Skip to main content
AVOID.NET

Audit log

Every state-changing event for Unidentified Base Vault (Safe Multisig Whitelist Exploit): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-10-05 20:04:32Z
    Score: ? → ? (no score change)
    anchoranchored
    chain
    ●mainnet-betaslot 453,681,204
    sig
    N7mhFYndwqTK…UVuwh68Pexplorer ↗
    hash
    B872XxRoB1y8…oDcRJsJNsha256 → base58
    verifying row…full verify ↗
    canonical bytes (10434 B) ▸
    {"actor":"system:backfill","investigation_id":"f4994bfb-e3c7-480f-9e29-60b72dcd212c","kind":"publish","page_slug":"unidentified-base-vault-safe-multisig-whitelist-exploit","published_at":"2026-10-05T20:04:32.407Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Unidentified Base Vault (Safe Multisig Whitelist Exploit)","sections":[{"content":"On October 4, 2026, a vault contract on the Base network, address 0xD1895f2019c2152FC2b9022D57f19198c4CFCABC, was drained of approximately 1,783.067 aBaswstETH (an Aave V3 Base-market interest-bearing token representing wstETH), valued at roughly $6 million at the time. According to reporting citing on-chain monitoring, the vault's 3-of-7 Safe multisignature wallet removed a contract associated with the eventual attacker from the vault's Aave V3 borrower whitelist at approximately 08:52 UTC, then re-added the same contract roughly one minute later, around 08:53 UTC. Both transactions reportedly carried valid signatures from existing Safe signers. Once whitelisted, the attacker's contract, funded from attacker address 0x0B5126e1bc27C0de77e02e97945760A674EdB034, borrowed the vault's aBaswstETH holdings and transferred them to the attacker's own contract, which then redeemed the Aave receipt tokens for underlying wstETH. Reported loss estimates escalated during the attack, from an initial flagged amount near $2 million to the final confirmed total of about $6 million within roughly 25-40 minutes, across multiple outflow transactions. Part of the stolen wstETH was reportedly routed toward a bridge to Ethereum associated with Lido infrastructure. Security firms Blockaid, PeckShield, CertiK, GoPlus, and ExVul are reported to have identified and flagged the exploit in real time.","heading":"The Exploit","severity":"critical","sources":[{"credibility":2,"name":"Base Vault Hack: $6M in wstETH Drained After Attacker Gains Whitelist Access (CryptoTimes)","type":"news_article","url":"https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/"},{"credibility":2,"name":"Base vault drained of $6M in Aave deposit tokens after whitelist change (Crypto Briefing)","type":"news_article","url":"https://cryptobriefing.com/base-vault-drained-6m-aave-whitelist/"},{"credibility":2,"name":"Unidentified Base Vault Hit By $6M Multisig Exploit, Leaving $31.7M At Risk (mpost.io)","type":"news_article","url":"https://mpost.io/unidentified-base-vault-hit-by-6m-multisig-exploit-leaving-31-7m-at-risk/"}]},{"content":"Multiple outlets reported that the vault's 3-of-7 Safe multisignature wallet, created via Safe Proxy Factory version 1.4.1, had not executed any transaction in the 25 days preceding the attack, before suddenly executing the whitelist-removal and whitelist-re-addition transactions within about 60-70 seconds of each other on October 4, 2026. Both transactions reportedly carried valid signatures from existing signers, meaning the multisig's own signing threshold was technically satisfied rather than bypassed through a smart-contract bug. Reporting characterizes this pattern -- a long period of dormancy followed by two rapid, seemingly contradictory governance actions that directly enabled the drain -- as consistent with either compromised signer keys or social engineering of one or more of the seven signers, though no outlet reports this as confirmed; it remains an unverified, alleged explanation. The identities of the seven Safe signers have not been made public in available reporting, and the specific technical or procedural weakness that allowed the whitelist change to be exploited (for example, absence of a timelock or pause between a whitelist change and its effect) has not been established in public reporting.","heading":"Multisig Governance Failure","severity":"critical","sources":[{"credibility":2,"name":"Base Vault Hack: $6M in wstETH Drained After Attacker Gains Whitelist Access (CryptoTimes)","type":"news_article","url":"https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/"},{"credibility":2,"name":"Base vault drained of $6M in Aave deposit tokens after whitelist change (Crypto Briefing)","type":"news_article","url":"https://cryptobriefing.com/base-vault-drained-6m-aave-whitelist/"},{"credibility":2,"name":"Base Vault Exploit Drains About $6 Million, Puts $31.7 Million at Risk (TokenPost)","type":"news_article","url":"https://www.tokenpost.com/news/technology/26706"}]},{"content":"As of the most recent reporting, no project, team, or protocol has publicly identified itself as the operator of the vault or claimed responsibility for the funds held in it, including the roughly $31.7 million in deposits reported to remain in the vault at risk of further loss. This absence of a claimed operator means affected depositors currently have no confirmed point of contact for recovery, compensation, or security remediation, and it is not publicly known what further