← Unidentified Base Vault (October 2026 Whitelist Exploit)1 decision on this page
Audit log
Every state-changing event for Unidentified Base Vault (October 2026 Whitelist Exploit): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-10-09 17:58:48ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 454,950,461
- sig
3K1ucu8Q6yEM…CTfHGjXxexplorer ↗- hash
BYP8erRhDLk1…3nCnVZKxsha256 → base58
verifying row…full verify ↗canonical bytes (18022 B) ▸
{"actor":"system:backfill","investigation_id":"e33040f9-de45-4cfa-9784-eec3796f4508","kind":"publish","page_slug":"unidentified-base-vault-october-2026-whitelist-exploit","published_at":"2026-10-09T17:58:48.408Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Unidentified Base Vault (October 2026 Whitelist Exploit)","sections":[{"content":"On October 4, 2026, a vault deployed as an OpenZeppelin TransparentUpgradeableProxy at address 0xD1895f2019c2152FC2b9022D57f19198c4CFCABC on the Base layer-2 network suffered a loss of approximately 1,783 wstETH (~$6 million). The exploit did not exploit a vulnerability in Aave V3's core contracts or the Base network itself; it exploited the vault's application-level access control — specifically its borrower whitelist — which was governed by a 3-of-7 Safe multisig wallet (Safe owner: 0x6b27512a5943Ed327f6cb6C3EC1f0398229f42C4). The vault held Aave interest-bearing receipt tokens (aBaswstETH) as collateral at the time of the attack, with a total value locked of approximately $31.7 million. No team has publicly claimed ownership of the vault as of October 9, 2026.","heading":"Incident Overview","severity":"critical","sources":[{"credibility":2,"name":"Base Vault Hack: $6M in wstETH Drained After Attacker Gains Whitelist Access","type":"news_article","url":"https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/"},{"credibility":2,"name":"Base vault drained of $6M in Aave deposit tokens after whitelist change","type":"news_article","url":"https://cryptobriefing.com/base-vault-drained-6m-aave-whitelist/"},{"credibility":2,"name":"Unidentified Base Vault Hit By $6M Multisig Exploit, Leaving $31.7M At Risk","type":"news_article","url":"https://mpost.io/unidentified-base-vault-hit-by-6m-multisig-exploit-leaving-31-7m-at-risk/"}]},{"content":"The attack exploited the vault's whitelist access control rather than any flaw in the underlying Aave V3 protocol or the Base network. At 08:52 UTC, the vault's Safe multisig executed a transaction removing a newly deployed, previously unseen smart contract (attacker address: 0x0B5126e1bc27C0de77e02e97945760A674EdB034; receiving contract: 0xcdFE91301356da873562EF513828a60dba1F569d) from the borrower whitelist. One minute later at 08:53 UTC, the same multisig re-added the identical contract to the whitelist, with both transactions carrying valid ECDSA signatures from existing signers. The vault had executed zero Safe transactions in the 25 days prior to these two consecutive actions. Within approximately 70 seconds of the re-enablement, the whitelisted contract began borrowing aBaswstETH — Aave V3's interest-bearing receipt tokens for wstETH deposits on Base. Across six separate transfers between 08:53 and 09:12 UTC, 1,783.067 aBaswstETH were withdrawn. The attacker then redeemed these receipt tokens through Aave V3 for the underlying 1,783 wstETH. Stolen assets were reportedly routed through Lido's Base-to-Ethereum bridge, which carries a seven-day settlement window. The vault lacked a timelock mechanism, meaning whitelist changes took effect and were exploitable immediately.","heading":"Attack Mechanism","severity":"critical","sources":[{"credibility":3,"name":"Base DeFi Vault Exploit Drains $6M via Whitelist Access Control Failure","type":"news_article","url":"https://dev.to/qanzhi111/base-defi-vault-exploit-drains-6m-via-whitelist-access-control-failure-1e5f"},{"credibility":2,"name":"$6M Gone in 19 Min: Base DeFi Vault Hack [2026]","type":"news_article","url":"https://shattered.io/base-defi-vault-hack-6-million-19-minutes-2026/"},{"credibility":2,"name":"Base Vault Hack: $6 Million via a Permission List","type":"news_article","url":"https://cryptoticker.io/en/base-vault-whitelist-multisig-hack-october-2026/"},{"credibility":2,"name":"Base vault drained of $6M in Aave deposit tokens after whitelist change","type":"news_article","url":"https://cryptobriefing.com/base-vault-drained-6m-aave-whitelist/"}]},{"content":"The root cause of the exploit is attributed to a failure at the access control layer, but the precise mechanism by which the