1 min read
Base Vault Exploit Drains About $6 Million, Puts $31.7 Million at Risk
The attacker withdrew 1,783 aBaswstETH and redeemed it through Aave V3 for about 1,783 wstETH.

An exploit drained about $6 million from a vault on Base, with roughly $31.7 million in assets still at risk when the incident was disclosed Oct. 5.
The attacker used a Safe multisignature wallet to add a malicious contract to the vault’s lending whitelist. That contract enabled the withdrawal of 1,783 aBaswstETH, which was redeemed through Aave V3 for about 1,783 wstETH.
The incident points to failures in the vault’s multisignature governance and access controls. The vault had not executed a Safe transaction for 25 days before the attack. Social engineering or collusion were raised as possible explanations, but neither was established.