Unidentified Base Network Vault Exploited for $6 Million via Whitelist Vulnerability
AI مارکیٹ کا خلاصہ
An unnamed Base vault was exploited for ~$6M after an attacker used a Safe multisig to whitelist a malicious lending contract, then withdrew 1,783 aBaswstETH and swapped into wstETH via Aave V3. The incident highlights governance/whitelist design risk where approved addresses can pull assets without collateral, and the lack of timely disclosure/remediation amplifies counterparty concerns across Base and ETH DeFi.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
ETH/USDT-2.94%
AI تجزیاتی سمجھ · ETH/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
According to reports from Odaily Planet Daily on Dec. 12, an unidentified vault on the Base network suffered a $6 million exploit. Gonçalo Magalhães, Head of Security at Immunefi, revealed that the attacker utilized a Safe multisig wallet to add a malicious contract to the vault's lending whitelist. This maneuver allowed the perpetrator to withdraw 1,783 aBaswstETH, which were subsequently swapped for wstETH via Aave V3. Despite the attack, approximately $31.7 million remained in the vault. Magalhães noted that while the whitelist mechanism appeared secure, it permitted approved addresses to withdraw assets without collateral. Although researchers had identified the vulnerability during the week of Dec. 4, a lack of clear disclosure channels delayed reporting. As of Dec. 12, more than 24 hours after the incident, no project team has claimed responsibility for the vault or announced remediation plans.