Base DeFi Vault Loses Over $6M After Suspicious Whitelist Change
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

Highlights:
- An attacker stole over $6 million from an unnamed DeFi vault on Base after getting whitelist access.
- PeckShield traced about 1,783 wstETH linked to the attack, but Aave and Base were not hacked.
- Investigators are reviewing the approvals made before the attack, and the vault owner remains unknown.
An unidentified DeFi vault on Base lost more than $6 million after a newly deployed contract gained whitelist access and withdrew assets. Blockchain security firm Blockaid first reported the exploit on October 4, estimating an initial loss of about $2.02 million across roughly four transactions. The firm later said the stolen amount had climbed above $6 million.
Blockaid said the attacker used a newly created contract added to the vault’s whitelist. The contract then borrowed aBaswstETH and transferred the related tokens to an attacker-controlled address.
🚨 Blockaid detected an ongoing exploit on an unnamed vault on Base.
A brand-new contract was added to the vault's whitelist, then borrowed aBaswstETH from the vault and sent the aTokens to the attacker's contract.
~$2.02M drained from the vault so far across ~4 txs. Attack…
— Blockaid (@blockaid_) October 4, 2026
Attacker Used Whitelist Access to Drain the Vault
A whitelist lets selected addresses or smart contracts carry out restricted actions. In this case, someone added the attacker’s newly created contract to the vault’s whitelist shortly before the funds started leaving. Further on-chain analysis linked about 1,783 wrapped staked Ether (wstETH) to the theft. Blockchain security firm PeckShield valued the stolen tokens at around $6 million and identified an address linked to the attacker.
The assets involved were connected to Aave V3 on Base. However, available evidence does not show Aave itself was compromised. The attacker appears to have targeted the separate vault and its permission system rather than the underlying lending protocol. Similarly, there is no evidence that the Base blockchain was breached. The incident appears limited to infrastructure operating on the network.
Multisig Activity Emerges Before the Exploit
On-chain data also shows unusual changes to the vault’s whitelist shortly before the attack. Someone removed the newly deployed contract from the whitelist and added it back about one minute later. Soon after, the unauthorized borrowing began.
A multisignature Safe controlled the vault and required approval from three of seven authorized signers. Projects often use multisig wallets to prevent a single compromised key from gaining full control of funds.
However, investigators still do not know how the attacker secured the approvals needed to change the whitelist. They have not found evidence confirming whether the attacker compromised private keys, tricked signers into approving malicious transactions, or exploited another weakness in the vault’s access controls.
Identity of Affected Vault Still Unknown
Blockaid did not disclose the affected vault’s name in its initial alerts. The organization behind the contract has also not publicly identified itself. That leaves several important questions unanswered, including how the attacker gained permission, whether additional funds remain exposed and whether any stolen assets can be recovered.
Blockaid also revealed some of the attack addresses and provided an example transaction on BaseScan. This information lets researchers follow the trail of stolen assets. For now, however, the most pressing question remains how the hacker penetrated the vault.
The Base vault attack comes after a tough September regarding cryptocurrency security. PeckShield said there were 55 hacks, resulting in losses amounting to around $766.49 million. Bitget and Liquid Network accounted for most of the losses.
🚨 Crypto hackers stole $766 MILLION in September, the WORST month of 2026 so far.
That's up about 462% from August's $136.3 MILLION, across 55 major hacks, per PeckShield.
Most of the losses came from two incidents, at Liquid Network and Bitget.
Liquid Network has since had… pic.twitter.com/k9cNU8o1FE
— Coin Bureau (@coinbureau) October 2, 2026
Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.