malicious contract obtained valid multisig approval remains unconfirmed as of October 9, 2026. The vault's 3-of-7 Safe multisig required three of seven signers to approve any whitelist change. Multiple security researchers and outlets noted that investigators cannot determine from on-chain records alone whether the whitelist approval reflected stolen signing credentials, social engineering of one or more signers, or a deliberate insider action. The sequence — remove the malicious contract, then re-add it within 60 seconds with valid signatures — has been described by multiple reporters as anomalous, but no attribution of motive or actor identity has been established. The 25-day period of multisig inactivity immediately preceding the two exploit transactions has been cited as a potentially significant indicator, though its interpretation remains ambiguous. Absent a post-mortem, on-chain analysis alone cannot resolve the question of insider versus external compromise. The identities of the seven Safe signers have not been publicly established.","heading":"Governance Failure and Compromise Vector","severity":"high","sources":[{"credibility":2,"name":"Unidentified Base Vault Hit By $6M Multisig Exploit, Leaving $31.7M At Risk","type":"news_article","url":"https://mpost.io/unidentified-base-vault-hit-by-6m-multisig-exploit-leaving-31-7m-at-risk/"},{"credibility":2,"name":"Hacker gets added to a Base DeFi vault's whitelist twice in one minute","type":"news_article","url":"https://startupfortune.com/hacker-gets-added-to-a-base-defi-vaults-whitelist-twice-in-one-minute/"},{"credibility":2,"name":"Base Vault Hack: $6 Million via a Permission List","type":"news_article","url":"https://cryptoticker.io/en/base-vault-whitelist-multisig-hack-october-2026/"}]},{"content":"At the time the exploit concluded, approximately $31.7 million in assets remained within the vault. As of October 9, 2026, that residual TVL remained under control of the same 3-of-7 Safe multisig whose governance was compromised during the attack. No remediation measures, key rotation, vault freeze, or migration to a new contract have been publicly announced. The vault operator has not identified itself. An anonymous on-chain actor was reported to have messaged the attacker's address on-chain encouraging return of funds and requesting a tip, but no verified response or fund return occurred. No exchange freeze request or law-enforcement referral has been publicly reported. Users or counterparties with exposure to this vault contract face unresolved risk.","heading":"Ongoing Risk to Remaining TVL","severity":"critical","sources":[{"credibility":2,"name":"Base Vault Suffers About $6 Million Exploit With $31.7 Million Left","type":"news_article","url":"https://www.tokenpost.com/news/technology/27234"},{"credibility":2,"name":"Unidentified Base Vault Hit By $6M Multisig Exploit, Leaving $31.7M At Risk","type":"news_article","url":"https://mpost.io/unidentified-base-vault-hit-by-6m-multisig-exploit-leaving-31-7m-at-risk/"},{"credibility":2,"name":"$6M Gone in 19 Min: Base DeFi Vault Hack [2026]","type":"news_article","url":"https://shattered.io/base-defi-vault-hack-6-million-19-minutes-2026/"}]},{"content":"Blockchain security firm Blockaid flagged unusual activity at approximately 09:21 UTC — approximately 29 minutes after the first whitelist modification and nine minutes after the final withdrawal. By the time of detection, roughly $2.02 million had already been drained across the first four outflows. PeckShield independently confirmed the total loss of 1,783 wstETH (approximately $6 million) at 09:56 UTC. CertiK alerted on the newly deployed proxy contract at 09:59 UTC. ExVul provided a detailed breakdown at 10:09 UTC, confirming 1,783.067 aBaswstETH drained across six outflows. Spot On Chain contributed on-chain address tracing. No vault operator responded to any security firm's findings.","heading":"Detection and Security Firm Response","severity":"medium","sources":[{"credibility":2,"name":"Base Vault Hack: $6M in wstETH Drained After Attacker Gains Whitelist Access","type":"news_article","url":"https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/"},{"credibility":2,"name":"Base DeFi Vault Exploit Drains $6M After Attacker Gains Whitelist Access","type":"news_article","url":"https://blockonomi.com/base-defi-vault-exploit-drains-6m-after-attacker-gains-whitelist-access"}]},{"content":"As of October 9, 2026, no team or individual has publicly claimed ownership of the vault at 0xD1895f2019c2152FC2b9022D57f19198c4CFCABC. GoPlus