MABOnChain
Educational content only. Nothing on this site is financial advice.
Home / DeFi / Base Vault Loses $6M in wstETH After Whitelist Change
DeFi

Base Vault Loses $6M in wstETH After Whitelist Change

By MABOnChain Desk · Published · Updated · 3 min read

Abstract illustration for Base Vault Loses $6M in wstETH After Whitelist Change

Published October 5, 2026, 04:36 UTC. Details are preliminary; no operator has claimed the vault or published a post-mortem.

An unidentified vault on Base, the Ethereum layer-2 network incubated by Coinbase, lost about 1,783 wrapped staked Ether (wstETH), worth roughly $6 million, on Sunday, October 4, according to security firms cited by The Crypto Times.

How the attack unfolded

Web3 security firm Blockaid first flagged the incident publicly at 09:20 UTC, reporting an ongoing exploit on an unnamed Base vault. Blockaid said a brand-new contract had been added to the vault's whitelist, the list of addresses allowed to interact with its funds. That contract borrowed aBaswstETH, the receipt token Aave V3 issues on Base for supplied wstETH, and forwarded it to the attacker.

Blockaid initially estimated losses of about $2.02 million, then said they had passed $6 million while the attack continued. PeckShield reported at 09:56 UTC that an address had drained 1,783 wstETH. CertiK said at 09:59 UTC that a newly deployed proxy contract borrowed the aTokens and redeemed them through Aave for wstETH. ExVul put the total at 1,783.067 aBaswstETH across six outflows.

A whitelist change signed by the vault's own multisig

According to ExVul's timeline, the vault owner's Safe multisig wallet removed the attacker's contract from the whitelist at 08:52 UTC and re-enabled it one minute later, at 08:53 UTC. ExVul said both transactions carried valid signatures from the Safe's existing signers, and that the first borrow came about 70 seconds after the contract was re-enabled.

That puts the focus on how those approvals were obtained. No party has confirmed whether signer keys were compromised, a signing process was manipulated or something else failed.

Aave and Base not shown to be breached

Based on the security firms' descriptions, the attacker borrowed against the vault's own collateral and redeemed the aTokens. The Crypto Times reported there is no public evidence that Aave's core lending contracts or the Base network were compromised. Portfolio trackers show the victim address held large Aave V3 positions on Base, which fits a managed vault or yield strategy built on top of Aave.

As of the outlet's report, no team had identified itself as the vault's operator, and none had announced a fund freeze, recovery effort or bounty. Unverified community tracking suggested part of the proceeds had started bridging to Ethereum.

Part of a busy week

The incident follows several smaller DeFi exploits this week, including the FlashLoopAdapter module drain and GoldPesa's Uniswap v4 hook loss, which we cover in our weekly exploit roundup. The Crypto Times cited CertiK data putting September 2026 as the year's worst month for crypto losses so far, at about $766.4 million.

This article is news reporting and is not investment advice.

Sources

Related: What Are Layer 2 Rollups? Ethereum Scaling Explained · NEAR Intents Exploit: Full $3.8M Recovered

Not financial advice. This content is for information and education only. See our disclaimer, editorial policy and disclosures.

MABOnChain Daily Brief

The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.

Loading the signup form…

Prefer chat? Join us on Telegram

Keep reading