← Base Chain Vault Hack (October 2026)1 decision on this page
Audit log
Every state-changing event for Base Chain Vault Hack (October 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-10-04 20:04:14ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 453,358,520
- sig
3Zo2rdPuJjwK…77PiiLKKexplorer ↗- hash
GiNL27dKWSjq…Kbb3ckuZsha256 → base58
verifying row…full verify ↗canonical bytes (12285 B) ▸
{"actor":"system:backfill","investigation_id":"bd7ff93e-3a99-43f0-86f2-f30168ec78d8","kind":"publish","page_slug":"base-chain-vault-hack-october-2026","published_at":"2026-10-04T20:04:14.483Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Base Chain Vault Hack (October 2026)","sections":[{"content":"At approximately 08:52 UTC on October 4, 2026, the vault's multisig removed a newly deployed contract from its own asset whitelist, then re-added (re-enabled) that same contract roughly one minute later at 08:53 UTC, according to on-chain analysis by the security firm ExVul. Approximately 70 seconds after re-enabling, at around 09:04 UTC, the whitelisted contract executed the first of several borrow transactions against the vault's Aave V3 position on Base, pulling out 1,783.067 aBaswstETH (Aave's interest-bearing receipt token representing wrapped staked ether deposited on Base). The borrowed receipt tokens were transferred to an attacker-controlled contract and subsequently redeemed through Aave for the underlying wstETH, worth roughly $6 million at the time. The destination attacker address has been identified on-chain as 0x0B5126e1bc27C0de77e02e97945760A674EdB034, and the drained vault contract has been identified as an OpenZeppelin TransparentUpgradeableProxy at address 0xD1895f2019c2152FC2b9022D57f19198c4CFCABC. The security firm ExVul stated that both the whitelist-removal and whitelist-re-enabling transactions showed valid ECDSA signature recoveries matching the vault's existing signing identities, meaning the suspicious one-minute reversal was approved through what appeared to be legitimate multisig signatures rather than a forged or replayed transaction, leaving open the question of whether a signer's key, device, or approval process was itself compromised.","heading":"The Exploit","severity":"critical","sources":[{"credibility":2,"name":"Base Vault Hack: $6M in wstETH Drained After Attacker Gains Whitelist Access","type":"news_article","url":"https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/"},{"credibility":2,"name":"$6M Vanishes From Crypto Vault Controlled by 7 Mystery Signers","type":"news_article","url":"https://news.bitcoin.com/security/6m-vanishes-from-crypto-vault-controlled-by-7-mystery-signers/"},{"credibility":2,"name":"Over $6 million stolen from Base anonymous multi-signature wallet","type":"news_article","url":"https://www.kucoin.com/news/flash/over-6m-stolen-from-base-anonymous-multi-signature-wallet"}]},{"content":"The security monitoring firm Blockaid first flagged the exploit publicly at approximately 09:20–09:21 UTC on October 4, 2026, when the loss was initially estimated at roughly $2.02 million. Within about 40 minutes, by approximately 09:56–10:09 UTC, independent confirmations from PeckShield, CertiK, and ExVul converged on a figure of 1,783 wstETH drained, worth approximately $6 million — nearly three times the initial estimate. The rapid upward revision reflects the fact that the attack involved multiple sequential outflows (six documented withdrawals) rather than a single transaction, and that loss trackers updated their totals as each subsequent withdrawal was identified on-chain while the incident was still unfolding.","heading":"Escalating Loss Estimate During Live Incident","severity":"high","sources":[{"credibility":2,"name":"Data: Base Chain Vault Attack Losses Expand to About $6 Million","type":"news_article","url":"https://panews.io/articles/01a10663-a8a7-7095-a5c8-0cd0a78ca94d"},{"credibility":2,"name":"$6M Vanishes From Crypto Vault Controlled by 7 Mystery Signers","type":"news_article","url":"https://news.bitcoin.com/security/6m-vanishes-from-crypto-vault-controlled-by-7-mystery-signers/"},{"credibility":2,"name":"Base