Tools Crypto Exploit Tracker exploit-0145
Exploit record
Base vault loses $6m after malicious contract approval
- Loss
- $6M
- Attack vector
- Access Control
- Chain
- Base
- Sector
- DeFi
What happened
An unnamed vault on Base lost about $6m on 4 October after a newly approved contract used its borrowing path. ExVul reports six outflows totalling 1,783.067 aBaswstETH, tokens representing deposited wrapped staked Ether on Aave.
The controlling Safe wallet accepted three owner signatures on a preceding permission call. How those approvals were obtained remains unresolved. The recipient later redeemed the receipt tokens for about 1,783.067 wstETH; that redemption moved the same assets. The observed failure concerns the vault’s permissions and borrowing path. Blockaid’s earlier $2.02m alert was an interim estimate.
On-chain references
- Incident transactionbasescan.org/tx/0x0ec75c3be1f55bb08a92421796675e051993cdb6cb…
- Safe permission transactionbasescan.org/tx/0xed265fc80e4abe42d72d6bfd1623c89dd2d12f544d…
Sources
- Researcher reportx.com/exvulsec/status/2106688163452436763
- Blockaid interim alertx.com/blockaid_/status/2106675941313269950
On YFarmX
- Our reportingBase vault loses $6m in six transfers
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 5 October 2026