Base DeFi Vault Hack Reveals Insider Threat Behind $6 Million Theft
A $6 million theft on Coinbase’s Base network was not the result of a bug or exploit, but rather a deliberate action by someone with access to a DeFi vault’s whitelist. At 08:52 UTC on October 4, a Safe wallet managing the vault removed a contract from its whitelist, only to re-add it at 08:53 UTC. Both actions were signed by valid vault signers, indicating no technical flaw, just an insider allowing the attacker in before covering their tracks.
By the time security firm Blockaid detected the activity at 09:21 UTC, roughly $2.02 million had already been stolen. The final loss reached $6 million, involving the transfer of 1,783 wstETH, a liquid-staked ether token. The attacker borrowed aBaswstETH from the vault, moved it to their own infrastructure, and redeemed it for wstETH through Aave V3, leaving Aave’s core contracts untouched.
The vault is governed by a 3-of-7 Safe multisig, requiring three out of seven signers to approve actions. The identities of these signers remain unknown, and the vault had been inactive for 25 days before the sudden whitelist changes. This suggests a compromised or colluding signer, as quiet wallets rarely perform back-to-back administrative actions.
Roughly $31.7 million remains in the vault, still controlled by the same seven signers. The incident highlights a critical flaw in crypto security: smart contract audits and bug bounties cannot prevent insider threats where legitimate signers act maliciously.