Base Vault Loses $6 Million in wstETH After Whitelist Exploit
A DeFi vault on the Base network suffered a significant security breach on October 4, 2026, resulting in the loss of approximately $6 million worth of wstETH. The incident was not due to a smart contract bug but rather a malicious addition to the vault's borrower whitelist. An unknown actor added a harmful contract to the whitelist, allowing it to borrow and drain Aave deposit tokens.
The attack unfolded over roughly twenty-five minutes, with six outflows from the vault. The first was a test transfer, followed by larger withdrawals totaling about 1,783 wstETH. The stolen tokens were converted into wstETH and reportedly routed through Lido's Base-to-Ethereum bridge, which has a seven-day settlement window.
The vault is governed by a 3-of-7 Safe multisig, which had been inactive for twenty-five days before the attack. Suddenly, it approved two consecutive whitelist edits within sixty seconds. The breach highlighted the absence of a timelock mechanism, which would have provided a pause between governance actions and their execution.
As of now, the vault still holds around $31.7 million in assets, but no protocol has publicly claimed responsibility for it. This leaves depositors without a clear party to hold accountable or coordinate a response. The next critical event to watch is the Lido bridge withdrawal, which will reveal the attacker's next move once the settlement window closes.