Base Vault Loses $6 Million Due to Multisig Approval Flaw
Written with artificial intelligence.

A vault on the Base network suffered a loss of approximately 1,783 wstETH, valued at nearly $6 million, following a security lapse in its multisig approval process. The incident highlights vulnerabilities in vault management and the importance of securing key controls.
Incident Overview
On October 4, a vault deployed on Base experienced a significant security breach, resulting in the theft of about 1,783 wstETH, which is equivalent to nearly $6 million. This theft occurred when an unauthorized contract gained access to manipulate the vault's funds.
How the Breach Happened
The breach unfolded in a series of rapid actions involving the vault's whitelist, which allows certain addresses to access its funds. The attacker first obtained whitelisted status and borrowed the vault's aBaswstETH—tokens issued by Aave V3 for wstETH deposits. The attacker then transferred these tokens to a contract they controlled and redeemed them for 1,783 wstETH. Importantly, no indications of a compromise on the Aave protocol itself have been reported.
Multisig Approval Issues
The security teams monitored the theft as it escalated from $2 million to $6 million. The vault's multisig wallet, which typically requires multiple signatures for transaction approval, removed the attacker’s contract from its whitelist at 08:52:23 UTC but reactivated it just a minute and a half later at 08:53:51. Both transactions were validated by the same three signatures, suggesting a potential compromise of keys or manipulation of the approval process.
Recommendations for Users
Given this incident, users are urged to thoroughly investigate the governance of any vault before depositing funds. Key considerations include:
- Who holds the keys?
- How many signatures are required?
- Who can modify the whitelist?
Failing to verify these details can lead to significant vulnerabilities. As the industry grapples with the repercussions of such incidents, the need for robust security measures in decentralized finance remains critical.
