract address; one transaction exemplifies the affected activity, and most proceeds from the exploit flowed to a single address.
An authorized admin of the RaindexInventory contract sent an on-chain message to the address holding the proceeds, requesting return of the funds in exchange for an agreed bounty under what the admin framed as a bounty agreement. The message provided transaction references and identified the affected orderbook, asking the recipient to preserve the proceeds pending a follow-up signed on-chain message with full accounting, a bounty proposal, and return instructions.
The identity of the actor who executed the trades and claimed the proceeds remains unconfirmed, as does whether or how much of the exploited value has been or will be recovered. No independent verification of the bug's technical cause or scope has been announced.