A $6m Base Vault Drain Left One Question: Who Held the Keys?

A vault can follow every rule in its code and still leave everyone asking who gave permission. On Base, a reported $6 million wstETH withdrawal passed through an anonymous multisignature Safe and a freshly re-enabled borrower. The transactions are visible; the people, intent and explanation are not.

The episode is being described as a Base vault exploit, but that label must not outrun the evidence. No project has publicly claimed the vault, and no root cause has been confirmed. The urgent issue is narrower—and more uncomfortable: how can users assess a vault when its controller is anonymous and its whitelist can change without an identifiable operator explaining why?

What the transactions show

Security researchers tracked 1,783.067 aBaswstETH leaving an unnamed vault contract across six outflows on 4 October. The receipt tokens were redeemed through Aave V3 for about 1,783 wstETH, valued at roughly $6 million. Blockaid first estimated about $2.02 million across four transactions, then updated its alert to more than $6 million; ExVul reported the six-outflow total. These were evolving incident estimates, not a separately verified loss ledger.

The sequence is more revealing than the headline amount. ExVul’s timeline records the vault’s owner Safe disabling the newly added contract’s whitelist membership at 08:52:23 UTC on 4 October, then enabling it again at 08:53:51. At 08:55:01, about 70 seconds after readmission, the borrower received its first 1 aBaswstETH; five more outflows brought the total to 1,783.067. The same signing identities produced three successful ECDSA signature recoveries for each administrative action, ExVul said. That is evidence about transactions and signatures, not the identity or state of mind of the signers. The on-chain record of the Safe execution makes the administrative step inspectable; it cannot explain the humans behind it.

Flow diagram of the reported Base vault incident: 1,783.067 aBaswstETH left the unnamed vault across six outflows, was redeemed through Aave V3 into approximately 1,783 wstETH, and was valued by security firms at about $6 million.
Reported flow from the unnamed Base vault: 1,783.067 aBaswstETH across six outflows, redeemed through Aave V3 into about 1,783 wstETH worth roughly $6 million. Figures are security-research estimates.

What a valid Safe signature does—and does not—prove

The tempting story is an anonymous 3-of-7 Safe and a Base vault whitelist manipulated before a drain. That is a fair description of the sequence, but it does not settle whether a key was stolen, a signer deceived, or a withdrawal authorised in the ordinary course. Valid signatures mean the Safe accepted sufficient signatures under its rules; they do not establish who controlled those keys or what the signers intended.

ExVul said “the precise authorization failure remains unconfirmed.” GoPlus Security raised phishing, social engineering and insider collusion as possibilities, not findings. Those limits matter: there is no basis to claim a Base network compromise or a breach of Aave’s core lending contracts. The public chain can show calls and flows; by itself, it cannot establish consent, deception or beneficial ownership.

A competing community theory says the 1,783 wstETH matched the amount deposited on 5 June plus accrued interest, followed the same chunk pattern, and left another 8,000 WETH untouched—suggesting a legitimate withdrawal. This has not been independently verified. Even if the arithmetic holds, it would not identify the owner or explain why no public operator had confirmed the transaction. Treat this as a hypothesis, not exoneration or proof.

The governance gap is the story

This is where the “Base vault exploit” framing can obscure more than it reveals. The observable risk sits at the application level: an unnamed vault, an anonymous 3-of-7 Safe and a borrower whitelist. A permission list is a security boundary. If a newly admitted contract can access a large position, administrators should be identifiable enough to explain who proposed, approved and monitored that access. On-chain governance cannot be meaningfully scrutinised if the chain records authority but no accountable party interprets it.

Bitcoin.com News reported that the visible owner was an anonymous Safe and no project or operator had publicly claimed the vault at the time of its report. GoPlus later described it as unclaimed and estimated that about $31.7 million remained. That was GoPlus’s estimate at 23:40 UTC on 4 October—not a current balance or proof that all those assets remained exposed. The figure needs a live check before anyone repeats it as present fact.

Timeline of the reported 4 October 2026 Base vault incident: the Safe disabled and re-enabled a borrower whitelist entry, the first 1 aBaswstETH outflow followed about 70 seconds later, and security firms issued progressively updated estimates. The sequence alone does not establish intent or root cause.
Key administrative and incident timestamps reported by ExVul on 4 October UTC. The interval from re-enabling the borrower to its first recorded outflow was about 70 seconds; chronology does not establish intent or root cause.

Explain the permission, then the loss

The next useful disclosure is not another confident label. It is a post-mortem from whoever can speak for the vault: who controlled the Safe, how the borrower was added and re-enabled, what safeguards governed the whitelist, and whether signers believed they were authorising those actions. If no one can answer, users are left with a transaction trace and a name-free multisig—not enough to distinguish an exploit from an authorised withdrawal.

That ambiguity is itself consequential. DeFi users often assess code, collateral and audit claims; they also need to know who holds administrative power and how that power is checked. A vault that cannot identify an accountable operator makes that assessment harder precisely when unusual activity occurs.

Until an operator or credible investigation supplies evidence, describe this as an unexplained withdrawal or security incident—not a proven insider job, key compromise, or attack on Base or Aave. The mystery is not simply where the wstETH went. It is whether anyone with authority over the vault can give the public a verifiable account of why the whitelist opened the door.

This article is for information purposes only and should not be considered trading or investment advice. Nothing herein shall be construed as financial, legal, or tax advice. Bullish Times is a marketing agency committed to providing corporate-grade press coverage and shall not be liable for any loss or damage arising from reliance on this information. Readers should perform their own research and due diligence before engaging in any financial activities.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top