Base Vault Loses $6 Million in Multisig Whitelist Exploit
An unclaimed vault on Base lost 1,783 wstETH, about $6 million, on 4 October 2026 after its own 3-of-7 multisig re-approved an attacker contract.
An unidentified lending vault on Base, the Ethereum layer 2 network built by Coinbase, lost about 1,783 wstETH, worth roughly $6 million (about ₹58 crore), on Sunday, 4 October 2026. At 08:52 and 08:53 UTC (14:22 and 14:23 IST), the vault's own 3-of-7 Safe multisig removed and then re-added an attacker's contract to its borrower whitelist, and that contract drained the funds. About $31.7 million was left in the vault.
Key takeaways
- The loss was about 1,783 wstETH, the wrapped form of Lido's staked ether, taken in six outflows over roughly 25 minutes on 4 October 2026.
- The cause was a permission change, not a code bug: two whitelist transactions one minute apart carried valid signatures from the vault's own signers.
- Neither the Base network nor Aave's core contracts were compromised. The attacker used Aave V3 on Base exactly as designed to redeem receipt tokens.
- No team has claimed the vault, and its seven signers are publicly unknown. No post-mortem had appeared as of 5 October.
- No exchange was involved. The loss falls on depositors in this one DeFi vault.
What happened in the Base vault exploit
The Base vault exploit began with two administrative transactions. At 08:52 UTC on 4 October, the Safe multisig that controls the vault removed a newly deployed contract from the vault's list of approved borrowers. At 08:53 UTC the same Safe added it back. Both transactions carried at least three valid signatures from the vault's seven signers, and the multisig had made no transactions at all in the 25 days before that minute.
Once whitelisted, the contract borrowed 1,783 aBaswstETH, the interest-bearing receipt token that Aave V3 on Base issues for deposited wstETH, and sent it to an attacker-controlled address. That address redeemed the receipts through Aave for the underlying wstETH. Blockchain security firms began flagging the drain at about 09:20 UTC (14:50 IST), when roughly $2.02 million had already gone. The total passed $6 million by about 10:01 UTC.
How the attacker got the signatures is still unknown. Stolen keys, a tricked signer and insider collusion have all been raised, but none has been confirmed.
The Base vault exploit in numbers
The Base vault exploit figures below are as of 5 October 2026, using ₹96.40 to the dollar.
| Item | Detail |
|---|---|
| Date | Sunday, 4 October 2026 |
| Whitelist changes | 08:52 and 08:53 UTC (14:22 and 14:23 IST) |
| Control | 3-of-7 Safe multisig, signers unknown |
| Stolen | About 1,783 wstETH, roughly $6 million (about ₹58 crore) |
| Gone when first flagged (about 09:20 UTC) | About $2.02 million |
| Still in the vault | About $31.7 million (about ₹306 crore) |
| Outflows | Six, over roughly 25 minutes |
Ether itself was steady. ETH closed Sunday at $2,726.94 on Binance's ETH/USDT market, up 1.5% on the day, and traded at $2,714.19 at 21:31 UTC on 5 October. The live rate of ₹259,145 is on our Ethereum price in INR page. Lido, which issues stETH and wstETH, has its governance token LDO on our Lido DAO price page.
Why the Base vault exploit matters for Indian investors
The Base vault exploit shows that a DeFi product can be drained without any bug in its code. Whoever holds the admin keys can change the rules, and here a one-minute change let an outside contract borrow everything it could. Before you deposit through a self-custody wallet, check who controls the vault, how many signers it has, and whether admin changes wait behind a delay. Our explainer on how DeFi works covers these basics.
Indian users have seen this pattern before. In July 2024, WazirX lost about $230 million from a 4-of-6 multisig wallet after its signers approved what looked like a routine transaction, which handed control of the wallet's contract to the attackers. Our page on WazirX today explains where that case stands. Our report on 2026 DeFi losses shows key and account compromises overtaking code bugs this year.
Tax gives no cushion either. Crypto gains in India are taxed at a flat 30% plus 4% cess, with 1% TDS on transfers, and a crypto loss cannot be set off against other income or gains. Our guide on crypto loss set-off rules has the details.
What to watch next
The Base vault case leaves four open questions as of 5 October 2026.
- Ownership: whether any team claims the vault and publishes a post-mortem explaining how three signatures were obtained.
- The remaining funds: whether the roughly $31.7 million still in the vault is moved to safety before any second attempt.
- The stolen wstETH: where it moves next, and whether any of it can be frozen while it is bridged or swapped.
- Aave on Base: whether the lending market changes any settings, although its contracts worked as designed.
FAQ
What happened to the Base vault on 4 October 2026?
An unclaimed vault on Base lost about 1,783 wstETH, roughly $6 million, after its 3-of-7 Safe multisig re-added an attacker's contract to its borrower whitelist at 08:53 UTC. The contract borrowed Aave receipt tokens from the vault, and the attacker redeemed them for wstETH.
Was Aave or the Base network hacked?
No. Aave V3 and the Base chain worked as designed. The failure was in the vault's own permissions, where valid multisig signatures approved the attacker's contract.
Are Indian crypto exchange users affected by the Base vault hack?
No exchange was involved, so exchange balances are not affected. The loss falls on people who deposited in this one DeFi vault through their own wallets.
This article is AI-assisted, educational and general in nature. It is not financial advice and never a guarantee of profit. Every trade is at your own risk on your own exchange. See our risk disclosure and editorial policy.