A $6 million cryptocurrency vault was drained on Base, Coinbase's Ethereum layer two protocol, on October 4. Security firms including Blockaid, Peckshield, Certik, and Exvul traced approximately 1,783 wstETH (wrapped staked ether) removed from the vault within roughly 40 minutes of the initial detection.
The incident's most unusual aspect is the vault's ownership structure. Onchain records indicate the vault is controlled by a 3-of-7 Safe—a multisignature contract requiring three of seven signatures to authorize actions—whose seven signers have not been publicly identified. No protocol or organization has claimed ownership of the vault.
How the Theft Occurred
According to security firms, the attackers borrowed 1,783.067 aBaswstETH (Aave receipt tokens representing staked ether on Base) from the vault. These tokens were then moved to an attacker-controlled contract and redeemed through Aave for the underlying wstETH.
The mechanism involved adding a newly created contract to the vault's whitelist, a step that security researchers have identified but whose authorization failure remains unconfirmed. Exvul counted six separate token outflows from the vault.
What Was Not Compromised
Base itself was not hacked, and security firms have not attributed the theft to compromised Aave core contracts. The precise cause—whether a stolen credential, faulty permissions, or another vulnerability—has not been confirmed by investigators.
The Anonymous Architecture
The drained vault is an OpenZeppelin transparent proxy owned by a Safe created approximately 324 days ago. Upgrade authority is controlled through a separate contract layer. The vault's address is 0xD1895f2019c2152FC2b9022D57f19198c4CFCABC, and its Safe owner is 0x6b27512a5943Ed327f6cb6C3EC1f0398229f42C4.
While onchain records make the vault, its owner contract, and the seven signing addresses visible to investigators, the identity of the people or organization behind these addresses remains unknown. No public team has provided information about the vault's purpose or ownership.
Systemic risk appears contained, though the sale of stolen wstETH could create near-term pressure on its price. The incident remains under investigation with no confirmed account of the exact cause.


