Base wstETH Vault Whitelist Exploit
An attacker whitelisted a fresh contract on an unidentified Base vault and borrowed against its Aave V3 position to drain about 1,783 wstETH, roughly $6 million.
- Date
- Victim
- Unidentified Base vault
- Chain(s)
- Status
- Funds Stolen
- Attribution
- 0x0B5126e1bc27C0de77e02e97945760A674EdB034
On October 4, 2026, an unidentified vault on Base was drained of roughly 1,783 wstETH, worth approximately $6 million, after an attacker added a freshly deployed contract to the vault's whitelist and borrowed against its Aave V3 position. Security firm Blockaid first flagged the outflows at around $2 million before the loss climbed past $6 million over six separate transfers.
What happened
The drained proxy contract, 0xD1895f2019c2152FC2b9022D57f19198c4CFCABC, held an Aave V3 position on Base denominated in aBaswstETH (Aave's interest-bearing receipt for wrapped staked Ether). The attacker got a newly created contract added to the vault's whitelist, then used that authorization to borrow aBaswstETH from the vault and forward the aTokens to an attacker-controlled contract, which redeemed them through Aave V3 for the underlying wstETH. Aave's core contracts were not compromised, and Base itself was not hacked — the protocol simply converted tokens as designed; the failure was in the vault's own authorization controls.
The suspicious detail is how the whitelist was manipulated. The vault was governed by a 3-of-7 Safe multisig (0x6b27512a5943Ed327f6cb6C3EC1f0398229f42C4), created roughly 324 days earlier, whose seven signers remain publicly unidentified. On-chain traces show that Safe removed the attacker's contract from the whitelist at 08:52 UTC and re-enabled it one minute later — both transactions carrying valid approvals from the Safe's existing signers. That pattern points to compromised signing credentials rather than a smart-contract bug, though no official post-mortem has confirmed the root cause.
Aftermath
No protocol has claimed the vault, named its signers, published a post-mortem, or announced a recovery effort or bounty as of this writing. The stolen wstETH moved to the attacker address 0x0B5126e1bc27C0de77e02e97945760A674EdB034 on Base. With no identified operator, affected depositors have had no formal channel for reimbursement.
Why it matters
The Base vault loss fits 2026's dominant failure mode: not a clever contract exploit but compromised keys and permissioned access behind an otherwise sound protocol — the same signer-credential pattern that produced Bybit and Radiant Capital. It is also the second Base incident in days to end at an Aave V3 position, following the FlashLoopAdapter drain of October 1 — a reminder that money-market receipt tokens like aBaswstETH are only as safe as the authorization layer wrapped around them. Finally, the anonymity of the victim is its own warning: an unaudited, unnamed vault with an opaque multisig left users with no post-mortem, no attribution, and no path to recovery, in contrast to the rapid full clawback at NEAR Intents the same week.
Sources & on-chain evidence
- [01]cryptotimes.iohttps://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/
- [02]blockonomi.comhttps://blockonomi.com/base-defi-vault-exploit-drains-6m-after-attacker-gains-whitelist-access
- [03]news.bitcoin.comhttps://news.bitcoin.com/security/6m-vanishes-from-crypto-vault-controlled-by-7-mystery-signers
- [04]phemex.comhttps://phemex.com/news/article/6m-in-wsteth-drained-from-base-network-protocol-98739