An unidentified vault on Base, the Ethereum layer-2 (L2) community incubated by Coinbase, misplaced about 1,783 wrapped staked Ether (wstETH), price roughly $6 million, on Sunday, October 4, 2026.
Blockchain safety corporations stated a newly deployed contract gained whitelist entry to the vault and borrowed in opposition to its place on Aave V3 earlier than the belongings have been moved to an attacker-controlled deal with. The loss grew from about $2 million to $6 million whereas the assault was nonetheless in progress.
$6 million wstETH stolen from an unnamed Base vault, exposing entry‑management weaknesses in L2 yield vaults.
Assault leveraged Aave V3 borrowing, marking the fourth Aave‑linked exploit on Base inside every week, elevating systemic danger considerations.
Multisig whitelist reversal suggests compromised signer approvals, prompting business requires stricter governance on decentralized finance contracts.
How the Base Vault Exploit Unfolded
Web3 safety agency Blockaid was the primary to publicly flag the incident. At 09:20 UTC (Coordinated Common Time), it reported an ongoing exploit on an unnamed vault on Base. In line with Blockaid, a brand-new contract had been added to the vault’s whitelist, a listing of addresses permitted to work together with the vault’s funds. That contract borrowed aBaswstETH and forwarded the tokens to the attacker’s contract.
On the time, Blockaid estimated that about $2.02 million had been drained throughout roughly 4 transactions. In a follow-up put up within the same thread, the agency stated whole losses had handed $6 million and the assault was nonetheless ongoing. One transaction cited by Blockaid is publicly viewable on BaseScan, the block explorer for Base.
Blockchain safety agency PeckShield stated at 09:56 UTC that deal with 0x0B..dB034 had drained 1,783 wstETH, valued at about $6 million, on Base.
Three minutes later, at 09:59 UTC, CertiK’s alert account described a newly deployed proxy contract borrowing about 1,783 aBaswstETH from vault 0xD1..FCABC. CertiK stated the tokens have been redeemed by Aave into roughly 1,783 wstETH held on the attacker’s deal with.
Safety agency ExVul gave essentially the most detailed rely at 10:09 UTC. It put the loss at 1,783.067 aBaswstETH throughout six outflows from the vault and recognized the contract receiving the stolen funds as 0xcd..F569d.
What Was Taken and How It Works
wstETH is the wrapped, non-rebasing model of stETH, the staked Ether token issued by liquid staking protocol Lido. In contrast to stETH, its steadiness doesn’t change each day. As a substitute, its worth in Ether grows as staking rewards accrue.
aBaswstETH is the interest-bearing receipt token, referred to as an aToken, that Aave V3 points on Base when customers provide wstETH to the lending protocol. Holders can redeem aTokens for the underlying asset.
Based mostly on the safety corporations’ descriptions, the attacker’s path was a borrow in opposition to the vault’s collateral, adopted by redemption of the aTokens into wstETH. There isn’t any public proof that Aave’s core lending contracts or the Base community have been compromised.
Sufferer Vault Holds Giant Aave Positions on Base
The victim contract is a TransparentUpgradeableProxy, a typical OpenZeppelin good contract design that lets an administrator improve a contract’s logic with out altering its deal with.
Portfolio trackers present the deal with has held massive Aave V3 positions on Base, with tens of thousands and thousands of {dollars} in provided belongings in opposition to substantial borrows. That profile suits a managed vault or yield technique constructed on high of Aave, moderately than a core Aave market. No group or protocol has publicly recognized itself because the vault’s operator.
Whitelist Change Was Signed by the Vault’s Personal Multisig
Probably the most important element up to now comes from ExVul’s follow-up timeline. In line with ExVul, the vault proprietor’s Secure, a multisignature (multisig) good contract pockets that requires a number of approvals for every transaction, eliminated the attacker contract from the whitelist at 08:52 UTC. One minute later, at 08:53 UTC, the identical Secure re-enabled it.
ExVul stated each administrative transactions confirmed three profitable Elliptic Curve Digital Signature Algorithm (ECDSA) signature recoveries beneath the identical signing identities. In easy phrases, the modifications carried legitimate approvals from the Secure’s current signers. The primary borrow happened 70 seconds after the contract was re-enabled.
This locations the deal with how these approvals have been obtained, moderately than on a flaw in Aave or within the vault’s lending logic. Whether or not the signers’ keys have been compromised, a signing course of was manipulated, or one other failure occurred has not been confirmed by any celebration.
The place the Stolen wstETH Went
Exercise on the attacker’s address exhibits interactions with the loot contract, a withdrawal routed by the Aave Base pool proxy and later calls involving the Lido wstETH token on Base.
Unverified group monitoring has pointed to a part of the proceeds starting a bridge to Ethereum by Lido infrastructure, a course of that usually takes a number of days. As of the newest BaseScan snapshot, the attacker deal with now not holds a fabric wstETH steadiness and exhibits solely a small quantity of ETH.
As of publication, no protocol has claimed the vault, issued a autopsy, frozen funds or introduced a restoration effort or bounty supply.
Fourth Aave-Linked or Base Incident in a Week
The incident provides to a run of exploits involving Aave-linked infrastructure and Base. On October 2, The Crypto Occasions reported {that a} FlashLoopAdapter exploit drained about $305,000 from two Secure wallets operating leveraged Aave V3 loops, an assault during which Aave’s core pools were used but not broken. A day later, GoldPesa’s GPXHooks contract was allegedly drained for $114,000 on Base.
The broader backdrop can also be extreme. September 2026 was the 12 months’s worst month for crypto losses at about $766.4 million, in accordance with CertiK, whereas hackers had already drained $972 million across the top 10 incidents of the first half.
The October 4 Base vault hack at present stands as an access-control failure on an unidentified vault, not a systemic breach of Aave or Base. A full account will rely on the vault’s operator figuring out itself and explaining how a contract it had simply faraway from its whitelist was accredited once more inside a minute.
Additionally Learn: Bitget Hackers Lose $700K as Script Error Sends USDC, ETH to Wrong Chainflip Channels
Disclaimer: The knowledge researched and reported by The Crypto Occasions is for informational functions solely and isn’t an alternative choice to skilled monetary recommendation. Investing in crypto belongings includes important danger resulting from market volatility. At all times Do Your Personal Analysis (DYOR) and seek the advice of with a certified Monetary Advisor earlier than making any funding choices.





