chiprook
← Security
SecurityOctober 7, 2026, 19:56

Base DeFi Vault Exploit Drains $6M via Whitelist Access Control Failure

On October 4, 2026, an unnamed DeFi vault on the Base network lost roughly $6 million in wstETH. An attacker manipulated the vault's whitelist through a 3-of-7 Safe multisig, adding a malicious contract that withdrew 1,783 aBaswstETH in 19 minutes and redeemed them via Aave V3.

Base DeFi Vault Exploit Drains $6M via Whitelist Access Control Failure
#Base#Aave#Lido#Safe
Read next
Security

FlashLoopAdapter exploit drains $305K from Aave V3 Safe module

Security

Hacker loses $7.73M to MEV bot in rsETH Safe module exploit

Security

Study: flash loan attackers shift from oracle manipulation to protocol logic exploits

Security

Hacker turns 25 cents into 46 billion fake Bitcoins to steal $770,000 from Symbiosis DeFi exchange