Mysterious $6M Exploit Rocks Coinbase Ethereum Layer Two Protocol
A mysterious exploit occurred on October 4th at 09:21 UTC, involving a vault controlled by a 3-of-7 Safe on Coinbase's Ethereum layer two (L2) protocol, Base. The incident began with a loss of approximately $2.02 million, which quickly escalated to over $6 million within 40 minutes. The security firms Peckshield, Certik, and Exvul all converged on a tally of 1,783.067 aBaswstETH borrowed from the vault and redeemed through Aave on Base into about 1,783 wstETH.
The tokens taken were Aave receipt tokens representing wrapped staked ether deposited on the L2 Base. A newly created contract was added to the vault's whitelist, borrowed those receipt tokens, moved them to an attacker-controlled contract, and redeemed them through Aave for the underlying wstETH. Exvul counted six outflows, but the precise authorization failure remains unconfirmed.
The drained vault is an Openzeppelin transparent proxy whose owner points to a Safe created about 324 days ago. This Safe requires three of seven signatures to act, but it carries no public protocol name, and none of its seven signer addresses has been publicly identified by the security firms tracking the incident.