Base DeFi Vault Exploit Drains $6M After Attacker Gains Whitelist Access

Wait 5 sec.

TLDR:A Base DeFi vault lost over $6M after an attacker added a new contract to its whitelist and drained assets.Blockaid first estimated $2.02M in losses before raising the total above $6M as the exploit continued.Spot On Chain and PeckShield both traced about 1,783 wstETH to attacker address 0x0B5126…B034 on Base.No evidence shows Aave or Base core systems were breached, while the vault’s root cause remains unconfirmed.A DeFi vault operating on Base has lost over $6 million after an attacker gained whitelist access and used a new contract to extract assets. Blockchain security firm Blockaid first reported the exploit on October 4, estimating about $2.02 million had been drained across roughly four transactions. Blockaid detected an ongoing exploit on an unnamed vault on Base.A brand-new contract was added to the vault's whitelist, then borrowed aBaswstETH from the vault and sent the aTokens to the attacker's contract.~$2.02M drained from the vault so far across ~4 txs. Attack…— Blockaid (@blockaid_) October 4, 2026The alert placed the vault’s authorization controls at the center of the incident. Blockaid said the attacker added a newly created contract to the whitelist, borrowed aBaswstETH, and transferred the resulting aTokens into an attacker-controlled contract. Reported losses then increased as security firms traced more transactions connected to the same address.Loss Estimate Climbs as Attack Remains ActiveBlockaid later raised its estimate above $6 million and said the attack remained active. Spot On Chain separately estimated losses at approximately 1,783 wstETH, worth around $6 million. The firm identified the suspected attacker as 0x0B5126…B034.1,783 wstETH (~$𝟲𝗠) drained on Base in a suspected exploit. Address 0x0B5126…B034 identified as the suspected exploiter wallet; attack method and target protocol not yet disclosed.𝗛𝘂𝗽𝘇𝘆 𝘁𝗮𝗸𝗲: A $6M drain is notable but likely 𝗰𝗼𝗻𝘁𝗮𝗶𝗻𝗲𝗱 to a single Base… pic.twitter.com/a1g9k1s15n— Hupzy (Spot On Chain) (@hupzy_agent) October 4, 2026PeckShield independently also linked that address to the theft of 1,783 wstETH on Base, supporting the estimate. Available evidence places the whitelist mechanism at the center of the exploit sequence.However, investigators have not established how the new contract obtained authorization. A whitelist normally limits interactions to approved contracts or addresses. Here, a newly created contract received approval before the borrowing activity began, according to Blockaid.No public evidence has established whether the approval resulted from an administrative key issue, configuration error, access-control function, or smart-contract vulnerability. The stolen asset connects the incident to Aave liquidity infrastructure, but current evidence does not show that Aave’s core lending contracts were compromised.Evidence Points Away From Core Aave and Base SystemsBaseScan identifies aBaswstETH as Aave Base wstETH. Aave documentation describes aTokens as interest-bearing tokens issued when assets are supplied to its markets. Those tokens represent deposited assets and accrued yield.That distinction keeps the focus on the unidentified vault’s authorization controls rather than Aave’s lending infrastructure. Spot On Chain said broader systemic risk appeared limited, although selling the stolen wstETH could create short-term market pressure.Any effect would depend on where and how quickly the attacker liquidates assets. wstETH is Lido’s non-rebasing version of stETH. Instead of increasing balances as staking rewards accrue, its exchange rate against stETH changes over time. Base is an Ethereum Layer 2 built on the OP Stack.No evidence indicates that the underlying network itself was compromised. The affected vault has not been identified, while no official post-mortem has established the exploit’s root cause. The $6 million loss estimate therefore remains subject to change as investigators trace transactions.The post Base DeFi Vault Exploit Drains $6M After Attacker Gains Whitelist Access appeared first on Blockonomi.