Base Vault Exploit Drains $6 Million via Multisig Whitelist Manipulation
On October 4, 2026, an attacker successfully drained approximately $6 million, or 1,783 wstETH, from a vault deployed on the Base network. The exploit was made possible through the manipulation of a Safe multisig whitelist, a security measure designed to restrict which addresses can interact with the vault’s funds. The attacker altered the authorized address list, allowing them to redirect the wstETH holdings to their own address.
The incident highlights a growing trend in DeFi exploits targeting multisig and access-control infrastructure, rather than traditional smart contract vulnerabilities. Safe, formerly known as Gnosis Safe, is a widely used multisig wallet infrastructure in DeFi, making such exploits particularly concerning. The attack could have been facilitated either by a flaw in the smart contract logic governing the whitelist or by a compromise of the signing keys required to approve changes.
At the time of writing, no official statement had been issued by the team or protocol linked to the affected vault, leaving key details about the vault’s operator unconfirmed. wstETH, or wrapped staked ether, allows holders to earn Ethereum staking rewards while maintaining a transferable token for use in DeFi. This exploit is economically equivalent to losing the underlying staked ether position, underscoring its severity.
Security researchers have increasingly warned about the risks associated with whitelist and permission management systems, noting that a single successful manipulation can grant an attacker the same control over a vault’s funds as a legitimate signer. This incident adds to a series of DeFi exploits in 2026 that have specifically targeted these systems.