Base wstETH Vault Whitelist Exploit
An attacker whitelisted a fresh contract on an unidentified Base vault and borrowed against its Aave V3 position to drain about 1,783 wstETH, roughly $6 million.
Vuln-watch · relayed from a public source; see Source & attribution below
Summary
An attacker whitelisted a fresh contract on an unidentified Base vault and borrowed against its Aave V3 position to drain about 1,783 wstETH, roughly $6 million.
Incident
- Victim: Unidentified Base vault
- Date (UTC): 2026-10-04
- Estimated loss: $6.0M
- Chain(s): Base
- Attack type: private key compromise
- Funds status: stolen
- Attacker:
0x0B5126e1bc27C0de77e02e97945760A674EdB034
Recommended actions
- If you use Unidentified Base vault, move funds to a fresh wallet with a new seed phrase once the vendor confirms the root cause
- Update the wallet software only from official sources
- Beware of follow-on phishing: ignore unofficial "refund", "recovery", or "claim" links and DMs; use the project's verified channels only
Source & attribution
Full analysis on Blockchain Breaches, 0xCERT's incident archive: https://www.blockchainbreaches.com/en/breaches/base-wsteth-vault-2026. Primary sources: https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/ ; https://blockonomi.com/base-defi-vault-exploit-drains-6m-after-attacker-gains-whitelist-access ; https://news.bitcoin.com/security/6m-vanishes-from-crypto-vault-controlled-by-7-mystery-signers ; https://phemex.com/news/article/6m-in-wsteth-drained-from-base-network-protocol-98739.
References
- https://www.blockchainbreaches.com/en/breaches/base-wsteth-vault-2026
- https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/
- https://blockonomi.com/base-defi-vault-exploit-drains-6m-after-attacker-gains-whitelist-access
- https://news.bitcoin.com/security/6m-vanishes-from-crypto-vault-controlled-by-7-mystery-signers
- https://phemex.com/news/article/6m-in-wsteth-drained-from-base-network-protocol-98739
OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.
Published 2026-10-04 · last updated 2026-10-08
curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0230/signed.txt | gpg --verify