# A Governance Timeout, a Flash-Loan Oracle Trick and an Unvalidated Parameter: Three New Exploit Proofs Published

Panther Protocol lost 5.12 million ZKP on Base after nobody bonded against a malicious proposal, and researchers added working reproductions of two further attack classes to the public exploit archive.

- Published: 2026-08-09T06:30:14.346Z
- Canonical: https://polylog.news/crypto/2026-08-09/a-governance-timeout-a-flash-loan-oracle-trick-and-an-unvali
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [DeFiHackLabs](https://github.com/SunWeb3Sec/DeFiHackLabs/commit/36c3e5d3c4c4b2141c0cebd4b265be994f6bc54f), [DeFiHackLabs](https://github.com/SunWeb3Sec/DeFiHackLabs/commit/cca8b236f178ed4c9c19ba3d90ef2aa3ac476953), [DeFiHackLabs](https://github.com/SunWeb3Sec/DeFiHackLabs/commit/24546388f6264313f543c8e7232bd5cba14cc735), [Rekt News](https://www.rekt.news/)

Security researchers published three new proof-of-concept reproductions to the DeFiHackLabs archive in the past 48 hours, each corresponding to a distinct root cause. The largest is the Panther Protocol governance attack on Base. On 6 Augus…

This story is for subscribers. Read it in full at https://polylog.news/crypto/2026-08-09/a-governance-timeout-a-flash-loan-oracle-trick-and-an-unvali (subscription information: https://polylog.news/pricing).