0x6bf557bf6bf5…6bf557bc
Base vault loses $6M in Aave deposit tokens after whitelist change
A vault on Coinbase's Base network lost approximately 1,783 wstETH, valued near $6 million, on October 4 after its dormant multisig approved a malicious borrower in under a minute. The drain exploited access-layer logic, not Aave V3 itself.
Outputs
October 4, 2026: A vault on Base lost approximately 1,783 wstETH, valued at roughly $6 million
The vault's 3-of-7 Safe multisig had been dormant for 25 days before approving two whitelist edits within 60 seconds
Aave V3 itself was not compromised; the breach occurred in the vault's access control layer above the protocol
Stolen funds were routed through Lido's Base-to-Ethereum bridge, which carries a seven-day settlement window
Approximately $31.7 million in assets remain in the vault, governed by the same multisig that approved the malicious borrower
A vault on Coinbase's Base network lost approximately 1,783 wstETH, worth roughly $6 million, on October 4, 2026, after its 3-of-7 Safe multisig approved a malicious borrower through two consecutive admin edits executed within a single minute.
On-chain records show the vault at 0xD1895f2019c2152FC2b9022D57f19198c4CFCABC had not processed a transaction in 25 days before the drain. Between 08:52 and 08:53 UTC on October 4, two whitelist changes landed from the same signers. The combined effect elevated a malicious contract to the list of approved borrowers, granting it the ability to borrow the vault's deposited collateral.
How did the drain unfold?
Once the attacker contract cleared the whitelist, it borrowed aBaswstETH from the vault. aBaswstETH is Aave V3's interest-bearing receipt token on Base, representing a wstETH deposit in the lending market and redeemable for the underlying asset at any time.
The contract passed those receipts to an address Blockaid flagged as the attacker: 0x0B5126e1bc27C0de77e02e97945760A674EdB034. Six outflows followed from the vault over roughly twenty-five minutes. The first served as a test transfer; the remaining five carried the bulk of the stolen funds.
Blockaid initially sized the loss at approximately $2.02 million. The total grew as the remaining outflows cleared, reaching the final figure of about 1,783 wstETH.
The attacker redeemed the aBaswstETH through Aave V3, exchanging the receipts for underlying wstETH. Some of the proceeds reportedly moved through Lido's Base-to-Ethereum bridge, which carries a seven-day settlement window before assets arrive on mainnet.
What went wrong with the multisig?
The vault relies on a Safe multisig requiring three of seven designated keyholders to approve any administrative change. The same three signers approved both whitelist edits inside sixty seconds, with no delay between them.
It remains unclear how those signatures were obtained. The plausible range includes compromised private keys, social engineering against the signers, or approval of a transaction whose payload was disguised. None of the signers has been publicly identified.
After the drain, the vault still held approximately $31.7 million in remaining assets. Those funds remain governed by the same multisig that approved the malicious borrower, with no operational change documented since the incident.
Was Aave itself compromised?
Aave V3 was not compromised. The lending protocol honored the receipt tokens exactly as designed, redeeming them for the underlying wstETH at the prevailing rate.
The failure sat one layer up: in the access control logic that determined who could borrow the vault's deposit tokens. The vault's whitelist functioned as a permissioned entry point, and that permission layer is where the breach occurred.
A breach in a vault built on top of Aave is operationally and technically distinct from a breach of Aave. The protocol's core lending and redemption logic performed as specified.
What gaps in the vault's design matter most?
The vault appears to have lacked a meaningful timelock between a whitelist change and its execution. A timelock forces a waiting period between admin action approval and on-chain effect, giving stakeholders time to react to a malicious proposal. Its absence converted a governance vote into an instant withdrawal authorization.
The structure also lacked any post-change rate limit. A short borrow cooldown, or a per-block cap on newly whitelisted addresses, could have constrained the speed of the drain once the malicious contract gained access.
No protocol has publicly claimed the vault, leaving depositors without an obvious counterparty. Without a named operator, recovery, communication, and post-mortem coordination lack a coordinating entity.
What is the next marker to watch?
The most informative near-term on-chain event will be the conclusion of Lido's seven-day Base-to-Ethereum bridge settlement. Once the stolen wstETH arrives on mainnet, the attacker's next move, whether through an exchange, a mixing service, or continued holding, will become visible.
The vault's remaining $31.7 million also warrants monitoring. The same multisig that approved the malicious borrower retains full administrative control, and no governance freeze has been publicly announced.
via Crypto Briefing (Source)
More from Elena Vasquez
Show full bio
Staff writer covering marketplaces and e-commerce at Mempool Brief.
440 articles