1 min read

Base Vault Suffers About $6 Million Exploit With $31.7 Million Left

The attacker used a Safe multisignature wallet to add a malicious contract to the vault’s lending whitelist and withdraw assets.

Mentioned assets
A steel vault door beside two unmarked security keys / TokenPost.ai (mono)
A steel vault door beside two unmarked security keys / TokenPost.ai (mono)

An unnamed Base-based vault suffered an exploit that drained about $6 million while roughly $31.7 million in assets remained inside, leaving users exposed to a continuing security risk.

The attacker used a Safe multisignature wallet to add a malicious contract to the vault’s lending whitelist, then withdrew 1,783 aBaswstETH. The stolen assets were exchanged through Aave V3 for about 1,783 wstETH.

Gonçalo Magalhães, Immunefi’s security head, said the whitelist structure created the weakness because an approved address could remove assets without collateral. The flaw had been identified a week earlier, but researchers did not have a clear channel for disclosure.

More than 24 hours after the exploit, no team had publicly claimed responsibility for the vault or disclosed remediation measures.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…