{"id":93409,"date":"2024-09-16T05:07:30","date_gmt":"2024-09-16T09:07:30","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=93409"},"modified":"2024-09-16T05:07:34","modified_gmt":"2024-09-16T09:07:34","slug":"basebrosfi-project-vanishes-after-rug-pull","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/basebrosfi-project-vanishes-after-rug-pull\/","title":{"rendered":"BaseBrosFi Project Vanishes after Rug Pull"},"content":{"rendered":"\n<p>BaseBrosFi, a decentralized finance (DeFi) protocol on the <a href=\"https:\/\/coinscreed.com\/staging\/coca-cola-launches-nft-collection-on-base-blockchain.html\" data-type=\"post\" data-id=\"56596\">Base blockchain<\/a>, disappeared from the internet after an unaudited smart contract stole users' investments.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"805\" height=\"738\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/image-47.png\" alt=\"Source: BaseBrosFi\" class=\"wp-image-93428\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/image-47.png 805w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/image-47-300x275.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/image-47-768x704.png 768w\" sizes=\"(max-width: 805px) 100vw, 805px\" \/><figcaption class=\"wp-element-caption\">BaseBrosFi Project Vanishes after Rug Pull<\/figcaption><\/figure>\n\n\n\n<p>BaseBros terminated its official website and social media accounts on Telegram and X on September 13. Chain Audits, a blockchain security firm that had previously audited some BaseBros smart contracts, discovered that the DeFi project orchestrated a rug draw through &#8220;an unaudited and unverified Vault contract.&#8221;<\/p>\n\n\n\n<p>BaseBros had over 3,300 members on Telegram and approximately 2,000 followers on X at its disappearance.<\/p>\n\n\n\n<p>Smart contracts that were susceptible to auditing were the subject of scrutiny.<\/p>\n\n\n\n<p>ChainAudits asserted that it had conducted an audit of four of the five smart contracts utilized in the BaseBros initiative, and it also stated:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cUnfortunately the contract that facilitated the rug pull (Vault Contract) was not included in our audit scope, nor is verified on the blockchain.\u201d<\/p>\n<\/blockquote>\n\n\n\n<p>Funds deposited into the &#8220;Strategy&#8221; contract were accessible to the company proprietors through a backdoor vulnerability in the unaudited contract.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Incident Report<br><br>Yesterday on 13.09.2024, @BaseBrosFi, a DeFi project on <a href=\"https:\/\/twitter.com\/base?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@base<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>, executed a rug pull by gaining control of and draining ecosystem funds via an unaudited and unverified Vault contract.<br><br>The BaseBrosFi team exploited the unverified Vault Contract by overriding\u2026 <a href=\"https:\/\/t.co\/FIHK0rcUBt\" target=\"_blank\">https:\/\/t.co\/FIHK0rcUBt<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; ChainAudits (@ChainAudits) <a href=\"https:\/\/twitter.com\/ChainAudits\/status\/1834920031739682904?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">September 14, 2024<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">BaseBros' rug pull did not affect the Seamless protocol<\/h2>\n\n\n\n<p>Initially, the Seamless protocol was incorrectly presumed to be affected by the rug pull event due to the similar contract labeling. <\/p>\n\n\n\n<p>The bad actor transferred $130,000 worth of stolen funds through the crypto mixing service Tornado Cash, according to <a href=\"https:\/\/cyvers.ai\/\" target=\"_blank\" data-type=\"link\" data-id=\"https:\/\/cyvers.ai\/\" rel=\"noreferrer noopener nofollow\">blockchain investigator Cyvers<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">\ud83d\udea8ALERT\ud83d\udea8Our system flagged a suspicious transaction involving <a href=\"https:\/\/twitter.com\/SeamlessFi?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@SeamlessFi<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> on the <a href=\"https:\/\/twitter.com\/hashtag\/BASE?src=hash&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">#BASE<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> network earlier today.<br><br>A malicious contract was deployed on 13.09.2024 at 11:57:04 UTC, and a hack was executed just minutes later at 13:04:40 UTC.<br>The attacker bridged approximately $130K in\u2026 <a href=\"https:\/\/t.co\/mbDXb3Ku9D\" target=\"_blank\">https:\/\/t.co\/mbDXb3Ku9D<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> <a href=\"https:\/\/t.co\/1JtLWmXg7w\" target=\"_blank\">pic.twitter.com\/1JtLWmXg7w<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; \ud83d\udea8 Cyvers Alerts \ud83d\udea8 (@CyversAlerts) <a href=\"https:\/\/twitter.com\/CyversAlerts\/status\/1834644293757329522?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">September 13, 2024<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Seamless conducted an internal investigation and determined that the protocol and its investors' funds are secure from potential assaults. <\/p>\n\n\n\n<p>Additionally, Chain Audits verified that BaseBro Fi was the sole protocol that experienced a loss of funds from multiple pools.<\/p>\n\n\n\n<p>A seasoned hacker recently expressed gratitude to the attacker responsible for the $27 million breach of the DeFi protocol Penpie.<\/p>\n\n\n\n<p>The Euler Finance hacker, who had stolen $195 million in March 2023, sent an onchain appreciation message to the <a href=\"https:\/\/coinscreed.com\/staging\/penpie-hacker-moves-funds-via-tornado-cash.html\" data-type=\"post\" data-id=\"92209\">Penpie hacker<\/a>.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cGood job bro. I didn\u2019t see a hack like this for a while. I\u2019m happy you kept all the money and didn\u2019t let these bastards get back one dollar of what you took. You won, they lost. Good job.\u201d<\/p>\n<\/blockquote>\n\n\n\n<p>Nevertheless, the Euler Finance criminal had returned 90% of the stolen funds in exchange for legal immunity and a 10% reward.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>BaseBrosFi, a decentralized finance (DeFi) protocol on the Base blockchain, disappeared from the internet after an unaudited smart contract stole users&#8217; investments. BaseBros terminated its official website and social media accounts on Telegram and X on September 13. Chain Audits, a blockchain security firm that had previously audited some BaseBros smart contracts, discovered that the [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":93428,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[15835,21851,809],"class_list":["post-93409","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-base-blockchain","tag-basebrosfi","tag-rug-pull"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/09\/image-47.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/93409","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=93409"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/93409\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/93428"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=93409"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=93409"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=93409"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}