A previously unidentified crypto vault on Base lost approximately 1,783 wrapped staked Ether, worth about $6 million, Sunday after a newly deployed contract gained permission to interact with the vault and pulled assets tied to an Aave V3 position.
Security monitoring firm Blockaid first flagged the incident at about 09:20 UTC, when the estimated loss was roughly $2 million. Subsequent tracing by multiple security researchers put the total near 1,783 wstETH. The loss estimate therefore increased materially while investigators were still reconstructing the transactions. The Crypto Times
The affected vault appears to be controlled through a 3-of-7 Safe multisignature wallet. The identities of the seven signers and the entity behind the vault had not been publicly established by scan time. That missing attribution is important. The incident should not be described as a hack of Base, Coinbase, Aave or Safe without additional evidence. TokenPost
The transaction path described by security researchers centers on a newly deployed contract that was added to the vault’s whitelist. That contract borrowed aBaswstETH, the Aave receipt token associated with wstETH supplied on Base, and moved the position into an attacker-controlled contract. The assets were then redeemed into approximately 1,783 wstETH. The Crypto Times
Public reporting and the available security analysis have not established how the new contract obtained whitelist authorization. A compromised signer, malicious approval, governance failure and other possibilities remain hypotheses until the authorization path is reconstructed. The evidence currently establishes the movement of assets and the role of the whitelisted contract, not the root cause.
The distinction matters for systemic risk. Aave’s lending contracts were used in the transaction path, but no evidence available at scan time showed that Aave V3 itself was compromised. The same applies to Base’s core network infrastructure. The incident is presently best classified as a vault-specific security failure. Gate.com
The attacker-controlled address and subsequent movement of the wstETH are now the main recovery trail. An exchange deposit would establish that the assets reached an exchange, but would not by itself prove a sale. Movement through bridges, swaps or privacy infrastructure would similarly need to be described transaction by transaction.
TOKEN RECON ASSESSMENT
The most consequential signal is not the $6 million figure. It is that a high-value vault protected by a 3-of-7 multisig still appears to have authorized a contract capable of extracting the position.
Multisig security is only as strong as the permissions and transaction controls surrounding it. If the whitelist change was validly approved by the required signers, investigators need to determine why those approvals were issued. If the threshold was bypassed or signer access was compromised, the incident becomes a different class of operational-security failure.
Sources
CryptoTimes, Base Vault Hack: $6M in wstETH Drained After Attacker Gains Whitelist Access
Bitcoin.com News, $6M Vanishes From Crypto Vault Controlled by 7 Mystery Signers