ChainBleedv0.1 · open intel
← back to feed·ETHFRONTEND2025-12-12 · 6mo ago
Incident · SLOWMIST

ZEROBASE

Frontend Attack
Estimated loss
$123.0K
VERDICT —OUT OF SCOPE
Root cause is a frontend / UI hijack — users authorized the malicious transaction from a compromised site or DNS. On-chain contract was not the failure surface; pre-deployment audit cannot catch this class.
▰ METHOD
FRONTEND
FRONTEND
Root cause

Root-cause analysis not yet published. The incident description below contains all currently available signal — review the attack transaction directly for definitive forensics.

Forensic narrative

According to SlowMist founder Yu Cos and ZEROBASE officials, a malicious contract on the BSC chain, “Vault” (0x0dd2…2396), impersonated the ZEROBASE frontend to trick users into authorizing USDT. The incident is suspected to have occurred due to a compromise of the ZEROBASE frontend and was not an issue with the Binance Web3 wallet itself. So far, hundreds of addresses have been affected, with the largest single loss reaching $123,000. The stolen funds have been transferred to the Ethereum address 0x4a57…fc84. ZEROBASE has enabled an authorization monitoring mechanism, and the community is urging users to quickly revoke risky authorizations via revoke.cash. Attack method (per SlowMist): Frontend Attack. Reported loss: $ 123,000.

Primary source
https://x.com/zerobasezk/status/1999466921314648585
Sourced from
slowmist
Technical record
chain
ethereum
protocol
ZEROBASE
bug_class
frontend
date_occurred
2025-12-12
loss_usd
$123,000
source_id
sm:zerobase::2025-12-12
Related — same bug class· frontend
2026-04-14
1mo ago
CowSwap
Supply-chain attack
frontend
$1.20M
OUT OF SCOPE
2025-06-23
11mo ago
CoinTelegraph
Frontend Attack
frontend
OUT OF SCOPE
2025-06-21
11mo ago
CoinMarketCap
Frontend Attack
frontend
$21.6K
OUT OF SCOPE
2024-08-20
1y ago
SOL
Parcl
Frontend Attack
frontend
OUT OF SCOPE
2023-09-19
2y ago
ETH
Balancer V2
Frontend Attack
frontend
$238.0K
OUT OF SCOPE
2022-09-02
3y ago
Kyber Network
Malicious Code Injection Attack
frontend
$265.0K
OUT OF SCOPE
ChainBleed — live web3 threat intelligence