Unidentified Base Vault Hit By $6M Multisig Exploit, Leaving $31.7M At Risk

Security researchers disclosed that an unidentified vault contract on Base lost approximately $6 million after attackers exploited weaknesses in its whitelist and multisignature controls. The incident was detected on October 4, when blockchain security firm Blockaid identified unusual withdrawals. Within roughly 40 minutes, the estimated loss had risen from $2.02 million to about $6 million.
According to GoPlus, PeckShield, CertiK and Exvul, the attacker borrowed 1,783.067 aBaswstETH from the vault and redeemed the Aave receipt tokens for approximately 1,783 wstETH. aBaswstETH represents wrapped staked Ether supplied to Aave’s Base market.
The attack was not caused by a vulnerability in Aave’s core lending contracts or in the Base network. Instead, investigators linked the theft to a failure involving the vault’s multisignature governance and access controls. A newly created contract was added to the vault’s borrowing allowlist through a Safe multisignature transaction. Once whitelisted, the contract could borrow the vault’s Aave position and redeem the underlying assets.
The vault’s operating owner is a three-of-seven Safe created through Safe Proxy Factory 1.4.1. Seven signer addresses control the account, but their identities have not been publicly established. Investigators can trace the on-chain transactions but cannot determine from blockchain records alone whether the whitelist update resulted from stolen credentials, social engineering, an insider threat or another governance failure.
Notably, the Safe had not executed a transaction on the vault for 25 days before two transactions were completed during the attack. This sudden activity may indicate that signers were manipulated or that an internal party approved the change. No security firm has publicly confirmed which explanation is correct.
Unclaimed Ownership and Remaining Exposure
The lack of a known owner has complicated the response. No project team has publicly acknowledged the vault, announced a remediation plan or explained how the unauthorized whitelist addition was approved. The vault is an OpenZeppelin transparent proxy with a separate upgrade authority, adding another contract layer between the asset holder and the ultimate controller.
Approximately $31.7 million in assets reportedly remained in the vault after the withdrawal. An unidentified on-chain user later sent the attacker a message encouraging them to withdraw the remaining funds and requesting a tip, but there has been no publicly verified response.
For now, the direct systemic risk appears limited because Aave’s Base deployment and the underlying blockchain remained unaffected. Nevertheless, the episode illustrates how privileged administrative functions can create a greater risk than the smart contracts they govern. Multisignature approval alone does not guarantee security when signer identities, transaction review procedures and internal controls are weak.
The incident also places attention on wstETH liquidity. Selling approximately 1,783 wstETH could create short-term market pressure, although the receipt token’s broader peg has not been shown to be at risk. Further details may emerge if the Safe signers, the vault’s controlling organization or the attacker publicly identifies themselves.
Disclaimer
In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.
About The Author
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.
More articles
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.



