White-hat hacker posts final enforcement notice for ~30 WETH exploit on Arbitrum/Base, offering 10% bounty for return before law enforcement reporting.
Security & Exploits ·
A white-hat security researcher posted an onchain message declaring the conclusion of a grace period for the return of approximately 30 WETH stolen in an exploit affecting Arbitrum and Base. The message, broadcast from 0xc7d5acaea25f06450aae5a6ee0ec5f70d4fe355f on Base, stated that enforcement actions are now underway and offered a final settlement: the attacker could return the funds and receive 10% (~3.4 WETH) as a bounty, avoiding legal consequences and receiving public credit.
The researcher detailed that stolen funds—approximately 23.08 WETH on Base and 10.70 WETH on Arbitrum, plus cbBTC—have been traced to specific attack contracts on Arbitrum and consolidated into a single wallet. The message indicated that the addresses are being reported simultaneously to Chainabuse, tracing firms including Chainalysis, TRM, and Elliptic, and to exchange compliance and law enforcement. Once these reports are filed, the researcher stated that the flagged addresses will be frozen across centralized exchanges, bridges, and mixers upon any fund movement, with evidence forwarded to law enforcement.
The critical unknown is whether the attacker will accept the bounty offer before the reports are filed or face the enforcement pipeline through established tracing and regulatory channels. No prior public disclosure of the exploit's scope, affected smart contracts, or root cause has been disclosed.