When money leaves a DeFi vault, headlines often blur two different stories: a failure in the vault’s own access controls, and a failure in the underlying lending protocol. Trade-press and security-firm reporting on this incident draws that line clearly.
On 4 October 2026, an unidentified DeFi vault on Base—Coinbase’s Ethereum layer-2 network—lost roughly 1,783 wstETH, valued at about $6 million, according to Crypto Briefing and overlapping security-firm timelines. [1]
A vault here is a pooled smart-contract account that holds assets and sets who may borrow or withdraw them. wstETH is a wrapped form of Lido-staked ether commonly used as collateral and yield-bearing liquidity.
What was reported to have happened
Crypto Briefing, citing on-chain timelines and security firms such as Blockaid, reports that the vault’s own governance approved a change to who was allowed to borrow from it shortly before the funds left, and that the outflows ran over roughly twenty-five minutes on the morning of 4 October (UTC). [1]
Security firms reported that Aave V3 was not compromised: Aave honoured valid deposit receipts. The failure, in that framing, sat in the vault’s access-control layer above Aave, not in Aave’s core contracts. [1]
Impact, not a how-to
What matters for readers is the outcome and attribution: about $6m in wstETH left an unclaimed vault after a governance whitelist change, while reporters say the lending market underneath behaved as designed. [1]
What remains unclear
No named protocol has publicly claimed ownership of the vault, and Crypto Briefing notes no official protocol post-mortem at the time of writing. How the three Safe signatures were obtained is not established on-chain. Remaining vault balances and bridge-routing claims vary by reporter; treat those as secondary colour, not settled facts. [1]
Why the distinction matters
A vault layered on a lending market can lose funds because of how it decides who may borrow, even when the lending market behaves as designed. That is a different public narrative from “Aave was hacked”—and the reporting here explicitly rejects the latter.
What we don’t know
- Which project (if any) operates the vault; none has claimed it publicly. [1]
- Whether keys were compromised, signers were tricked, or another path produced the three signatures. [1]
- Exact remaining assets and any bridged-fund status beyond trade-press estimates that differ across outlets.
The Bottom Line
Trade press and security firms describe an unidentified Base vault losing about 1,783 wstETH (~$6m) after its multisig whitelisted a new borrower contract, while stating Aave V3 itself was not compromised. Until a named issuer publishes a post-mortem, the honest label is trade-press / investigator reporting, not an official protocol disclosure.
Sources
- Crypto Briefing, Base vault drained after whitelist change — 5 October 2026 (trade press) — https://cryptobriefing.com/base-vault-drained-6m-aave-whitelist/
