-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 0xCERT Security Advisory 0xCERT-2026-0230 ============================================================ Advisory-ID: 0xCERT-2026-0230 Severity: High Published: 2026-10-04T00:00:00.000Z Updated: 2026-10-08T22:51:22.909Z Chains: Base URL: https://www.0xcert.com/advisory/0xCERT-2026-0230 Title: Base wstETH Vault Whitelist Exploit Summary - ------- An attacker whitelisted a fresh contract on an unidentified Base vault and borrowed against its Aave V3 position to drain about 1,783 wstETH, roughly $6 million. Details - ------- Summary An attacker whitelisted a fresh contract on an unidentified Base vault and borrowed against its Aave V3 position to drain about 1,783 wstETH, roughly $6 million. Incident - - Victim: Unidentified Base vault - - Date (UTC): 2026-10-04 - - Estimated loss: $6.0M - - Chain(s): Base - - Attack type: private key compromise - - Funds status: stolen - - Attacker: 0x0B5126e1bc27C0de77e02e97945760A674EdB034 Recommended actions - - If you use Unidentified Base vault, move funds to a fresh wallet with a new seed phrase once the vendor confirms the root cause - - Update the wallet software only from official sources - - Beware of follow-on phishing: ignore unofficial "refund", "recovery", or "claim" links and DMs; use the project's verified channels only Source & attribution Full analysis on Blockchain Breaches, 0xCERT's incident archive: https://www.blockchainbreaches.com/en/breaches/base-wsteth-vault-2026. Primary sources: https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/ ; https://blockonomi.com/base-defi-vault-exploit-drains-6m-after-attacker-gains-whitelist-access ; https://news.bitcoin.com/security/6m-vanishes-from-crypto-vault-controlled-by-7-mystery-signers ; https://phemex.com/news/article/6m-in-wsteth-drained-from-base-network-protocol-98739. References - ---------- - - https://www.blockchainbreaches.com/en/breaches/base-wsteth-vault-2026 - - https://www.cryptotimes.io/2026/10/04/base-vault-hack-6m-in-wsteth-drained-after-attacker-gains-whitelist-access/ - - https://blockonomi.com/base-defi-vault-exploit-drains-6m-after-attacker-gains-whitelist-access - - https://news.bitcoin.com/security/6m-vanishes-from-crypto-vault-controlled-by-7-mystery-signers - - https://phemex.com/news/article/6m-in-wsteth-drained-from-base-network-protocol-98739 Verify with the 0xCERT OpenPGP key: https://www.0xcert.com/pgp.asc Fingerprint: 5F94 3ED1 1E50 CF31 2128 C493 CCC7 D9EC 9415 723D -----BEGIN PGP SIGNATURE----- wrsEARYKAG0FgmrIPAcJEDe9Tbcr+ZxrRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmfT7SBu6/pzCxDpCW64LTEwuoBYRpHyL9yIqIZ2 6H5S0RYhBGCkkFZbJcT5QWu27ze9Tbcr+ZxrAADBRQEAvn+xLY66lNHvxXam ZY5eGccLbZQImDHyOGamS2A4oR0BAL3nZ4lvnWcgQwd6h86xilkK7BNzQBuE G+TzlsxKoscF =6oMP -----END PGP SIGNATURE-----