1 min read

Base Vault Exploit Drains About $6 Million, Puts $31.7 Million at Risk

The attacker withdrew 1,783 aBaswstETH and redeemed it through Aave V3 for about 1,783 wstETH.

Mentioned assets
A vault door stands beside a damaged access control panel / TokenPost.ai
A vault door stands beside a damaged access control panel / TokenPost.ai

An exploit drained about $6 million from a vault on Base, with roughly $31.7 million in assets still at risk when the incident was disclosed Oct. 5.

The attacker used a Safe multisignature wallet to add a malicious contract to the vault’s lending whitelist. That contract enabled the withdrawal of 1,783 aBaswstETH, which was redeemed through Aave V3 for about 1,783 wstETH.

The incident points to failures in the vault’s multisignature governance and access controls. The vault had not executed a Safe transaction for 25 days before the attack. Social engineering or collusion were raised as possible explanations, but neither was established.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…