Base vault ~$6m loss: whitelist change, not an Aave core breach

Published:

When money leaves a DeFi vault, headlines often blur two different stories: a failure in the vault’s own access controls, and a failure in the underlying lending protocol. Trade-press and security-firm reporting on this incident draws that line clearly.

On 4 October 2026, an unidentified DeFi vault on Base—Coinbase’s Ethereum layer-2 network—lost roughly 1,783 wstETH, valued at about $6 million, according to Crypto Briefing and overlapping security-firm timelines. [1]

A vault here is a pooled smart-contract account that holds assets and sets who may borrow or withdraw them. wstETH is a wrapped form of Lido-staked ether commonly used as collateral and yield-bearing liquidity.

What was reported to have happened

Crypto Briefing, citing on-chain timelines and security firms such as Blockaid, reports that the vault’s own governance approved a change to who was allowed to borrow from it shortly before the funds left, and that the outflows ran over roughly twenty-five minutes on the morning of 4 October (UTC). [1]

Security firms reported that Aave V3 was not compromised: Aave honoured valid deposit receipts. The failure, in that framing, sat in the vault’s access-control layer above Aave, not in Aave’s core contracts. [1]

Impact, not a how-to

What matters for readers is the outcome and attribution: about $6m in wstETH left an unclaimed vault after a governance whitelist change, while reporters say the lending market underneath behaved as designed. [1]

What remains unclear

No named protocol has publicly claimed ownership of the vault, and Crypto Briefing notes no official protocol post-mortem at the time of writing. How the three Safe signatures were obtained is not established on-chain. Remaining vault balances and bridge-routing claims vary by reporter; treat those as secondary colour, not settled facts. [1]

Why the distinction matters

A vault layered on a lending market can lose funds because of how it decides who may borrow, even when the lending market behaves as designed. That is a different public narrative from “Aave was hacked”—and the reporting here explicitly rejects the latter.

What we don’t know

  • Which project (if any) operates the vault; none has claimed it publicly. [1]
  • Whether keys were compromised, signers were tricked, or another path produced the three signatures. [1]
  • Exact remaining assets and any bridged-fund status beyond trade-press estimates that differ across outlets.

The Bottom Line

Trade press and security firms describe an unidentified Base vault losing about 1,783 wstETH (~$6m) after its multisig whitelisted a new borrower contract, while stating Aave V3 itself was not compromised. Until a named issuer publishes a post-mortem, the honest label is trade-press / investigator reporting, not an official protocol disclosure.

Sources

  1. Crypto Briefing, Base vault drained after whitelist change — 5 October 2026 (trade press) — https://cryptobriefing.com/base-vault-drained-6m-aave-whitelist/
TSN
TSNhttps://tsnmedia.org/
Welcome to TSN. I'm a data analyst who spent two decades mastering traditional analytics—then went all-in on AI. Here you'll find practical implementation guides, career transition advice, and the news that actually matters for deploying AI in enterprise. No hype. Just what works.

Related articles

Recent articles