www.cryptotimes.io Base Vault Hack: $6 Million Stolen via Whitelist Exploit
Article Content
- •1,783 wstETH worth $6 million stolen from a vault on Base.
- •Attacker exploited a whitelist vulnerability by deploying a new contract.
- •No flaws in Base or Aave's core systems were identified.
On October 4, 2026, a vault on the Ethereum layer-2 network Base was hacked, resulting in the theft of 1,783 wrapped staked Ether (wstETH), valued at approximately $6 million. The attacker gained access to the vault's whitelist by deploying a new contract, which allowed them to borrow assets against the vault's holdings on Aave V3. The attack escalated quickly, with initial loss estimates at $2 million that grew to $6 million as the exploit continued. Security firms Blockaid, PeckShield, and CertiK monitored the incident in real-time, noting that the vault's transaction approval process was compromised. The specific authorization weakness that facilitated the attack remains unidentified. No vulnerabilities in Base or Aave's core contracts were reported. The vault has not issued any public statements regarding the incident.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Base in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
How did the attacker gain access?
Is the vault's security compromised?
What should vault users do now?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…