NewsCryptoBase DeFi Vault Exploit Drains $6 Million After Attacker Gains Whitelist Access

Base DeFi Vault Exploit Drains $6 Million After Attacker Gains Whitelist Access

Author: Blockonomi·

Key Takeaways

  • •An attacker added a newly created contract to the vault's whitelist and used it to borrow aBaswstETH, sending the resulting aTokens to an attacker-controlled contract.
  • •Blockaid's loss estimate rose from roughly $2.02 million to more than $6 million, with the exploit reported as still in progress.
  • •Spot On Chain and PeckShield independently identified address 0x0B5126…B034 as the suspected exploiter and linked it to the theft of 1,783 wstETH.
  • •The root cause of the whitelist breach has not been established, and the affected vault has not been publicly identified.
  • •Analysts see limited systemic risk, though selling the stolen wstETH could create short-term market pressure.
Base DeFi Vault Exploit Drains $6 Million After Attacker Gains Whitelist Access

A decentralized finance vault operating on Base has lost more than $6 million after an attacker gained whitelist access and used a newly created contract to extract assets from the protocol. Blockchain security firm Blockaid first reported the exploit on October 4, estimating at the time that about $2.02 million had been drained across roughly four transactions. The firm later raised its estimate above $6 million and said the attack remained active.

Blockaid detected an ongoing exploit on an unnamed vault on Base. A brand-new contract was added to the vault's whitelist, then borrowed aBaswstETH from the vault and sent the aTokens to the attacker's contract. ~$2.02M drained from the vault so far across ~4 txs. Attack… — Blockaid (@blockaid_) October 4, 2026

The alert placed the vault's authorization controls at the center of the incident. Blockaid said the attacker added the newly created contract to the whitelist, borrowed aBaswstETH, and transferred the resulting aTokens into an attacker-controlled contract. Reported losses then climbed as security firms traced additional transactions connected to the same address.

Loss Estimate Climbs as Attack Remains Active

Blockaid subsequently revised its loss estimate above $6 million and reported that the exploit was still in progress. Spot On Chain separately put the losses at approximately 1,783 wstETH, worth around $6 million, and identified the suspected attacker as address 0x0B5126…B034. The analytics firm noted that the attack method and the target protocol had not yet been disclosed.

1,783 wstETH (~𝟲𝗠) drained on Base in a suspected exploit. Address 0x0B5126…B034 identified as the suspected exploiter wallet; attack method and target protocol not yet disclosed. 𝗛𝘂𝗽𝘇𝘆 𝘁𝗮𝗸𝗲: A $6M drain is notable but likely 𝗼𝗻𝘁𝗮𝗶𝗻𝗲𝗱 to a single Base… pic.twitter.com/a1g9k1s15n — Hupzy (Spot On Chain) (@hupzy_agent) October 4, 2026

PeckShield independently linked the same address to the theft of 1,783 wstETH on Base, lending further support to the estimate. The findings from the two firms corroborate both the scale of the theft and the identity of the suspected exploiter wallet.

Available evidence places the whitelist mechanism at the center of the exploit sequence, though investigators have not established how the new contract obtained authorization. A whitelist normally limits interactions to approved contracts or addresses, a common security control intended to ensure that only vetted code can touch a protocol's funds. Authorization-related failures — where an attacker obtains approved permissions rather than defeating the underlying code — are a recurring category in DeFi security incidents. In this case, a newly created contract received approval before the borrowing activity began, according to Blockaid.

No public evidence has established whether the approval resulted from an administrative key issue, a configuration error, an access-control function, or a smart-contract vulnerability. The stolen asset connects the incident to Aave liquidity infrastructure, but current evidence does not show that Aave's core lending contracts were compromised.

Evidence Points Away From Core Aave and Base Systems

BaseScan identifies aBaswstETH as Aave Base wstETH. Aave documentation describes aTokens as interest-bearing tokens issued when assets are supplied to its markets; tokens represent both the deposited assets and the yield they accrue. That distinction keeps the focus on the unidentified vault's authorization controls rather than on Aave's lending infrastructure — and illustrates how protocols built on top of widely used primitives can still fail at their own permission layer.

Spot On Chain said broader systemic risk appeared limited, although selling the stolen wstETH could create short-term market pressure. Any effect would depend on where and how quickly the attacker liquidates the assets.

wstETH is Lido's non-rebasing version of stETH. Instead of increasing holder balances as staking rewards accrue, its exchange rate against stETH changes over time. Base, for its part, is an Ethereum Layer 2 network built on the OP Stack, and no evidence indicates that the underlying network itself was compromised.

The affected vault has not been publicly identified, and no official post-mortem has yet established the exploit's root cause. Until the operator releases an official account of the event, key questions — including how the attacker obtained whitelist access — remain unanswered. Further developments to watch include identification of the vault's operator, a formal root-cause analysis, and any movement of the stolen wstETH, which Spot On Chain has said could create short-term market pressure if sold. The $6 million loss estimate therefore remains subject to change as investigators continue to trace transactions linked to the incident.

Source: Blockonomi