A crypto vault on Coinbase's Base network lost more than $6 million on Oct. 4, yet no protocol has claimed it. Security firms traced the stolen funds to a freshly whitelisted contract, while onchain records point to an anonymous seven-signer Safe as the vault's owner.
Losses Blew Past $6 Million in 40 Minutes
Blockaid spotted what looked like an exploit unfolding on a Base vault at 09:21 UTC on Oct. 4, when about $2.02 million had already drained out. Roughly 40 minutes later, security firms traced about 1,783 wstETH taken from the vault, pushing the loss past $6 million.
No protocol has stepped forward to claim the vault. Base itself was not hacked, and Aave's core contracts have not been blamed for the incident.
A Freshly Whitelisted Contract Moved the Tokens
Peckshield, Certik and Exvul converged on the same tally: 1,783.067 aBaswstETH was borrowed from the vault and redeemed through Aave into roughly 1,783 wstETH. Those receipt tokens represented wrapped staked ether deposited on Base.
A newly created contract was added to the vault's whitelist, then it borrowed the receipt tokens, moved them to an attacker-controlled contract, and redeemed them through Aave for the underlying wstETH. Exvul counted six outflows, but the precise authorization failure remains unconfirmed.
Seven Signers, Zero Names
Onchain records show the drained vault is an Openzeppelin transparent proxy owned by a Safe created about 324 days ago. That Safe requires three of seven signatures to act, yet none of its seven signer addresses has been publicly identified.
Investigators can see the vault, its owner contract, the signing addresses and the token trail. What they cannot see is the organization behind those addresses, or whether the whitelist change came from stolen credentials, a white hacker, or faulty permissions. Systemic risk appears contained for now, though unloading the stolen wstETH could put near-term pressure on its peg.
Source: Bitcoin News
Trading involves risk.