Skip to main content
AVOID.NET

Unidentified Base Vault (October 2026 Whitelist Exploit)

avoid.net/unidentified-base-vault-october-2026-whitelist-exploit→8/100·78% conf.
[AI-DRAFTED · AWAITING FACT-CHECK]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·3K1ucu…GjXx
last updated 2026-10-09

Summary

On October 4, 2026, a DeFi vault operating on the Base network (contract address 0xD1895f2019c2152FC2b9022D57f19198c4CFCABC) lost approximately 1,783 wstETH (~$6 million) after a malicious contract was added to the vault's borrower whitelist via a 3-of-7 Safe multisig. The vault's operator identity had not been publicly disclosed as of October 9, 2026, and no post-incident statement, remediation plan, or confirmed fund recovery has emerged. A further ~$31.7 million in assets remained in the vault under the same multisig governance structure after the exploit.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about Unidentified Base Vault (October 2026 Whitelist Exploit)?

Timeline(10 events)

30 September 2026

A security flaw in the vault's access control was allegedly identified approximately four days before the exploit, but researchers lacked a public disclosure channel as the vault's operator had not identified itself.

TokenPost

4 October 2026

At 08:52 UTC, the vault's 3-of-7 Safe multisig executed a transaction removing a newly deployed, attacker-controlled contract from the vault's borrower whitelist.

Crypto Briefing

4 October 2026

At 08:53 UTC — approximately one minute later — the same multisig re-added the identical attacker contract to the whitelist. Both transactions carried valid ECDSA signatures from existing signers.

Startup Fortune

4 October 2026

Between 08:53 and 09:12 UTC (~19 minutes), the attacker's whitelisted contract withdrew 1,783.067 aBaswstETH from the vault across six separate transfers and redeemed them through Aave V3 for approximately 1,783 wstETH (~$6 million).

CryptoTimes

4 October 2026

At 09:21 UTC, Blockaid flagged the ongoing exploit; approximately $2.02 million had already been drained at time of detection.

Startup Fortune

4 October 2026

At 09:56 UTC, PeckShield confirmed the total loss of 1,783 wstETH (~$6 million). CertiK alerted on the proxy contract at 09:59 UTC. ExVul provided a full breakdown at 10:09 UTC.

CryptoTimes

4 October 2026

Stolen wstETH reported routed toward Lido's Base-to-Ethereum bridge, which carries a seven-day settlement window before mainnet arrival.

Crypto Briefing

5 October 2026

GoPlus Security and additional security firms disclosed that approximately $31.7 million in assets remained in the vault, still governed by the same compromised multisig. No operator claimed responsibility.

Shattered.io

7 October 2026

TokenPost reported that more than 24 hours after the exploit, no team had publicly claimed responsibility or disclosed remediation measures. The vault operator remained anonymous.

TokenPost

9 October 2026

As of this date, no post-mortem, fund recovery, key rotation, or vault freeze has been publicly announced. Vault operator identity remains undisclosed.

Multiple sources
Provenance & Audit Trail

Decision Log

  • #1publishRecorded on Solana ✓10/9/2026, 5:58:48 PM
    slot 454950461 · hash BYP8erRhDLk1gPbBn8cDCG79nk9uN91wxg323nCnVZKx

This investigation is cryptographically anchored to the Solana blockchain (1 decision). 0 of 12 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 10/9/2026, 5:58:36 PM

last updated: 10/9/2026, 5:58:36 PM

avoid.net — verified advice for a post-truth world