Sunday, October 4, 2026Live markets
BBTC$85,821.13 +1.32%EETH$2,704.24 +0.64%BBNB$792.91 +0.92%XXRP$1.51 +1.42%SSOL$121.52 +1.52%TTRX$0.3357 +0.03%HHYPE$90.91 +1.64%ZZEC$1,333.34 +1.14%DDOGE$0.0967 +4.02%LLINK$14.19 +1.10%XXMR$546.29 -2.11%AADA$0.2517 +2.68%XXLM$0.2204 +2.07%NNEAR$4.92 +3.55%
DeFi

Base DeFi Vault Loses Over $6M in Whitelist Exploit

CDBy · · 3 min read
Base DeFi Vault Loses Over $6M in Whitelist Exploit

A DeFi vault running on Base lost more than $6 million on October 4 after an attacker added a newly created contract to the vault’s whitelist and used it to extract assets, according to Blockonomi.

Blockchain security firm Blockaid first flagged the incident, putting early losses at about $2.02 million across roughly four transactions. The firm later raised its estimate above $6 million and said the exploit remained active. Spot On Chain and PeckShield independently estimated the losses at approximately 1,783 wstETH, worth around $6 million, and identified 0x0B5126…B034 as the suspected exploiter address on Base.

Key facts

  • Blockaid first reported the exploit on October 4, 2026, estimating roughly $2.02 million drained across about four transactions.
  • The firm then raised its loss estimate above $6 million and said the attack was still ongoing.
  • Spot On Chain and PeckShield each traced about 1,783 wstETH, worth around $6 million, to 0x0B5126…B034.
  • The attacker added a brand-new contract to the vault’s whitelist, borrowed aBaswstETH and sent the aTokens to an attacker-controlled contract.
  • No evidence indicates Aave’s core lending contracts or Base’s underlying network were breached.

A whitelist at the centre of the sequence

Blockaid described the sequence plainly: a newly created contract was added to the vault’s whitelist, then borrowed aBaswstETH from the vault, and the resulting aTokens were transferred into a contract the attacker controlled. Whitelists normally restrict a vault to interacting only with approved contracts or addresses. In this case the approval came before the borrowing began, according to Blockaid.

What remains unresolved is how that contract obtained authorization in the first place. Investigators have not publicly established whether an administrative key issue, a configuration error, an access-control function or a smart-contract vulnerability is responsible. The affected vault has not been named, and no official post-mortem has set out a root cause, so the $6 million figure is still subject to revision as transactions are traced.

Why the Aave link is not a breach

The drained asset ties the incident to Aave liquidity infrastructure: BaseScan identifies aBaswstETH as Aave Base wstETH, and Aave documentation describes aTokens as interest-bearing tokens issued when assets are supplied to its markets, representing deposited assets and accrued yield. That connection is why the story has drawn attention beyond the unidentified vault, but the available evidence does not show Aave’s core lending contracts were compromised.

Spot On Chain said broader systemic risk appeared limited, while noting that selling the stolen wstETH could create short-term market pressure depending on where and how quickly the attacker liquidates. wstETH is Lido’s non-rebasing version of stETH, whose exchange rate against stETH changes over time rather than its holder balances. Base is an Ethereum Layer 2 built on the OP Stack, and nothing suggests the network itself was affected.

Why it matters

The incident shifts attention to authorization design rather than to the lending markets that hold the underlying assets. Vaults that gate deposits and borrows behind a whitelist are only as strong as the process that adds addresses to it, and an approval granted too readily can hand an attacker the same permissions a legitimate integration would receive. For depositors, the distinction matters: losses here sit with the unidentified vault rather than with Aave or Base. For the wider Base DeFi market, the immediate question is whether the stolen wstETH reaches liquid venues and adds selling pressure.

What to watch

Two concrete developments will move the story: identification of the vault and publication of a post-mortem establishing how the new contract was whitelisted, and on-chain movement of the 1,783 wstETH from 0x0B5126…B034 toward exchanges or other liquid venues. Until a root cause is confirmed, the loss total may be revised again.

Disclaimer: This article is for information only and is not investment, financial or trading advice. Cryptocurrency prices are highly volatile. Always do your own research.

Source: Blockonomi

CD

The CryptoNewsroom editorial desk covers Bitcoin, Ethereum, altcoins, DeFi, regulation and crypto markets. Editorial policy

Related stories