Goldpesa Hack Shows Why DeFi Rebalancing Bugs Keep Costing Millions
Oct 4, 2026
A flaw in GPXHooks' rebalance() function let an attacker drain about $114,900 from Goldpesa, the latest reminder that small logic gaps in DeFi contracts can be costly.
Another Day, Another DeFi Exploit
Goldpesa just became the latest protocol to learn an expensive lesson about smart contract logic. According to security researchers, an attacker found a gap in the GPXHooks rebalance() function and walked away with roughly $114,900 in USDC.
The issue wasn't some exotic zero-day. It came down to a shared PositionManager that didn't properly check whether the GPX/USDC delta was zero before letting liquidity operations run. The attacker combined an unlock call with an unsettled mint position to create a negative delta, then triggered a rebalance to generate a credit out of thin air.
Small Bugs, Real Losses
The final withdrawal only pulled out the net amount, but the phantom debt left behind was enough to cause real damage. It's a reminder that rebalancing and accounting logic are some of the riskiest parts of any DeFi protocol to get right, and even well-audited projects can miss an edge case like this one.
For traders, it's another data point in a long list this year: DeFi hacks haven't slowed down, they've just gotten more technical.