An unidentified vault on Base lost approximately 1,783.067 wstETH, worth about $6 million, after a newly deployed contract gained permission to access its Aave V3 position on October 4. Onchain records for the affected vault show that it is controlled by a Safe requiring three of seven owners to authorize transactions. The incident affected a third-party vault and its permissioning structure, not Base or Aave V3’s core contracts.
Security researchers traced six withdrawals of aBaswstETH, the Aave receipt token representing supplied wstETH on Base. The sequence began with a one-token test before escalating through larger transfers totaling 1,783.067 aBaswstETH, which the attacker subsequently redeemed for the underlying wstETH. The amount removed from the vault is the approximately $6 million loss estimate, rather than the much larger value of the vault’s remaining Aave positions.
Valid Safe Signatures Leave the Root Cause Unresolved
The most unusual part of the incident occurred immediately before the drain. Onchain analysis indicates that the attacker’s newly created contract was removed from the vault’s whitelist at approximately 08:52 UTC and added back roughly one minute later. Both operations were executed through the controlling Safe with the required three valid owner signatures. Investigators can therefore identify how the malicious contract received permission, but not yet why three authorized signatures approved that change.
That distinction prevents the incident from being conclusively classified as a smart-contract access-control bug. No public evidence currently establishes whether private keys were compromised, signers were deceived, the signing workflow was manipulated or another authorization failure occurred. A cryptographically valid multisig transaction proves that the Safe’s threshold was satisfied, not that the human owners intended the resulting action.
Once whitelisted, the contract could access the vault’s Aave position and transfer the aBaswstETH before redeeming it through Aave. The pattern differs from the recent FlashLoopAdapter exploit, where faulty module authentication directly exposed two Safe wallets, but both incidents show how delegated permissions can become the effective security perimeter around otherwise functioning protocols. Using Aave inside a managed vault does not make the vault’s own governance and authorization code part of Aave’s security guarantees.
A similar boundary appeared when a third-party SquidRouterModule exposed 86 Safe wallets. In that case, execution rights granted to an auxiliary module enabled the drain without compromising Safe’s base multisig contracts. The recurring risk is privileged infrastructure layered around wallets, not evidence that multisig cryptography itself has failed.
Stolen wstETH Begins Moving Off Base
PublicAML’s onchain tracking subsequently reported that the attacker obtained transaction gas through Tornado Cash-linked activity and divided the stolen assets after the drain. Roughly 1,001 wstETH was routed toward Lido bridging infrastructure for transfer to Ethereum, while approximately 782 wstETH remained on Base at the time of the tracker’s snapshot. Those movements describe the post-exploit disposition of the stolen assets and do not change the underlying 1,783.067 wstETH loss total.
Base vault drain ($6M wstETH), followed on chain.
• Both Safe transactions that whitelisted the attacker's contract carry 3 valid owner signatures
• Gas came from Tornado Cash, 2.5 hours before the first token moved
• 1,001 wstETH is in the Lido bridge's 7-day window to…— PublicAML (@PublicAML) October 4, 2026
The vault itself still held substantial positions after the attack. Public reporting put its remaining assets at approximately $31.7 million, but that figure should not be described as an additional confirmed loss or automatically added to the incident total. Remaining TVL is not the same as assets successfully exposed or stolen, just as assets protected during the recent legacy Magic Eden approval exploit had to be separated from actual attacker proceeds.
No protocol, fund or company has publicly claimed ownership of the vault, and the seven Safe signers remain unidentified in public reporting. No official post-mortem or reimbursement plan has been published either. The confirmed picture is therefore narrower than an Aave or Base exploit: a privately controlled vault authorized a contract that subsequently removed roughly $6 million, while the reason those permissions were granted remains unresolved.
