Unidentified Base Network Vault Exploited for $6 Million via Whitelist Vulnerability

AI Market Summary
An unnamed Base vault was exploited for ~$6M after an attacker used a Safe multisig to whitelist a malicious lending contract, then withdrew 1,783 aBaswstETH and swapped into wstETH via Aave V3. The incident highlights governance/whitelist design risk where approved addresses can pull assets without collateral, and the lack of timely disclosure/remediation amplifies counterparty concerns across Base and ETH DeFi.
Impact level
● Medium
Affected assets
ETH/USDT-3.65%
AI Insight · ETH/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
According to reports from Odaily Planet Daily on Dec. 12, an unidentified vault on the Base network suffered a $6 million exploit. Gonçalo Magalhães, Head of Security at Immunefi, revealed that the attacker utilized a Safe multisig wallet to add a malicious contract to the vault's lending whitelist. This maneuver allowed the perpetrator to withdraw 1,783 aBaswstETH, which were subsequently swapped for wstETH via Aave V3. Despite the attack, approximately $31.7 million remained in the vault. Magalhães noted that while the whitelist mechanism appeared secure, it permitted approved addresses to withdraw assets without collateral. Although researchers had identified the vulnerability during the week of Dec. 4, a lack of clear disclosure channels delayed reporting. As of Dec. 12, more than 24 hours after the incident, no project team has claimed responsibility for the vault or announced remediation plans.