Security described it as a contract with tens of millions of dollars in Aave V3 Base exposure that no project had identified itself as operating. Reporting from TokenPost (October 7, 2026) noted that a security flaw may have been identified as early as approximately September 30, 2026 — roughly four days before the exploit — but researchers lacked a clear disclosure channel because no operator had identified itself. The complete absence of any post-incident statement, post-mortem, or remediation plan means depositors and counterparties have received no information about the compromise or the status of remaining funds. The vault's Safe owner address (0x6b27512a5943Ed327f6cb6C3EC1f0398229f42C4) and the seven signer addresses remain publicly unattributed.","heading":"Operator Anonymity and Disclosure Failure","severity":"high","sources":[{"credibility":2,"name":"Base Vault Suffers About $6 Million Exploit With $31.7 Million Left","type":"news_article","url":"https://www.tokenpost.com/news/technology/27234"},{"credibility":2,"name":"$6M Vanishes From Crypto Vault Controlled by 7 Mystery Signers","type":"news_article","url":"https://news.bitcoin.com/security/6m-vanishes-from-crypto-vault-controlled-by-7-mystery-signers/"},{"credibility":2,"name":"Unidentified Base Vault Hit By $6M Multisig Exploit, Leaving $31.7M At Risk","type":"news_article","url":"https://mpost.io/unidentified-base-vault-hit-by-6m-multisig-exploit-leaving-31-7m-at-risk/"}]},{"content":"Multiple security firms and reporting outlets confirmed that the exploit did not reflect a vulnerability in Aave V3's core lending contracts or the Base layer-2 network. Aave V3 functioned as designed: it honored redemption requests from a contract the vault's own governance had whitelisted. The vulnerability was entirely at the application level — the vault's access control and multisig governance. This incident has been noted in the context of a broader pattern: reporting from CryptoTimes described this as the fourth Aave-linked incident on Base within a one-week period, and placed it against a backdrop in which September 2026 recorded approximately $766.4 million in crypto losses industry-wide. Neither Aave nor the Base network has been named as a responsible party.","heading":"Aave V3 and Base Network Scope","severity":"low","sources":[{"credibility":2,"name":"Base Vault Hack: $6M in wstETH Drained After Attacker Gains Whitelist Access","type":"news_article","url":"https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/"},{"credibility":3,"name":"Base DeFi Vault Exploit Drains $6M via Whitelist Access Control Failure","type":"news_article","url":"https://dev.to/qanzhi111/base-defi-vault-exploit-drains-6m-via-whitelist-access-control-failure-1e5f"}]}],"sources_used":[{"credibility":2,"name":"Base Vault Hack: $6M in wstETH Drained After Attacker Gains Whitelist Access","type":"news_article","url":"https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/"},{"credibility":2,"name":"Base vault drained of $6M in Aave deposit tokens after whitelist change","type":"news_article","url":"https://cryptobriefing.com/base-vault-drained-6m-aave-whitelist/"},{"credibility":2,"name":"Unidentified Base Vault Hit By $6M Multisig Exploit, Leaving $31.7M At Risk","type":"news_article","url":"https://mpost.io/unidentified-base-vault-hit-by-6m-multisig-exploit-leaving-31-7m-at-risk/"},{"credibility":2,"name":"$6M Gone in 19 Min: Base DeFi Vault Hack [2026]","type":"news_article","url":"https://shattered.io/base-defi-vault-hack-6-million-19-minutes-2026/"},{"credibility":3,"name":"Base DeFi Vault Exploit Drains $6M via Whitelist Access Control Failure","type":"news_article","url":"https://dev.to/qanzhi111/base-defi-vault-exploit-drains-6m-via-whitelist-access-control-failure-1e5f"},{"credibility":2,"name":"Base Vault Hack: $6 Million via a Permission List","type":"news_article","url":"https://cryptoticker.io/en/base-vault-whitelist-multisig-hack-october-2026/"},{"credibility":2,"name":"Hacker gets added to a Base DeFi vault's whitelist twice in one minute","type":"news_article","url":"https://startupfortune.com/hacker-gets-added-to-a-base-defi-vaults-whitelist-twice-in-one-minute/"},{"credibility":2,"name":"Base DeFi Vault Exploit Drains $6M After Attacker Gains Whitelist Access","type":"news_article","url":"https://blockonomi.com/base-defi-vault-exploit-drains-6m-after-attacker-gains-whitelist-access"},{"credibility":2,"name":"$6M Vanishes From Crypto Vault Controlled by 7 Mystery