protective action, if any, has been taken to secure the remaining funds or the vault's Safe multisig since the attack. One source noted that an anonymous on-chain actor publicly urged the attacker to withdraw additional funds and offered a \"tip\" to do so, though no response from the attacker to this message was confirmed. Because the vault's identity and governance structure beyond the Safe signer-count are unverified, assessments of who is accountable, whether depositors will be made whole, and whether the remaining $31.7 million is adequately protected should be treated as low confidence pending identification of the operator.","heading":"Unknown Operator and Unresolved Accountability","severity":"high","sources":[{"credibility":2,"name":"Base vault drained of $6M in Aave deposit tokens after whitelist change (Crypto Briefing)","type":"news_article","url":"https://cryptobriefing.com/base-vault-drained-6m-aave-whitelist/"},{"credibility":2,"name":"Base Vault Hack: $6M in wstETH Drained After Attacker Gains Whitelist Access (CryptoTimes)","type":"news_article","url":"https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/"}]},{"content":"Reporting is consistent that neither the Aave protocol nor the underlying Base chain infrastructure were compromised in this incident; the exploit is attributed to a governance and access-control failure specific to the individual vault's own Safe multisig and its whitelist configuration for borrowing against its Aave V3 position, not to any vulnerability in Aave V3's smart contracts or Base's network-level security.","heading":"Scope: Aave and Base Not Implicated","severity":"medium","sources":[{"credibility":2,"name":"Unidentified Base Vault Hit By $6M Multisig Exploit, Leaving $31.7M At Risk (mpost.io)","type":"news_article","url":"https://mpost.io/unidentified-base-vault-hit-by-6m-multisig-exploit-leaving-31-7m-at-risk/"},{"credibility":2,"name":"Base vault drained of $6M in Aave deposit tokens after whitelist change (Crypto Briefing)","type":"news_article","url":"https://cryptobriefing.com/base-vault-drained-6m-aave-whitelist/"}]}],"sources_used":[{"credibility":2,"name":"Base Vault Hack: $6M in wstETH Drained After Attacker Gains Whitelist Access (CryptoTimes)","type":"news_article","url":"https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/"},{"credibility":2,"name":"Unidentified Base Vault Hit By $6M Multisig Exploit, Leaving $31.7M At Risk (mpost.io)","type":"news_article","url":"https://mpost.io/unidentified-base-vault-hit-by-6m-multisig-exploit-leaving-31-7m-at-risk/"},{"credibility":2,"name":"Base vault drained of $6M in Aave deposit tokens after whitelist change (Crypto Briefing)","type":"news_article","url":"https://cryptobriefing.com/base-vault-drained-6m-aave-whitelist/"},{"credibility":2,"name":"Base Vault Exploit Drains About $6 Million, Puts $31.7 Million at Risk (TokenPost)","type":"news_article","url":"https://www.tokenpost.com/news/technology/26706"}],"summary":"An unclaimed DeFi vault on the Base chain, deployed via an OpenZeppelin transparent proxy and governed by a 3-of-7 Safe multisignature wallet, lost approximately 1,783 wstETH (around $6 million) on October 4, 2026, after an attacker's contract was briefly added to the vault's Aave V3 borrower whitelist. No protocol or team has publicly claimed ownership of the vault, and roughly $31.7 million in additional deposits reportedly remains in it and exposed to further risk. The incident is under active investigation by multiple blockchain security firms, and the identity of the vault operator and the root cause of the multisig's behavior remain unconfirmed.","timeline":[{"date":"2026-10","date_original":"2026-10-04","event":"The vault's 3-of-7 Safe multisig removes a contract later linked to the attacker from the vault's Aave V3 borrower whitelist at approximately 08:52 UTC, then re-adds the same contract at approximately 08:53 UTC, roughly one minute later, following 25 days of multisig inactivity.","source":"Crypto Briefing","source_url":"https://cryptobriefing.com/base-vault-drained-6m-aave-whitelist/"},{"date":"2026-10","date_original":"2026-10-04","event":"Security monitoring firm Blockaid flags an initial drain of roughly $2 million from the vault across multiple transactions, around 09:20 UTC.","source":"CryptoTimes","source_url":"https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/"},{"date":"2026-10","date_original":"2026-10-04","event":"Total confirmed loss reaches approximately 1,783.067 aBaswstETH, redeemed for roughly 1,783 wstETH (around $6 million), across six outflow transactions; part of the funds reportedly begin moving toward a Base-to-Ethereum bridge associated with Lido.","source":"CryptoTimes / Crypto Briefing","source_url":"https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/"},{"date":"2026-10","event":"Reporting establishes that roughly $31.7 million in additional vault deposits remains unaccounted for by any public operator claim and is described as still at risk; the vault's operating protocol remains unidentified.","source":"mpost.io","source_url":"https://mpost.io/unidentified-base-vault-hit-by-6m-multisig-exploit-leaving-31-7m-at-risk/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 5dd167d3-a55e-4edf-851c-2daf98970390
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.