Base Vault Exploit Steals $6 Million Leaving Millions More at Risk
A recent exploit on the Base blockchain siphoned approximately $6 million from a vault, while an additional $31.7 million in assets remained at risk when the incident was disclosed on October 5. The attack involved the use of a Safe multisignature wallet, which allowed the attacker to introduce a malicious contract into the vault’s lending whitelist. This contract facilitated the withdrawal of 1,783 aBaswstETH, which was subsequently redeemed through Aave V3 for about 1,783 wstETH.
The breach highlights significant flaws in the vault’s multisignature governance and access controls. Notably, the vault had not processed a Safe transaction for 25 days prior to the attack, raising concerns about the security protocols in place. While theories of social engineering or collusion were discussed, no definitive evidence has been found to confirm either scenario.
The incident underscores the critical importance of robust security measures in decentralized finance (DeFi) platforms. The failure to execute transactions for an extended period before the attack suggests potential lapses in oversight and monitoring. As investigations continue, the crypto community remains vigilant about the risks associated with vulnerabilities in smart contract and governance systems.