Vault Attack Drives Reported Losses to About $6 Million","type":"news_article","url":"https://www.tokenpost.com/news/technology/26653"}]},{"content":"The vault is governed by a Safe (formerly Gnosis Safe) smart contract wallet at address 0x6b27512a5943Ed327f6cb6C3EC1f0398229f42C4 requiring 3 of 7 signatures to execute transactions, deployed via Safe Proxy Factory version 1.4.1 and created approximately 324 days before the incident, according to on-chain research cited by news outlets. As of publication, none of the seven signer addresses had been publicly identified, no protocol or team had publicly claimed ownership or operatorship of the vault, and no entity had issued an official post-mortem or statement about the incident. This lack of disclosed ownership and signer identity is a transparency concern independent of the exploit itself, since depositors in the vault had no public means of verifying who controlled approval rights over their funds.","heading":"Undisclosed 3-of-7 Multisig Governance","severity":"high","sources":[{"credibility":2,"name":"$6M Vanishes From Crypto Vault Controlled by 7 Mystery Signers","type":"news_article","url":"https://news.bitcoin.com/security/6m-vanishes-from-crypto-vault-controlled-by-7-mystery-signers/"},{"credibility":2,"name":"Base Vault Hack: $6M in wstETH Drained After Attacker Gains Whitelist Access","type":"news_article","url":"https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/"}]},{"content":"Multiple security researchers and outlets reported that the exploit was isolated to the vault's own access-control (whitelist) mechanism. Base's core layer-2 infrastructure was not identified as compromised, and Aave's core lending contracts were not found to have a vulnerability; Aave's receipt-token borrowing and redemption functioned as designed once the attacker's contract had been granted whitelist privileges on the vault. Analysis from Spot On Chain noted that systemic risk to the broader market was assessed as limited, though it flagged short-term concern that the attacker selling the stolen wstETH could place downward pressure on the liquid staking token's peg to ETH.","heading":"Scope: Base and Aave Infrastructure Not Compromised","severity":"medium","sources":[{"credibility":2,"name":"Data: Base Chain Vault Attack Losses Expand to About $6 Million","type":"news_article","url":"https://panews.io/articles/01a10663-a8a7-7095-a5c8-0cd0a78ca94d"},{"credibility":2,"name":"$6M Vanishes From Crypto Vault Controlled by 7 Mystery Signers","type":"news_article","url":"https://news.bitcoin.com/security/6m-vanishes-from-crypto-vault-controlled-by-7-mystery-signers/"}]},{"content":"As of the most recent reporting, the root cause of the compromise — whether a signer's private key was stolen, a signing device or workflow was manipulated, or the whitelist approval was otherwise socially engineered — had not been publicly confirmed by any security firm or by the vault's operator. No party had publicly claimed responsibility for operating the vault, no recovery or negotiation with the attacker had been reported, and no regulatory or law-enforcement action had been publicly announced in connection with the incident at the time of this writing. This entry should be treated as describing an active, unresolved incident; details may change as more information becomes available.","heading":"Unresolved Questions","severity":"high","sources":[{"credibility":2,"name":"Base Vault Hack: $6M in wstETH Drained After Attacker Gains Whitelist Access","type":"news_article","url":"https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/"},{"credibility":2,"name":"Over $6 million stolen from Base anonymous multi-signature wallet","type":"news_article","url":"https://www.kucoin.com/news/flash/over-6m-stolen-from-base-anonymous-multi-signature-wallet"}]}],"sources_used":[{"credibility":2,"name":"Base Vault Hack: $6M in wstETH Drained After Attacker Gains Whitelist Access","type":"news_article","url":"https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/"},{"credibility":2,"name":"Over $6 million stolen from Base anonymous multi-signature wallet","type":"news_article","url":"https://www.kucoin.com/news/flash/over-6m-stolen-from-base-anonymous-multi-signature-wallet"},{"credibility":2,"name":"Data: Base Chain Vault Attack Losses Expand to About $6 Million","type":"news_article","url":"https://panews.io/articles/01a10663-a8a7-7095-a5c8-0cd0a78ca94d"},{"credibility":2,"name":"$6M Vanishes From Crypto Vault Controlled by 7 Mystery Signers","type":"news_article","url":"https://news.bitcoin.com/security/6m-vanishes-from-crypto-vault-controlled-by-7-mystery-signers/"},{"credibility":2,"name":"Base Vault Attack Drives Reported Losses to About $6 Million","type":"news_article","url":"https://www.tokenpost.com/news/technology/26653"},{"credibility":2,"name":"Base Vault Loses More Than $6 Million in Exploit","type":"news_article","url":"https://www.tokenpost.com/news/technology/26676"},{"credibility":2,"name":"$6M wstETH Exploit Hits Base Network","type":"news_article","url":"https://phemex.com/news/article/6m-in-wsteth-drained-from-base-network-protocol-98739"}],"summary":"On October 4, 2026, an unidentified yield vault deployed on Coinbase's Base network lost approximately 1,783 wstETH (roughly $6 million) after an attacker gained whitelist privileges on the vault and used a newly deployed contract to borrow against the vault's Aave position before redeeming the borrowed receipt tokens for the underlying collateral. The vault is controlled by an anonymous 3-of-7 Safe multisig whose signers have never been publicly disclosed, and neither Base's core infrastructure nor Aave's core contracts were found to be compromised. The incident remains only partially explained: security firms confirmed the mechanics of the drain but had not, as of publication, determined how the attacker obtained whitelist approval or identified the vault's operator.","timeline":[{"date":"2026-10-04","date_evidence":"08:52 UTC (Oct 4, 2026): Vault's multisig wallet removed the attacker contract from whitelist","event":"Vault's 3-of-7 Safe multisig removes a newly deployed contract from the vault's asset whitelist.","source":"CryptoTimes / on-chain analysis by ExVul","source_url":"https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/"},{"date":"2026-10","date_evidence":"08:53 UTC: Same multisig re-enabled the contract (one minute later)","date_original":"2026-10-04","event":"The same multisig re-adds the contract to the whitelist roughly one minute after removing it.","source":"CryptoTimes / on-chain analysis by ExVul","source_url":"https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/"},{"date":"2026-10","date_evidence":"~09:04 UTC: First borrow occurred, roughly 70 seconds after re-enabling","date_original":"2026-10-04","event":"The whitelisted contract executes the first borrow against the vault's Aave position, pulling aBaswstETH.","source":"CryptoTimes / on-chain analysis by ExVul","source_url":"https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/"},{"date":"2026-10-04","date_evidence":"09:21 UTC, Oct. 4, 2026: Blockaid detected the exploit; $2.02M already gone","event":"Blockaid publicly flags the exploit; initial loss estimate of approximately $2.02 million.","source":"news.Bitcoin.com","source_url":"https://news.bitcoin.com/security/6m-vanishes-from-crypto-vault-controlled-by-7-mystery-signers/"},{"date":"2026-10","date_evidence":"09:56 UTC: PeckShield confirmed 1,783 wstETH drained","date_original":"2026-10-04","event":"PeckShield confirms total drained amount has reached 1,783 wstETH.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/"},{"date":"2026-10-04","date_evidence":"~10:01 UTC, Oct. 4, 2026: Loss exceeded $6 million (40 minutes after initial detection)","event":"Total confirmed loss exceeds $6 million, roughly three times the initial estimate.","source":"news.Bitcoin.com / PANews","source_url":"https://panews.io/articles/01a10663-a8a7-7095-a5c8-0cd0a78ca94d"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision be704761-ba9e-451f-b290-fdb29f7f113c
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.