Base vault drained of $6M in Aave deposit tokens after whitelist change

Photo: Rostislav Uzunov / Pexels

Base vault drained of $6M in Aave deposit tokens after whitelist change

An unclaimed vault on Base lost approximately 1,783 wstETH after its multisig approved a malicious borrower in a one-minute window

A DeFi vault on Base lost approximately 1,783 wstETH, valued at around $6 million, on October 4, 2026. The cause was not a clever smart contract bug. It was a change to the vault’s own guest list.

Someone added a malicious contract to the vault’s borrower whitelist. That contract then walked out with Aave deposit tokens. No protocol has yet stepped forward to say the vault belongs to it, which makes the incident awkward to assign blame for.

How the drain unfolded

On October 4, two whitelist changes landed between 08:52 and 08:53 UTC. Both were authorized by the same signers, and both happened within a single minute. The net effect was that a malicious contract earned a spot on the list of approved borrowers.

With that access, the contract borrowed aBaswstETH from the vault. That token is an interest-bearing receipt: proof that someone deposited wstETH into Aave on Base. Holding the receipt means you can redeem it for the underlying asset.

The contract passed those receipts to an attacker address, 0x0B5126e1bc27C0de77e02e97945760A674EdB034. The tokens were then redeemed through Aave for wstETH, the wrapped version of Lido’s staked ether.

Six outflows hit the vault, at 0xD1895f2019c2152FC2b9022D57f19198c4CFCABC, over roughly twenty-five minutes. The first was a test transfer.

Advertisement

Blockaid initially flagged the attack at approximately $2.02 million. The tally grew as the remaining outflows cleared, reaching the approximately 1,783 wstETH figure.

A quiet multisig wakes up

The vault is governed by a 3-of-7 Safe multisig. That means any three of seven designated keyholders must sign off before a change goes through.

This particular multisig had not executed a single transaction in twenty-five days before the attack. Then it suddenly approved two consecutive whitelist edits inside sixty seconds.

It remains unclear how the required signatures were obtained. The possibilities range from compromised keys to signers being tricked into approving something they did not fully understand.

After the drain, the vault still held around $31.7 million in assets.

Where the money went

The stolen aBaswstETH was converted into wstETH. Some stolen funds were reportedly routed through Lido’s Base-to-Ethereum bridge. That route carries a seven-day settlement window, meaning money in that pipe sits in a waiting room for a week before it arrives on the other side.

Aave held, the access layer did not

Aave V3 itself was not compromised. The lending protocol did exactly what it was built to do: it honored valid receipt tokens and paid out the underlying wstETH.

The failure sat one layer up, in how the vault decided who could borrow from it. A breach in a vault built on top of Aave is not the same as a breach of Aave.

What this means

This vault appears to have lacked a meaningful pause between the whitelist change and the moment that change became exploitable. A timelock, which forces a waiting period before admin actions take effect, is one of the standard defenses against exactly this scenario. Its absence turned a governance action into an instant withdrawal permit.

The roughly $31.7 million still sitting in the vault is now governed by the same multisig that approved the malicious borrower. No protocol has publicly claimed the vault, leaving depositors with no obvious party to hold accountable or to coordinate a response.

The next marker to watch is the Lido bridge withdrawal. Once the seven-day settlement window closes, the stolen wstETH arriving on Ethereum will reveal more about the attacker’s next move.

Disclosure: This article was edited by Estefano Gomez. For more information on how we create and review content, see our Editorial Policy.
Base vault drained of $6M in Aave deposit tokens after whitelist change
Base vault drained of $6M in Aave deposit tokens after whitelist change

An unclaimed vault on Base lost approximately 1,783 wstETH after its multisig approved a malicious borrower in a one-minute window

Photo: Rostislav Uzunov / Pexels

A DeFi vault on Base lost approximately 1,783 wstETH, valued at around $6 million, on October 4, 2026. The cause was not a clever smart contract bug. It was a change to the vault’s own guest list.

Someone added a malicious contract to the vault’s borrower whitelist. That contract then walked out with Aave deposit tokens. No protocol has yet stepped forward to say the vault belongs to it, which makes the incident awkward to assign blame for.

How the drain unfolded

On October 4, two whitelist changes landed between 08:52 and 08:53 UTC. Both were authorized by the same signers, and both happened within a single minute. The net effect was that a malicious contract earned a spot on the list of approved borrowers.

With that access, the contract borrowed aBaswstETH from the vault. That token is an interest-bearing receipt: proof that someone deposited wstETH into Aave on Base. Holding the receipt means you can redeem it for the underlying asset.

The contract passed those receipts to an attacker address, 0x0B5126e1bc27C0de77e02e97945760A674EdB034. The tokens were then redeemed through Aave for wstETH, the wrapped version of Lido’s staked ether.

Six outflows hit the vault, at 0xD1895f2019c2152FC2b9022D57f19198c4CFCABC, over roughly twenty-five minutes. The first was a test transfer.

Advertisement

Blockaid initially flagged the attack at approximately $2.02 million. The tally grew as the remaining outflows cleared, reaching the approximately 1,783 wstETH figure.

A quiet multisig wakes up

The vault is governed by a 3-of-7 Safe multisig. That means any three of seven designated keyholders must sign off before a change goes through.

This particular multisig had not executed a single transaction in twenty-five days before the attack. Then it suddenly approved two consecutive whitelist edits inside sixty seconds.

It remains unclear how the required signatures were obtained. The possibilities range from compromised keys to signers being tricked into approving something they did not fully understand.

After the drain, the vault still held around $31.7 million in assets.

Where the money went

The stolen aBaswstETH was converted into wstETH. Some stolen funds were reportedly routed through Lido’s Base-to-Ethereum bridge. That route carries a seven-day settlement window, meaning money in that pipe sits in a waiting room for a week before it arrives on the other side.

Aave held, the access layer did not

Aave V3 itself was not compromised. The lending protocol did exactly what it was built to do: it honored valid receipt tokens and paid out the underlying wstETH.

The failure sat one layer up, in how the vault decided who could borrow from it. A breach in a vault built on top of Aave is not the same as a breach of Aave.

What this means

This vault appears to have lacked a meaningful pause between the whitelist change and the moment that change became exploitable. A timelock, which forces a waiting period before admin actions take effect, is one of the standard defenses against exactly this scenario. Its absence turned a governance action into an instant withdrawal permit.

The roughly $31.7 million still sitting in the vault is now governed by the same multisig that approved the malicious borrower. No protocol has publicly claimed the vault, leaving depositors with no obvious party to hold accountable or to coordinate a response.

The next marker to watch is the Lido bridge withdrawal. Once the seven-day settlement window closes, the stolen wstETH arriving on Ethereum will reveal more about the attacker’s next move.

Disclosure: This article was edited by Estefano Gomez. For more information on how we create and review content, see our Editorial Policy.