Base Treasury Vault Exploited, About $6 Million Drained

AI Market Summary
A Base-chain treasury contract was compromised via multisig governance and access-control failures, enabling an attacker to whitelist a malicious lender and drain 1,783 aBaswstETH, redeemed into ~1,783 wstETH on Aave V3 (~$6m). While Aave core contracts and Base were unaffected, the incident highlights operational and social-engineering risk in multisig setups, with ~$31.7m reportedly still exposed in the compromised treasury.
Impact level
● Medium
Affected assets
ETH/USDT+1.21%
AI Insight · ETH/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
HuoXing Finance reported that on Oct. 5 the GoPlus security team flagged a breach involving a treasury contract on Base that the project team had not publicly acknowledged. The attacker used a Safe multisig to add a malicious contract to the lending whitelist, then withdrew 1,783 aBaswstETH and redeemed roughly 1,783 wstETH on Aave V3, for losses estimated at about $6 million. GoPlus said the incident points to breakdowns in multisig governance and access controls. The project team had not executed any Safe transactions tied to the treasury contract for 25 days before the exploit, raising the possibility of social engineering or insider collusion. Aave's core contracts and the Base network were not impacted. At the time of publication, around $31.7 million in assets remained at risk in the compromised treasury.