Signers","type":"news_article","url":"https://news.bitcoin.com/security/6m-vanishes-from-crypto-vault-controlled-by-7-mystery-signers/"},{"credibility":2,"name":"Base Vault Suffers About $6 Million Exploit With $31.7 Million Left","type":"news_article","url":"https://www.tokenpost.com/news/technology/27234"},{"credibility":2,"name":"Base Vault Exploit Drains About $6 Million, Puts $31.7 Million at Risk","type":"news_article","url":"https://www.tokenpost.com/news/technology/26706"},{"credibility":2,"name":"Unnamed Base Vault Exploited for $6 Million via Malicious Contract","type":"news_article","url":"https://www.kucoin.com/news/flash/unnamed-base-vault-exploited-for-6m-via-malicious-contract"}],"summary":"On October 4, 2026, a DeFi vault operating on the Base network (contract address 0xD1895f2019c2152FC2b9022D57f19198c4CFCABC) lost approximately 1,783 wstETH (~$6 million) after a malicious contract was added to the vault's borrower whitelist via a 3-of-7 Safe multisig. The vault's operator identity had not been publicly disclosed as of October 9, 2026, and no post-incident statement, remediation plan, or confirmed fund recovery has emerged. A further ~$31.7 million in assets remained in the vault under the same multisig governance structure after the exploit.","timeline":[{"date":"2026-09-30","event":"A security flaw in the vault's access control was allegedly identified approximately four days before the exploit, but researchers lacked a public disclosure channel as the vault's operator had not identified itself.","source":"TokenPost","source_url":"https://www.tokenpost.com/news/technology/27234"},{"date":"2026-10-04","event":"At 08:52 UTC, the vault's 3-of-7 Safe multisig executed a transaction removing a newly deployed, attacker-controlled contract from the vault's borrower whitelist.","source":"Crypto Briefing","source_url":"https://cryptobriefing.com/base-vault-drained-6m-aave-whitelist/"},{"date":"2026-10-04","event":"At 08:53 UTC — approximately one minute later — the same multisig re-added the identical attacker contract to the whitelist. Both transactions carried valid ECDSA signatures from existing signers.","source":"Startup Fortune","source_url":"https://startupfortune.com/hacker-gets-added-to-a-base-defi-vaults-whitelist-twice-in-one-minute/"},{"date":"2026-10-04","event":"Between 08:53 and 09:12 UTC (~19 minutes), the attacker's whitelisted contract withdrew 1,783.067 aBaswstETH from the vault across six separate transfers and redeemed them through Aave V3 for approximately 1,783 wstETH (~$6 million).","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/"},{"date":"2026-10-04","event":"At 09:21 UTC, Blockaid flagged the ongoing exploit; approximately $2.02 million had already been drained at time of detection.","source":"Startup Fortune","source_url":"https://startupfortune.com/hacker-gets-added-to-a-base-defi-vaults-whitelist-twice-in-one-minute/"},{"date":"2026-10-04","event":"At 09:56 UTC, PeckShield confirmed the total loss of 1,783 wstETH (~$6 million). CertiK alerted on the proxy contract at 09:59 UTC. ExVul provided a full breakdown at 10:09 UTC.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/"},{"date":"2026-10-04","event":"Stolen wstETH reported routed toward Lido's Base-to-Ethereum bridge, which carries a seven-day settlement window before mainnet arrival.","source":"Crypto Briefing","source_url":"https://cryptobriefing.com/base-vault-drained-6m-aave-whitelist/"},{"date":"2026-10-05","event":"GoPlus Security and additional security firms disclosed that approximately $31.7 million in assets remained in the vault, still governed by the same compromised multisig. No operator claimed responsibility.","source":"Shattered.io","source_url":"https://shattered.io/base-defi-vault-hack-6-million-19-minutes-2026/"},{"date":"2026-10-07","event":"TokenPost reported that more than 24 hours after the exploit, no team had publicly claimed responsibility or disclosed remediation measures. The vault operator remained anonymous.","source":"TokenPost","source_url":"https://www.tokenpost.com/news/technology/27234"},{"date":"2026-10-09","event":"As of this date, no post-mortem, fund recovery, key rotation, or vault freeze has been publicly announced. Vault operator identity remains undisclosed.","source":"Multiple sources","source_url":"https://mpost.io/unidentified-base-vault-hit-by-6m-multisig-exploit-leaving-31-7m-at-risk/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 5c491d5d-b21a-4187-8ca7-797b0cb342d5
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.