GemPad hack — December 2024
Incident facts
| Date of incident | (approximate) |
|---|---|
| Publicly disclosed | December 17, 2024 |
| Target type | Infrastructure provider |
| Loss | $1,900,000Published estimates range $1,900,000 to $2,100,000Price at time of incident |
| Method | ReentrancyReentrancy in the collectFees function of GemPad's shared token/LP locker template. The function transferred tokens to an external address before completing its state update, so the attacker deployed tokens whose transfer hooks called back into the locker, created a lock, and re-entered the withdrawal path repeatedly, withdrawing several times the value originally locked. The same template was deployed on Ethereum, BNB Chain and Base, and the attack was repeated on each. |
| Chains | Ethereum, BNB Chain, Base |
| Outcome | Unresolved |
What happened
In mid-December 2024 an attacker drained token and liquidity locks held by GemPad, a no-code launchpad that lets projects deploy tokens and lock LP positions from shared contract templates.
The flaw was a reentrancy bug in the locker's collectFees function, which moved tokens to an external address before finishing its state update. The attacker deployed tokens whose transfer hooks called back into the GemPad contract, locked a small amount of value, and then repeatedly re-entered the withdrawal path, taking out several times what had been deposited. Because the same vulnerable template was live on more than one network, the attack was repeated on Ethereum, BNB Chain and Base.
The figures do not agree. Halborn's technical write-up put the total at an estimated $1.9 million of locked assets; CertiK's December 2024 loss review cited $2.1 million. GemPad has published no accounting of its own, so the loss sits somewhere in that band, and no cited source fixes the exact day of the attack within December.
Halborn names BPay, Munch Protocol and AnonFi among the affected projects. The losses fell on those projects' locked liquidity rather than on GemPad's own treasury, which is why individual project audits did not catch the problem: the audited contracts were the tokens, not the launchpad infrastructure they depended on.
Most of the proceeds were sent to a mixing service and none were recovered. GemPad offered affected teams a relaunch with all upfront fees waived and committed 20% of its revenue share to a dedicated recovery fund, terms set out publicly by Munch Protocol on 19 December 2024.
Sources
- HalbornSecondary · retrieved 2026-08-01
- Cointelegraph (citing CertiK)Secondary · retrieved 2026-08-01
- MUNCH Protocol (affected project)Primary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "GemPad hack — December 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/gempadhttps://itokenly.com/hacks/gempadPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.