Base Vault Suffers About $6 Million Exploit With $31.7 Million Left
The attacker used a Safe multisignature wallet to add a malicious contract to the vault’s lending whitelist and withdraw assets.

An unnamed Base-based vault suffered an exploit that drained about $6 million while roughly $31.7 million in assets remained inside, leaving users exposed to a continuing security risk.
The attacker used a Safe multisignature wallet to add a malicious contract to the vault’s lending whitelist, then withdrew 1,783 aBaswstETH. The stolen assets were exchanged through Aave V3 for about 1,783 wstETH.
Gonçalo Magalhães, Immunefi’s security head, said the whitelist structure created the weakness because an approved address could remove assets without collateral. The flaw had been identified a week earlier, but researchers did not have a clear channel for disclosure.
More than 24 hours after the exploit, no team had publicly claimed responsibility for the vault or disclosed remediation measures.