Base DeFi vault loses $6M in wstETH due to compromised access control
On October 4, 2026, an unnamed DeFi vault on the Base network suffered a $6 million exploit. An attacker compromised the vault's whitelist controls via its multisignature wallet, adding a malicious contract to the approved list. Within minutes, the attacker withdrew approximately 1,783 aBaswstETH tokens from the vault across six transactions. Security firms Blockaid, Spot On Chain, and PeckShield tracked the stolen assets to a specific address on Base. The vulnerability was isolated to the vault's application-level controls, not the underlying Aave protocol or Base network.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in