🚨 $GPX got drained for $114.9k via a hook re-entrancy exploit on Uniswap v4

Attacker abused GPXHooks' reBalance() function which shares a PositionManager inside an unlock context without verifying zero deltas

The play:
• Attacker opens unlock and mints WETH/USDC position via MINT_POSITION without settling → leaves PositionManager with -114,999 USDC delta
• Swaps on GPX pool to trigger hourly rebalance
• Hook burns its real position and earns +148,868 USDC credit
• TAKE_PAIR only withdraws net positive delta → hook receives 33,868 USDC
• Attacker's phantom debt absorbs the difference
• Burns own position to cancel debt and takes 114,999 USDC straight out of PoolManager

Root cause: Missing delta-isolation check on shared PositionManager. Classic case of hook state bleeding into caller state in v4's flash accounting model

Attacker: 0x4a5FD2e9357cC87DF4cD6A1808174DBc8646899F
Victim contract: 0x4519e2b040ff1B64fa03aBe2AeF0BC99D7CcEaA8

If you're building on Uniswap v4 hooks, isolate your position manager state or you're next