A vault deployed on the Base network lost approximately 1,783 wstETH, worth nearly $6 million, after a malicious contract gained authorization to manipulate its funds. The owner’s Safe multisig first removed the attacker contract from the whitelist at 08:52:23 UTC, then reauthorized it just 90 seconds later at 08:53:51 UTC, with each operation carrying three valid signatures out of seven signers. The attacker then used Aave V3 to borrow the vault’s aBaswstETH, transfer them to a contract they controlled, and redeem them for the original wstETH. Aave itself is not implicated: the protocol simply processed a loan validated by the vault’s whitelist. No protocol has claimed ownership of the vault nor published a technical report to date.
Source: Read the original article

