Base Vault Hack Results in $6 Million Loss via Permission List Exploit
On October 4, 2026, a vault on the Ethereum layer 2 network Base was drained of approximately 1,783 wstETH, worth around $6 million at the time. The attack did not exploit a flaw in Aave's protocol but rather manipulated the vault's permission list, allowing the attacker to borrow and redeem deposits for Ether derivatives.
The incident began at 08:52 UTC when a Safe wallet removed a contract from the whitelist, only to re-add it a minute later. Both transactions carried valid signatures. By 09:20 UTC, the damage estimate reached $2.02 million, escalating to $6 million as the outflow continued. Security firms like Blockaid, PeckShield, CertiK, and ExVul documented the sequence minute by minute, though the vault's operator has not issued a statement.
The attack exploited the permission list rather than a protocol flaw. The attacker gained access by adding their contract to the whitelist, allowing it to behave like any other approved contract. The permission list was changed twice within a minute, suggesting deliberate manipulation. Analysts speculate that either existing signer keys were compromised or the approval process was manipulated.
The vault operated on a Safe multisig with a three-of-seven threshold, meaning any three of the seven stored keys could approve transactions. This design protects against individual key loss but offers little defense if multiple keys are controlled by a single entity. The absence of a timelock between permission changes and their implementation allowed the attacker to act swiftly.
Despite the breach, an eight-figure sum remained in the vault, reportedly around $31.7 million, under the same permission structure. The incident highlights the importance of access control and the risks associated with permission lists in DeFi vaults.