Timeline
- 7.5
Base Vault Drained of About $6 Million in Aave Deposit Tokens
A vault on Base was drained of roughly $6 million in Aave deposit tokens through six outflows that followed a change to the vault's borrower whitelist. The proceeds were redeemed for wstETH, and some of those funds subsequently entered bridge withdrawals toward Ethereum. On-chain reporting indicates the cause was not a smart contract bug but a change to the vault's borrower whitelist, where a malicious contract was added — highlighting access-control configuration as an attack surface for DeFi vault users on Base. On-chain data cited in reports shows the newly deployed contract was removed from the whitelist and added back about one minute later, after which the unauthorized borrowing began; the six outflows and the later bridging suggest deliberate execution rather than accidental misconfiguration. One report put the amount lost at roughly 1,783 wstETH.
- 7.0
PeckShield: Losses from Base vault attack expand to about $6 million
PeckShield monitoring shows that losses from an attack on an unnamed vault on Base have grown to about $6 million, roughly 1,783 wstETH. The figure is an escalation from the roughly $2.02 million that Blockaid had flagged earlier in the same incident. According to Foresight News' earlier report citing Blockaid, a new contract was added to the vault's whitelist, and the attacker borrowed aBaswstETH from the vault and sent aTokens to that contract, draining about $2.02 million across roughly four transactions. PeckShield's latest figure of about $6 million, or about 1,783 wstETH, indicates the drain grew beyond that initial total; the vault has not been publicly named.