Unidentified Base Vault (Safe Multisig Whitelist Exploit)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·N7mhFY…h68PSummary
An unclaimed DeFi vault on the Base chain, deployed via an OpenZeppelin transparent proxy and governed by a 3-of-7 Safe multisignature wallet, lost approximately 1,783 wstETH (around $6 million) on October 4, 2026, after an attacker's contract was briefly added to the vault's Aave V3 borrower whitelist. No protocol or team has publicly claimed ownership of the vault, and roughly $31.7 million in additional deposits reportedly remains in it and exposed to further risk. The incident is under active investigation by multiple blockchain security firms, and the identity of the vault operator and the root cause of the multisig's behavior remain unconfirmed.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(4 events)
October 2026
The vault's 3-of-7 Safe multisig removes a contract later linked to the attacker from the vault's Aave V3 borrower whitelist at approximately 08:52 UTC, then re-adds the same contract at approximately 08:53 UTC, roughly one minute later, following 25 days of multisig inactivity.
Crypto BriefingOctober 2026
Security monitoring firm Blockaid flags an initial drain of roughly $2 million from the vault across multiple transactions, around 09:20 UTC.
CryptoTimesOctober 2026
Total confirmed loss reaches approximately 1,783.067 aBaswstETH, redeemed for roughly 1,783 wstETH (around $6 million), across six outflow transactions; part of the funds reportedly begin moving toward a Base-to-Ethereum bridge associated with Lido.
CryptoTimes / Crypto BriefingOctober 2026
Reporting establishes that roughly $31.7 million in additional vault deposits remains unaccounted for by any public operator claim and is described as still at risk; the vault's operating protocol remains unidentified.
mpost.ioDecision Log
- hash: B872XxRoB1y8URPyf9wsL2xcXRJBqL4MwaWdoDcRJsJN
This investigation is cryptographically anchored to the Solana blockchain (1 event). 0 of 4 cited source URLs have an Internet Archive snapshot.
model: claude-code-investigator
generated: 10/5/2026, 8:04:29 PM
last updated: 10/5/2026, 8:04:32 PM
avoid.net — verified advice for a post-truth world