BaseBros Fi, a yield-optimization DeFi protocol on Coinbase’s Base blockchain, has disappeared after allegedly executing a rug pull via an unaudited smart contract that contained a backdoor, enabling the team to drain user funds estimated at over $130,000. The project’s website and social media accounts on X and Telegram were taken offline around September 13, effectively ending communication with users and preventing any recourse. Blockchain security firm Chain Audits reported that BaseBros had five smart contracts, four of which it had previously audited; the fifth, known as the Vault Contract, was neither audited nor verified on-chain and is identified as the mechanism used to siphon user deposits. According to Chain Audits, this unaudited contract contained a backdoor that allowed the operators to move funds into a “Strategy” contract and then withdraw them, consistent with a rug pull pattern. Blockchain investigator Cyvers estimated that roughly $130,000 in user funds were stolen and then routed through the crypto-mixing service Tornado Cash to obscure the transaction trail. The incident underscores persistent security risks in DeFi, particularly around unaudited or selectively audited smart contracts and opaque contract upgrades on emerging networks like Base. It also prompted clarification from the separate Base-based lending protocol Seamless, which stated after an internal review that it was not affected by the BaseBros exploit and that its users’ funds remained safe, highlighting how protocol name or ecosystem proximity can cause contagion fears even when codebases are unrelated. More broadly, the case illustrates how small-cap yield optimization projects can be vulnerable to or complicit in exit scams when critical contracts are excluded from audits and not verified on public explorers.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Base Chain

Comments