Base vault drained of $6 million in wstETH after whitelist exploit
CIE News ·
An unidentified vault on the Base network lost approximately 1,783 wstETH worth $6 million after an unauthorized contract gained whitelist permissions to borrow against its Aave V3 position.
An unidentified vault on the Base network lost approximately 1,783 wrapped staked Ether (wstETH), valued at roughly $6 million, following an exploit on October 4, 2026. Security firms reported that the losses expanded from an initial $2 million to $6 million across several transactions. Neither Base nor Aave's core lending contracts were compromised in the incident.
According to reports cited by cryptotimes.io and Bitcoin.com News, the attacker gained unauthorized whitelist access to the proxy contract at address 0xD1895f2019c2152FC2b9022D57f19198c4CFCABC. This allowed a newly deployed malicious contract to borrow Aave interest-bearing tokens (aBaswstETH) against the vault's collateral and redeem them for roughly 1,783 wstETH before transferring the funds away.
Investigators suspect compromised authorizations within the vault's controlling 3-of-7 multisig Safe at address 0x6b27512a5943Ed327f6cb6C3EC1f0398229f42C4, which reportedly removed and then re-approved the malicious contract shortly before the outflows. No project or team has publicly stepped forward to claim ownership of the drained vault.