An unidentified vault on Base, the Ethereum layer-2 network incubated by Coinbase, lost approximately 1,783 wrapped staked Ether (wstETH) — roughly $6 million — on Sunday, October 4, in an attack that security firms say turned on the vault's own access controls rather than on any flaw in Aave or Base themselves.

The incident was flagged in real time by four blockchain security firms, and the on-chain evidence is publicly viewable, which places it among the better-documented incidents of the week even though no operator has come forward to claim the vault.

How the Drain Unfolded

Blockaid was first to report publicly. At 09:20 UTC, the firm posted that an ongoing exploit was hitting an unnamed Base vault: a brand-new contract had been added to the vault's whitelist — the list of addresses permitted to interact with its funds — and had borrowed aBaswstETH, Aave V3's interest-bearing receipt token, forwarding the tokens to an attacker-controlled contract. Blockaid initially estimated $2.02 million had moved across roughly four transactions; a follow-up put losses above $6 million while the attack was still in progress.

PeckShield reported at 09:56 UTC that address 0x0B…dB034 had drained 1,783 wstETH, about $6 million, on Base. CertiK's alert account described a newly deployed proxy contract borrowing roughly 1,783 aBaswstETH from the victim vault and redeeming the tokens through Aave into wstETH held by the attacker. ExVul's count was the most detailed: 1,783.067 aBaswstETH across six outflows, received by contract 0xcd…F569d. One cited transaction is public on BaseScan, and The Crypto Times pieced the firms' timelines into a full account.

The Whitelist Flip

The most significant detail comes from ExVul's follow-up timeline. According to the firm, the vault owner's Safe — a multisignature wallet requiring several approvals per transaction — removed the attacker's contract from the whitelist at 08:52 UTC. One minute later, at 08:53 UTC, the same Safe re-enabled it. Both administrative transactions carried three valid ECDSA signature recoveries under the same signing identities, and the first borrow came about 70 seconds after the re-enable.

That sequence shifts the focus from contract logic to key management: someone or something obtained valid approvals from the Safe's existing signers. Whether signer keys were compromised, a signing process was manipulated, or another failure occurred has not been confirmed by any party. There is no public evidence that Aave's core lending contracts or the Base network itself were compromised.

The Victim and the Loot

The victim contract is a TransparentUpgradeableProxy, a standard OpenZeppelin design, with portfolio trackers showing tens of millions of dollars in Aave V3 positions on Base against substantial borrows — a profile consistent with a managed vault or yield strategy rather than a core Aave market. No team or protocol has publicly identified itself as the operator, and no post-mortem, freeze, recovery effort or bounty has been announced.

On-chain activity shows the attacker's address interacting with the loot contract, routing a withdrawal through the Aave Base pool and later through Lido's wstETH token. Unverified community tracking suggests part of the proceeds began bridging to Ethereum through Lido infrastructure, a process that typically takes days; the attacker address no longer holds a material wstETH balance.

Fourth Incident of the Week on Base-Linked Infrastructure

The drain is the fourth Aave-linked or Base incident in a week. On October 2, a FlashLoopAdapter exploit drained about $305,000 from two Safe wallets running leveraged Aave V3 loops, with Aave's pools used but not broken; a day later, GoldPesa's GPXHooks contract was allegedly drained for about $114,000 on Base. September was already the year's worst month for crypto losses at roughly $766 million, according to CertiK.

The pattern across the cluster is consistent: peripheral infrastructure — loop adapters, hooks, custom vaults and the multisigs that administer them — is failing around DeFi's core rails. Until an operator identifies itself and explains how a contract it had just delisted was re-approved within sixty seconds, the working assumption for every team running a whitelisted vault should be that the signer layer, not the strategy contract, is the asset most worth defending.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.