📅 Wednesday, 7 October 2026 · --:-- UTC Follow us
Ecosystem ▼
ID EN
Vault Tak Bertuan di Base Dibobol $6 Juta - Siapa Pun di Whitelist Bisa Kuras Aset Tanpa Kolateral

Ownerless Vault on Base Drained for $6M - Whitelisted Addresses Allowed to Extract Assets Without Collateral

An asset vault on Ethereum layer-2 network Base has been drained of $6 million, with no development team stepping forward to claim ownership. The anonymous vault was breached due to a fatal flaw in its whitelist system, while approximately $31.7 million in remaining funds was still locked inside when the incident occurred.

The attacker executed the exploit using a Safe multisignature wallet to slip a malicious contract directly into the lending vault’s whitelist. Once granted access, the contract promptly withdrew 1,783 aBaswstETH and swapped it for 1,783 wstETH via the Aave V3 protocol.

Immunefi security lead Gonçalo Magalhães revealed the underlying vulnerability: the contract logic allowed whitelisted entities to take assets without depositing any collateral at all. The vault operator’s identity remains completely unknown - on-chain records show only that the vault operated for 25 full days without a single Safe transaction before the attack struck.

Tragedy of a Known Vulnerability

Despite millions of dollars vanishing, no team has stepped forward to publicly claim ownership of the vault or outline remediation plans, even after 24 hours have passed. The loss is particularly ironic because the core issue could have been prevented had the developers not closed themselves off from the outside world.

A whitehat researcher had previously discovered the zero-collateral security loophole well before the attacker struck. However, the researcher could do little due to the absence of a bug disclosure channel, leaving no safe way to disclose the findings without facing legal risks.

According to Magalhães, a bug bounty program could have thwarted the attack from the start. The global security community would have quickly caught the glaring issue had the developers provided an official communication channel open for emergency reporting.

Evidence of Infrastructure Failure

The incident on the Base network adds to mounting evidence that smart contract audits are no longer an all-encompassing shield. Data shows that 88.3% of the total $764 million in crypto stolen throughout the second quarter of 2026 stemmed from infrastructure failures and compromised key management, rather than pure smart contract code flaws.

Launching projects anonymously is a frequent choice in the decentralized ecosystem. But leaving tens of millions of dollars in circulation without emergency contact channels has proven costly. When systems fail, there is no administrator in control to halt the asset theft. Reported by crypto.news.

Read also: This TRON Rental Site Drained $69,000 from 80 Victims - Ironically Google Gemini AI Deemed It Safe


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
📩 KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share