Unprotected admin function set fee recipient to attacker.
Attacker wallets funded and staged ahead of the access control exploit against BasedPerps.
$33.1M drained from BasedPerps on Base via Access Control.
Immunefi flagged the anomalous transactions and published an initial alert.
BasedPerps paused affected contracts or withdrawals and began tracing outbound flows.
Stolen assets followed through mixers, bridges, and exchange deposit addresses.
$1.5M frozen so far; tracing continues.