# Exploit Researchers Publish Working Attacks on a Lending Pool and a Base Forwarder Contract

The new proof-of-concept code covers spot-price manipulation at LpdFi and an unprotected arbitrary-call contract on Base, with a recorded loss of about 16.62 ether. In July, stolen keys rather than contract bugs caused the largest losses.

- Published: 2026-08-04T05:45:02.328Z
- Canonical: https://polylog.news/crypto/2026-08-04/exploit-researchers-publish-working-attacks-on-a-lending-poo
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [DeFiHackLabs](https://github.com/SunWeb3Sec/DeFiHackLabs/commit/72e1dfad54e16700b30b1880cf2751aa8db3e27c), [DeFiHackLabs](https://github.com/SunWeb3Sec/DeFiHackLabs/commit/f4baf9701b393060378167315c4123fbdde26342), [Rekt News](https://www.rekt.news/), [DeFiHackLabs](https://github.com/SunWeb3Sec/DeFiHackLabs/commit/d3b389c2053eac0baefd1342ab77ddaeb4b03b5f)

Security researchers at DeFiHackLabs published reproducible attack code for two incidents over the weekend. The first targets LpdFi, also known as LOOPSDAO, through spot-price manipulation combined with an issue-boundary error. This is one…

This story is for subscribers. Read it in full at https://polylog.news/crypto/2026-08-04/exploit-researchers-publish-working-attacks-on-a-lending-poo (subscription information: https://polylog.news/pricing).