Base's Week: Four Incidents Around Aave-Linked Infrastructure

The $6 million wstETH vault drain covered separately today was not an isolated event — it capped a week in which peripheral infrastructure around Aave V3 and Base failed repeatedly.

On October 2, a FlashLoopAdapter exploit drained about $305,000 (114 ETH) from two Safe wallets running leveraged Aave V3 loop strategies, according to The Crypto Times; Aave's core pools were used in the attack but not broken. A day later, on-chain investigator Defimon linked a drain of roughly $114,000 from GoldPesa's GPXHooks contract to a Uniswap v4-style hook transaction, with proceeds moving through USDT across Solana and BNB Chain, The Crypto Times reported — the project has not confirmed the loss, hence "alleged."

Then came Sunday's $6 million vault drain, executed after the vault's own Safe multisig removed and re-enabled the attacker's contract within sixty seconds, per ExVul's timeline. Nothing in the cluster implicates Aave's core contracts or Base itself; everything in it implicates adapters, hooks, custom vaults and the signer layers that control them. For defenders, the week is a single lesson restated four times: the attack surface has moved to the edges.

CertiK Confirms September as 2026's Worst Month

CertiK's loss dashboard, marked updated October 3, recorded approximately $766 million in September losses — the worst month of the year — and about $1.27 billion for the third quarter as a whole, per the dashboard and The Crypto Times' accounting. The September figure is dominated by the Bitget hot-wallet breach ($387.5 million) and the Liquid Network exploit ($320 million), the latter partially reversed when the actors returned 3,400 BTC, roughly 85% of the bitcoin withdrawn.

A caveat worth keeping attached to all such totals: they measure incident value at detection time, not funds permanently lost after recoveries, freezes and negotiations. The gap between the two numbers is exactly where the NEAR Intents full recovery — and whatever is eventually recovered from Bitget — will show up.

Checkpoints Today

  • Bitget: Withdrawal restoration is complete — the exchange announced October 2 that all remaining token withdrawals, fiat rails and customer-to-customer services had resumed, closing out the phased recovery that began September 28.
  • Multisig hygiene: The Base vault incident is the second this month (after the FlashLoop Safes) where the compromise sat in the signer layer of a Safe rather than in contract logic. Time-locked execution and a second approval path for whitelist changes remain the cheapest defenses available.
  • NEAR Intents: Back in full operation after the $3.8 million exploit was returned in full and the probe closed October 2.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.