Base Vault Exploit Highlights Gaps in Disclosure and Security
A $6 million exploit targeting an unidentified Base vault has highlighted a critical gap in vulnerability disclosure processes, according to Immunefi’s head of security. The incident involved a malicious contract gaining access to the vault and withdrawing approximately 1,783 wstETH tokens. Despite the significant loss, the vault’s operators remained unidentified more than 24 hours after the attack, leaving no public response or remediation plan.
Gonçalo Magalhães, head of security at Immunefi, emphasized that the vault’s whitelist mechanism was insufficient for protection. Approved addresses could withdraw assets without providing collateral, a design flaw that made the vault highly vulnerable. Magalhães noted that the lack of identified operators complicated any whitehat intervention, as researchers risked legal trouble when acting on unidentified projects.
The exploit occurred after the vault had gone 25 days without executing a Safe transaction, raising suspicions of social engineering or collusion. With seven Safe signers still unidentified, Magalhães called for the vault’s controllers to step forward and address the incident. He also stressed that a bug bounty program could have identified the flaw before the attack occurred.
Immunefi’s CEO, Mitchell Amador, previously highlighted the importance of private disclosure and authorization in preventing exploits. He advocated for protocols to establish rescue conditions and reward terms before emergencies arise, referencing Immunefi’s Whitehat Safe Harbor framework as a solution. The company’s August report showed that bug bounties had prevented 374 threats in July alone, underscoring their effectiveness in catching vulnerabilities missed by audits.