Base DeFi Vault Loses $6M After Malicious Whitelist Addition
Image: Crypto BriefingOn October 4, 2026, a Base DeFi vault lost approximately $6 million, equal to 1,783 wstETH, after a malicious contract was added to its borrower whitelist. The stolen aBaswstETH tokens are Aave Base wstETH deposit receipts, separate from Aave's core lending infrastructure. The vault is governed by a 3-of-7 Safe multisig, with two whitelist changes occurring within a one-minute window that day. No protocol has claimed ownership of the unidentified vault, which still holds roughly $31.7 million in assets.
Key points
- The exploit occurred after a malicious contract was added to the vault's borrower whitelist.
- The stolen aBaswstETH tokens are Aave Base wstETH deposit receipts, separate from Aave's core infrastructure.
- No protocol has claimed ownership of the unidentified affected vault.
Why it matters
The incident highlights risks associated with whitelist access controls and multisig governance for DeFi vaults. It also confirms that breaches of vaults built on Aave do not impact Aave's core lending infrastructure.
What's unclear
The identity of the affected vault and its affiliated protocol has not been confirmed
No official post-mortem has determined the root cause of the whitelist compromise
Price context · AAVE
At publication
$181.69
Now
$183.50
Change since
+1.00%
7 days · dashed line = publication
Sources · 2 publishers
Crypto Briefing
Tier 2
Base vault drained of $6M in Aave deposit tokens after whitelist change
Coverage timeline
- First reported by Blockonomi
- Confirmed by Crypto Briefing
- CryptoVideos brief published
How this brief was made. Our system found this event in 2 independent publications, summarised two complete reports with AI and checked every number above against the source text. Sources are linked in full. Not financial advice. Report an error