Base DeFi Vault Hacked $6 Million in 19 Minutes
On October 4, 2026, a DeFi vault on Base, the Ethereum layer-2 network incubated by Coinbase, suffered a $6 million loss in wrapped staked Ether (wstETH). The attack exploited a vulnerability in the vault's lending whitelist, which was manipulated to allow an unknown contract to drain funds. Security firms like PeckShield and GoPlus Security detected the breach within an hour, but as of October 7, no one has identified the vault's operator, frozen the funds, or recovered any losses.
The incident unfolded in just 19 minutes. At 08:52 UTC, a Safe multisignature wallet removed a newly deployed contract from the vault's whitelist. One minute later, the same contract was re-added, granting it permission to interact with the vault. The attacker then withdrew 1,783.067 aBaswstETH and redeemed it for approximately 1,783 wstETH through Aave V3. Despite the quick detection, the lack of a clear resolution highlights ongoing challenges in DeFi security.
The attack did not target Aave's core lending contracts or the Base network itself. Instead, it exploited the vault's governance logic, specifically the whitelist mechanism. This access-control pattern, while standard, can be dangerous if not properly managed. The Safe multisig, designed to prevent single points of failure, failed to stop the breach because the whitelist change appeared routine.
Security researchers note that this incident is part of a broader pattern in 2026, where attackers increasingly focus on permission lists, multisig approvals, and access controls rather than exploiting bugs in smart contract code. This shift has significant implications for how DeFi protocols, auditors, and depositors assess and manage risk moving into 2027.