Base DeFi Vault Hit for $6M in Attack Using Whitelist Access
A DeFi vault on Base has lost over $6 million after an attacker gained access to its whitelist and extracted assets. The attack was first reported by Blockaid on October 4, with an initial loss estimate of $2.02 million. However, as the exploit continued, the loss estimate was raised to over $6 million. The attacker used a newly created contract to borrow aBaswstETH from the vault and transfer the resulting aTokens to an attacker-controlled contract. The incident has raised questions about the vault's authorization controls, but the root cause of the attack remains unconfirmed.
The affected vault has not been identified, and no official post-mortem has established the exploit's root cause. The $6 million loss estimate is therefore subject to change as investigators continue to trace transactions. The stolen asset connects the incident to Aave liquidity infrastructure, but current evidence does not show that Aave's core lending contracts were compromised. The security firms Spot On Chain and PeckShield have traced the stolen assets to the attacker's address, 0x0B5126…B034.