Approximately $6 million Withdrawn from Vault on Base, Operator Unknown
Key Points of This Article
- Attack contract re-registered by multi-signature
- Damage amount expanded from initial estimate of approximately $2.02 million
Unauthorized Withdrawal from Vault on Base
On the 4th, approximately 1,783 wstETH (worth about $6 million) was illegally withdrawn from a vault (a smart contract that holds and manages funds) on the Layer 2 network Base, with the operator remaining unknown. Blockchain security firm PeckShield reported the damage on X that same night. As of the 5th, the operator had not come forward.
wstETH is a wrapped version of the staked Ethereum (ETH) token "stETH" issued by leading liquid staking provider Lido. Unlike stETH, the balance does not fluctuate daily, and its value in ETH increases according to the accumulation of staking rewards.
Withdrawal Immediately After Whitelist Re-registration
According to Blockaid, which first reported the anomaly, a newly created contract was added to the vault's whitelist, allowing the attacker to borrow aBaswstETH from the vault and send it to the attacker's contract. aBaswstETH is a receipt token issued when wstETH is deposited in Aave V3's Base market. The attacker redeemed this on Aave to obtain wstETH.
The vault is operated by a multi-signature (Safe) that can be controlled with the approval of 3 out of 7 owners. According to a timeline released by security firm ExVul, this multi-signature removed the relevant contract from the whitelist at 17:52 JST and re-registered it one minute later at 17:53. Both operations had valid signatures from existing signers. The first borrowing was executed approximately 70 seconds after the re-registration.
Damage Amount Expanded to Approximately Three Times Initial Estimate
In an initial report released around 18:20, Blockaid stated that approximately $2.02 million had flowed out in about four transactions, and the attack was ongoing. By 18:56, PeckShield reported the damage amount to be approximately $6 million, and CertiK issued a similar warning.
There is no information indicating that there was a problem with Aave's infrastructure or the Base network itself, and it has not been confirmed whether the signer's keys were leaked or if the signing process was manipulated. The attacker's address starts with "0x0B5126" and ends with "B034."
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Ethereum ETF Loses $641.3 Million Over Eight Sessions

Crypto firms turn to Anthropic AI to find security flaws

Ethereum Foundation Releases EIP Draft Proposing Proof of Execution Chain and Constant Time Synchronization

Thailand SEC Allows Bitcoin and Ethereum ETFs to Trade

Sean Bowe Criticizes Justin Drake's Quantum Warning for Undermining Credibility

OSL Launches USDGO Market-Neutral Fund On-Chain for Hong Kong Investors

Google Cloud Shuts Down Blockchain Service and Sets Final Migration Deadline to Quicknode

Citrini Research predicts tokenization could surpass BTC and ETH

Ethereum Sepolia Test Network Increases Gas Limit to 200 Million

Report Estimates $50 Billion Inflow into Crypto Market in 2023, Momentum Improves in Q4

31.2% of Bitcoin Supply Held Under Visible Public Keys

On-chain Options Protocol Derive V3 Migration Completed, Trading Resumes

Banks Prepare for Quantum Transition with 2027 Target

A $1,000 MetaMask incident could turn Ethereum’s staking queue into a $5 billion traffic jam

Starknet Plans to Become a Quantum-Resistant Layer 1

BitGo CEO: Bitcoin Hacking is Impossible Amid AI Decryption Warnings

Sber Tests Cryptocurrency Operations in Its App

Taiko Proposal 39 Completed, Supporting Permit and Permit2

Vitalik Buterin Warns About the Impact of Artificial Intelligence on Cryptography

2.6 Trillion KOK Coin Fraud Case, Calls for Strengthening FIU Role in National Assembly

Oneiro Launches Revolution Network V2

HashKey, BitGo add ETH and SOL staking for institutions

Polygon Open Money Stack adds TRON support for USDT payments and payouts

WEEX Exclusive:September Fed Minutes Point to Another Hike This Year| WEEX TradFi Daily Brief (October 8, 2026)
Major equity indexes closed lower on October 7 ET. Long-end yields rose again, and the 30-year yield hit a roughly 24-year high. September Fed minutes showed most participants thought another increase in the federal funds target range before year-end could be appropriate. CME pricing for a 25 bp hike at the October 27–28 meeting has fallen below 20%, far below about 70% in the days after the September decision. Bitcoin traded near $83,300. The October 8 focus is jobless claims and pre-market earnings from Pepsi and Delta.

September Fed Minutes Point to Another Hike This Year| WEEX TradFi Daily Brief (October 8, 2026)
Major equity indexes closed lower on October 7 ET. Long-end yields rose again, and the 30-year yield hit a roughly 24-year high. September Fed minutes showed most participants thought another increase in the federal funds target range before year-end could be appropriate. CME pricing for a 25 bp hike at the October 27–28 meeting has fallen below 20%, far below about 70% in the days after the September decision. Bitcoin traded near $83,300. The October 8 focus is jobless claims and pre-market earnings from Pepsi and Delta.

Coin Orders to the Most Favorable Exchange: Key Issue of 'Best Execution Duty' Emerges to Change Market Landscape

Metis Launches Rise Monthly Developer Incentive Program to Reward AI Agent Deployment Teams

Grayscale Adds BitGo as Custodian for Hyperliquid Staking ETF

Vitalik Buterin Warns AI May Undermine Cryptography, Recommends Prioritizing Hash-Based Cryptography







