DeFi Vault on Base Hacked for $6 Million in wstETH
A recent attack on a decentralized finance (DeFi) vault operating on Base, Ethereum's layer-2 network, has resulted in losses exceeding $6 million. The incident occurred on October 4, with Blockaid and PeckShield reporting the incident in quick succession.
The attacker exploited a flaw in the vault's access control by adding a new contract to the whitelist, which permits transactions from pre-approved contracts or addresses. This allowed the attacker to borrow 'aBaswstETH' from the vault and transfer it to another contract under their control.
aBaswstETH is an interest-bearing token representing wstETH deposited into the Base market of the lending service Aave, reflecting both the underlying principal and accrued yield. The attack vector appears to be a flaw in the vault's approval management, with multiple possibilities existing for how the new contract obtained approval.
On-chain analytics firm Spot On Chain independently tracked the losses and indicated that approximately 1,783 wstETH was drained, worth roughly $6 million. The firm identified a wallet address suspected of belonging to the attacker as '0x0B5126…B034.'