Base Network Vault Exploit Results in $6 Million wstETH Loss
On October 4, 2026, an exploit on an unnamed vault within the Ethereum Layer 2 network Base resulted in a loss of approximately $6 million worth of wstETH. The incident was reported by blockchain security firms PeckShield and Blockaid, which monitored the ongoing attack.
The vault, which operates by allowing pre-approved contracts to manage and lend assets, was compromised when a newly created contract was added to its whitelist. This contract then borrowed aBaswstETH from the vault and transferred it to the attacker’s control. The aBaswstETH, a token issued by the decentralized finance (DeFi) lending protocol Aave, represents deposited wstETH on Base.
Security firms confirmed that the attacker converted the aBaswstETH into wstETH through Aave, effectively draining 1,783 wstETH from the vault. The wstETH is a liquid staking token derived from stETH, which users receive when staking ETH through the Lido protocol. Blockaid initially reported that around $2.02 million was siphoned off in four transactions before the attack escalated.
While the attacker’s method of obtaining whitelist permissions remains unclear, the incident did not appear to compromise the Base network itself. The attack was confined to the vault’s operations, leveraging Aave’s standard withdrawal process to transfer the assets.