Skip to content
Base Vault Hack: $6 Million Stolen via Whitelist Exploit

Base Vault Hack: $6 Million Stolen via Whitelist Exploit

First seen 5 Oct 2026, 11:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 12:27 UTC
  • •1,783 wstETH worth $6 million stolen from a vault on Base.
  • •Attacker exploited a whitelist vulnerability by deploying a new contract.
  • •No flaws in Base or Aave's core systems were identified.

On October 4, 2026, a vault on the Ethereum layer-2 network Base was hacked, resulting in the theft of 1,783 wrapped staked Ether (wstETH), valued at approximately $6 million. The attacker gained access to the vault's whitelist by deploying a new contract, which allowed them to borrow assets against the vault's holdings on Aave V3. The attack escalated quickly, with initial loss estimates at $2 million that grew to $6 million as the exploit continued. Security firms Blockaid, PeckShield, and CertiK monitored the incident in real-time, noting that the vault's transaction approval process was compromised. The specific authorization weakness that facilitated the attack remains unidentified. No vulnerabilities in Base or Aave's core contracts were reported. The vault has not issued any public statements regarding the incident.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-04
Initial exploit detected
At 09:20 UTC, Blockaid reported an ongoing exploit on a vault on Base, estimating losses at $2.02 million.
Cryptotimes
2026-10-04
Total losses confirmed
By 09:59 UTC, total losses had escalated to $6 million as the attack continued.
Cryptotimes
2026-10-04
Security firms monitor incident
Multiple security firms, including Blockaid and PeckShield, tracked the exploit in real-time, noting the transaction approvals were compromised.
Tokenpost

More articles in this cluster (3)

Following this threat?

Track Base in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

How did the attacker gain access?
The attacker deployed a new contract that was added to the vault's whitelist, allowing them to borrow assets.
Is the vault's security compromised?
The specific weakness in the vault's transaction approval process has not been identified, but it was exploited in this incident.
What should vault users do now?
Users should review their vault's permission settings and consider implementing stricter controls to prevent unauthorized access.