Skip to content

exploit

Base vault loses 1,783 wstETH ($6M) after multisig signs attacker twice in 90 seconds

An unidentified Base vault's 3-of-7 Safe approved an attacker contract, let it drain 1,783 wstETH via Aave V3, then re-approved it — $31.7M still exposed under the same multisig.

by 3 min read

An unidentified yield vault on Base lost 1,783 wstETH, worth roughly $6 million, on October 4 after its 3-of-7 Safe multisig signed off on an attacker-controlled contract — twice. The vault's Safe both added the malicious contract to its lending whitelist and reinstated it less than two minutes later, with three valid signatures from the same signers on each transaction. Approximately $31.7 million in assets held under the same multisig remain exposed.

What happened

A newly deployed contract was whitelisted inside the vault's permissioning layer, then used that access to borrow 1,783 aBaswstETH on Aave V3's Base deployment, transfer the tokens to an attacker-controlled address, and redeem them for the underlying wstETH, as Journal du Coin pieced together from the on-chain trail. Between the removal of the attacker's contract and its reinstatement, less than 90 seconds elapsed. Each Safe transaction carried the three required signatures.

Aave's core contracts were not compromised; the vault's Safe approvals were, per CryptoTimes's attack summary. Base chain infrastructure was also unaffected — the loss sits entirely on the custodial design of the vault.

The numbers

  • Stolen: 1,783 wstETH (~$6.0M at prevailing wstETH/USD)
  • Remaining at risk under the same Safe: ~$31.7M
  • Multisig threshold: 3 of 7
  • Time between whitelist removal and reinstatement: ~90 seconds
  • Last Safe transaction on the treasury before the exploit: ~25 days earlier

Mechanism

Vaults that gate access by whitelist delegate the risk entirely to the signer set. If the Safe approves a malicious contract, there is no secondary check — no timelock, no oracle, no risk-committee pause. In this incident the three signers who approved the attacker's contract were the same three who approved its reinstatement minutes later, which rules out a one-off operational slip and points to either a signer compromise, social engineering of the signer set, or coordinated insider action.

On-chain forensics flagged 25 days of inactivity on the Safe before the exploit — a window long enough to execute a credential-phishing campaign against a signer or signers.

What to watch

  1. The remaining $31.7M. The same multisig still controls it. Movement from the Safe is the only reliable signal of whether the signer set is still intact.
  2. A protocol claim. No team has publicly claimed ownership of the vault or published a post-mortem. If a project owns this treasury, that silence is itself informative.
  3. Signer identification. The three signers who approved the attacker-contract transactions are visible on-chain by signature. Attribution to real-world identities depends on anyone recognising the keys.
  4. Base DeFi follow-on. This is the fourth Aave-related incident on Base inside a week. Expect Aave governance to look at whether permissioned integrators warrant additional guardrails on the Base deployment.

Context

Whitelist-gated vaults have been the attack surface in several multimillion-dollar incidents this year — the common denominator is that the Safe signer set functions as the only line of defence, and once compromised there is no delay between approval and loss. The pattern has driven some protocols to add Timelock controllers between a Safe and privileged contract calls; this vault had none. For readers tracking the Base-specific trend, this is the fourth incident on the chain in seven days by Aave-tooling exposure alone.

Related stories