Unidentified Base Vault (October 2026 Whitelist Exploit)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·3K1ucu…GjXxSummary
On October 4, 2026, a DeFi vault operating on the Base network (contract address 0xD1895f2019c2152FC2b9022D57f19198c4CFCABC) lost approximately 1,783 wstETH (~$6 million) after a malicious contract was added to the vault's borrower whitelist via a 3-of-7 Safe multisig. The vault's operator identity had not been publicly disclosed as of October 9, 2026, and no post-incident statement, remediation plan, or confirmed fund recovery has emerged. A further ~$31.7 million in assets remained in the vault under the same multisig governance structure after the exploit.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(10 events)
30 September 2026
A security flaw in the vault's access control was allegedly identified approximately four days before the exploit, but researchers lacked a public disclosure channel as the vault's operator had not identified itself.
TokenPost4 October 2026
At 08:52 UTC, the vault's 3-of-7 Safe multisig executed a transaction removing a newly deployed, attacker-controlled contract from the vault's borrower whitelist.
Crypto Briefing4 October 2026
At 08:53 UTC — approximately one minute later — the same multisig re-added the identical attacker contract to the whitelist. Both transactions carried valid ECDSA signatures from existing signers.
Startup Fortune4 October 2026
Between 08:53 and 09:12 UTC (~19 minutes), the attacker's whitelisted contract withdrew 1,783.067 aBaswstETH from the vault across six separate transfers and redeemed them through Aave V3 for approximately 1,783 wstETH (~$6 million).
CryptoTimes4 October 2026
At 09:21 UTC, Blockaid flagged the ongoing exploit; approximately $2.02 million had already been drained at time of detection.
Startup Fortune4 October 2026
At 09:56 UTC, PeckShield confirmed the total loss of 1,783 wstETH (~$6 million). CertiK alerted on the proxy contract at 09:59 UTC. ExVul provided a full breakdown at 10:09 UTC.
CryptoTimes4 October 2026
Stolen wstETH reported routed toward Lido's Base-to-Ethereum bridge, which carries a seven-day settlement window before mainnet arrival.
Crypto Briefing5 October 2026
GoPlus Security and additional security firms disclosed that approximately $31.7 million in assets remained in the vault, still governed by the same compromised multisig. No operator claimed responsibility.
Shattered.io7 October 2026
TokenPost reported that more than 24 hours after the exploit, no team had publicly claimed responsibility or disclosed remediation measures. The vault operator remained anonymous.
TokenPost9 October 2026
As of this date, no post-mortem, fund recovery, key rotation, or vault freeze has been publicly announced. Vault operator identity remains undisclosed.
Multiple sourcesDecision Log
- slot 454950461 · hash BYP8erRhDLk1gPbBn8cDCG79nk9uN91wxg323nCnVZKx
This investigation is cryptographically anchored to the Solana blockchain (1 decision). 0 of 12 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 10/9/2026, 5:58:36 PM
last updated: 10/9/2026, 5:58:36 PM
avoid.net — verified advice for a post-truth world