Base Vault Loses $6 Million in Exploit on October 4
A security incident at Base, an Ethereum layer-2 network, resulted in a loss of over $6 million on October 4. The incident occurred on a multisignature crypto vault, which is a wallet that requires multiple signatures to approve transactions. The vault in question used a Safe configuration, which requires three out of seven signers to approve transactions. The attacker borrowed wstETH, a wrapped stETH token, from the vault and exchanged it for wstETH through Aave, a decentralized lending platform. The specific authorization weakness that enabled the transactions has not been established.
The incident is centered around the vault and its transaction approvals, with no evidence of a breach of Base's core contracts or Aave's core contracts. The identities of the seven signers have not been made public. The incident highlights the importance of robust security measures in the crypto space.