Approximately $6 million Withdrawn from Vault on Base, Operator Unknown

By: coinpost.jp|10/05/2026 00:17:02


Key Points of This Article

  • Attack contract re-registered by multi-signature
  • Damage amount expanded from initial estimate of approximately $2.02 million

Unauthorized Withdrawal from Vault on Base

On the 4th, approximately 1,783 wstETH (worth about $6 million) was illegally withdrawn from a vault (a smart contract that holds and manages funds) on the Layer 2 network Base, with the operator remaining unknown. Blockchain security firm PeckShield reported the damage on X that same night. As of the 5th, the operator had not come forward.

wstETH is a wrapped version of the staked Ethereum (ETH) token "stETH" issued by leading liquid staking provider Lido. Unlike stETH, the balance does not fluctuate daily, and its value in ETH increases according to the accumulation of staking rewards.

Withdrawal Immediately After Whitelist Re-registration

According to Blockaid, which first reported the anomaly, a newly created contract was added to the vault's whitelist, allowing the attacker to borrow aBaswstETH from the vault and send it to the attacker's contract. aBaswstETH is a receipt token issued when wstETH is deposited in Aave V3's Base market. The attacker redeemed this on Aave to obtain wstETH.

The vault is operated by a multi-signature (Safe) that can be controlled with the approval of 3 out of 7 owners. According to a timeline released by security firm ExVul, this multi-signature removed the relevant contract from the whitelist at 17:52 JST and re-registered it one minute later at 17:53. Both operations had valid signatures from existing signers. The first borrowing was executed approximately 70 seconds after the re-registration.

Damage Amount Expanded to Approximately Three Times Initial Estimate

In an initial report released around 18:20, Blockaid stated that approximately $2.02 million had flowed out in about four transactions, and the attack was ongoing. By 18:56, PeckShield reported the damage amount to be approximately $6 million, and CertiK issued a similar warning.

There is no information indicating that there was a problem with Aave's infrastructure or the Base network itself, and it has not been confirmed whether the signer's keys were leaked or if the signing process was manipulated. The attacker's address starts with "0x0B5126" and ends with "B034."

-- Price

--
--
--

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com