Base Vault Suffers ~$6M Exploit, Still Holds $31.7M in Assets
Odaily reports: Gonçalo Magalhães, Head of Security at Immunefi, stated that an unnamed Base vault suffered an approximately $6 million exploit, while still holding around $31.7 million in assets at the time of the incident. According to a briefing, the attacker used a Safe multisig wallet to add a malicious contract to the vault's lending whitelist, then withdrew 1,783 aBaswstETH and swapped it for approximately 1,783 wstETH via AaveV3. Gonçalo Magalhães noted that while whitelisted addresses may appear secure, approved addresses can withdraw assets without collateral, constituting a vulnerability; this whitelist weakness had been discovered the previous week, but researchers lacked a clear disclosure channel. More than 24 hours after the incident, no team had publicly claimed responsibility or disclosed remediation measures.