A DeFi vault operating on Base suffered losses exceeding $6 million after an attacker gained whitelist access and used a newly created contract to extract assets. Blockchain security firm Blockaid first detected the exploit on October 4, initially reporting approximately $2.02 million drained across roughly four transactions before revising the estimate upward.
According to Blockaid's analysis, the attacker added a new contract to the vault's whitelist, borrowed aBaswstETH from the vault, and transferred the resulting aTokens to an attacker-controlled contract. The authorization mechanism appears central to the exploit sequence, though investigators have not yet established how the new contract obtained approval.
Loss Estimate Rises as Investigation Continues
Security analysts from Spot On Chain and PeckShield independently traced approximately 1,783 wstETH to the suspected attacker address 0x0B5126…B034 on Base, corroborating the $6 million loss estimate. Blockaid indicated the attack remained active as losses continued to climb.
The stolen asset, aBaswstETH, is Aave's interest-bearing token representing wstETH supplied to its Base market. Current evidence does not indicate that Aave's core lending contracts were compromised. Instead, the incident appears isolated to the unidentified vault's authorization controls.
Root Cause Remains Unconfirmed
Investigators have not established whether the whitelist approval resulted from an administrative key issue, configuration error, access-control function, or smart-contract vulnerability. No evidence suggests that Base's underlying network was compromised.
The affected vault has not been publicly identified, and no official post-mortem has established the exploit's root cause. Spot On Chain noted that broader systemic risk appeared limited, though potential market impact would depend on where and how quickly the attacker liquidates the stolen wstETH.


