An asset vault on Ethereum layer-2 network Base has been drained of $6 million, with no development team stepping forward to claim ownership. The anonymous vault was breached due to a fatal flaw in its whitelist system, while approximately $31.7 million in remaining funds was still locked inside when the incident occurred.
The attacker executed the exploit using a Safe multisignature wallet to slip a malicious contract directly into the lending vault’s whitelist. Once granted access, the contract promptly withdrew 1,783 aBaswstETH and swapped it for 1,783 wstETH via the Aave V3 protocol.
Immunefi security lead Gonçalo Magalhães revealed the underlying vulnerability: the contract logic allowed whitelisted entities to take assets without depositing any collateral at all. The vault operator’s identity remains completely unknown - on-chain records show only that the vault operated for 25 full days without a single Safe transaction before the attack struck.
Tragedy of a Known Vulnerability
Despite millions of dollars vanishing, no team has stepped forward to publicly claim ownership of the vault or outline remediation plans, even after 24 hours have passed. The loss is particularly ironic because the core issue could have been prevented had the developers not closed themselves off from the outside world.
A whitehat researcher had previously discovered the zero-collateral security loophole well before the attacker struck. However, the researcher could do little due to the absence of a bug disclosure channel, leaving no safe way to disclose the findings without facing legal risks.
According to Magalhães, a bug bounty program could have thwarted the attack from the start. The global security community would have quickly caught the glaring issue had the developers provided an official communication channel open for emergency reporting.
Evidence of Infrastructure Failure
The incident on the Base network adds to mounting evidence that smart contract audits are no longer an all-encompassing shield. Data shows that 88.3% of the total $764 million in crypto stolen throughout the second quarter of 2026 stemmed from infrastructure failures and compromised key management, rather than pure smart contract code flaws.
Launching projects anonymously is a frequent choice in the decentralized ecosystem. But leaving tens of millions of dollars in circulation without emergency contact channels has proven costly. When systems fail, there is no administrator in control to halt the asset theft. Reported by crypto.news.
Read also: This TRON Rental Site Drained $69,000 from 80 Victims - Ironically Google Gemini AI Deemed It Safe
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




