Base Vault Hacked for $6M in wstETH via Aave-Linked Exploit
An unknown vault on Base, the Ethereum layer-2 (L2) network incubated by Coinbase, was hacked on October 4, 2026, with the attacker gaining whitelist access and draining about 1,783 wrapped staked Ether (wstETH), worth roughly $6 million. The loss grew from about $2 million to $6 million while the attack was still in progress.
The attacker leveraged Aave V3 borrowing, marking the fourth Aave-linked exploit on Base within a week, raising systemic risk concerns. Multisig whitelist reversal suggests compromised signer approvals, prompting industry calls for stricter governance on decentralized finance contracts.
The victim contract is a TransparentUpgradeableProxy, a standard OpenZeppelin smart contract design, and has held large Aave V3 positions on Base, with tens of millions of dollars in supplied assets against substantial borrows. No team or protocol has publicly identified itself as the vault's operator.
The incident adds to a run of exploits involving Aave-linked infrastructure and Base, with September 2026 being the year's worst month for crypto losses at about $766.4 million, according to CertiK.