T
iTokenly

Grand Base hack — April 2024

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedApril 15, 2024
Target typeOther
Loss$2,000,000Published estimates range $1,700,000 to $2,500,000Price at time of incident
MethodPrivate key compromiseControl of the project's deployer wallet was used to mint GB tokens without limit - one transaction alone created 22.5 million - which were sold into the protocol's own liquidity across hundreds of swaps on Aerodrome, converted to ether and bridged to Ethereum. The GB contract placed no cap on deployer minting.
ChainsBase
OutcomeUnresolved

What happened

Grand Base was a real-world-asset tokenisation protocol on Coinbase's Base network offering gAssets, tokens tracking shares in large listed technology companies. On 15 April 2024 at 03:01:27 UTC an attacker holding the project's deployer key minted tens of millions of GB tokens, including 22.5 million in a single transaction, and sold them into the protocol's liquidity, converting the proceeds to ether over hundreds of swaps on Aerodrome before bridging to Ethereum.

The published figures diverge. PeckShield first reported roughly 527 ETH, about $1.7 million, bridged out, and later added a further 90 ETH, producing the widely repeated total of about 615 ETH or $2 million. Neptune Mutual's own tracing followed funds through five wallets to a single address holding 808.57 ETH, which it valued at approximately $2.5 million. CertiK confirmed the attacker had taken control of the deployer contracts and minted GB without authorisation.

A Grand Base administrator posted in the project's Telegram channel that an exploit had occurred on its contracts and asked users to remove liquidity immediately, saying the token contract was no longer safe. Staff later said they had traced the attacker's wallets and were in contact with centralised exchanges about freezing funds. No recovery has been reported.

The GB token fell about 99 percent within a day. Because the contract allowed the deployer to mint without any cap, community members questioned whether the incident was a compromise at all rather than an insider action; Molly White's Web3 Is Going Great logged the entry under both hack and rug pull. The team's account of a stolen key has not been independently confirmed and no one has been charged.

Sources

  1. CointelegraphSecondary · retrieved 2026-08-01
  2. CryptopolitanSecondary · retrieved 2026-08-01
  3. Neptune MutualSecondary · retrieved 2026-08-01
  4. Web3 Is Going Great (Molly White)Secondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Grand Base hack — April 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/grand-base
https://itokenly.com/hacks/grand-base

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.