T
iTokenly

Unidentified Base vault (Aave V3 wstETH position) hack — October 2026

Verified — 5 sourcesLast checked October 4, 2026

Incident facts

Date of incident
Publicly disclosedOctober 4, 2026
Target typeOther
Loss$5,992,000Price at time of incident
MethodOther or undisclosedA contract added to the vault's whitelist through its owner's 3-of-7 Safe, with valid signatures, withdrew the vault's Aave receipt tokens; how those signatures were obtained has not been disclosed
ChainsBase
OutcomeUnresolved

What happened

An unidentified vault on Base that held a leveraged wstETH position on Aave V3 lost 1,783.067 wstETH, about $5.99m, on 4 October 2026. The vault is an upgradeable proxy contract owned by a Safe multisig that needs three of its seven signers to act. No protocol, fund or company has said the vault is theirs, and none of the seven signers has been publicly identified. Blockaid flagged the attack at 09:20 UTC, when about $2.02m had gone, and PeckShield, CertiK and ExVul later put the total at about 1,783 wstETH. Neither Aave's core contracts nor the Base network were compromised.

The vault let whitelisted contracts move its Aave position. According to ExVul, the owner Safe removed the attacker's newly deployed contract from the whitelist at 08:52 UTC and re-enabled it at 08:53, both changes carrying valid signatures from the Safe's existing signers. This registry read from the chain that both transactions were submitted by the address that had deployed the vault in February 2025, while the Safe's earlier transactions had been submitted by a different address. From 08:55 UTC the attacker's contract pulled the vault's Aave receipt tokens, aBaswstETH, in six transfers: a test of one token, then 100, three of 500 and a final 182.067 between 09:08 and 09:12 UTC. The attacker redeemed the 1,783.067 tokens through Aave for wstETH at 09:23 UTC and moved the wstETH to another address at 10:47. How the signatures for the whitelist change were obtained, whether through compromised keys, a manipulated signing process or something else, has not been disclosed.

The amount recorded is the 1,783.067 aBaswstETH that left the vault, which this registry read from its token transfers, valued at the wstETH price of those minutes, about $3,360. When this registry checked later on 4 October, the vault still held about $31.8m of collateral against $7.8m of debt on Aave, so the theft did not push it into liquidation. No owner had come forward by the evening of 4 October, and no post-mortem, freeze, recovery or bounty offer had been announced.

Sources

  1. Blockaid on XSecondary · retrieved 2026-10-04
  2. The Crypto TimesSecondary · retrieved 2026-10-04
  3. Bitcoin.com NewsSecondary · retrieved 2026-10-04
  4. Vault token transfers on Base, read by this registryOn-chain · retrieved 2026-10-04
  5. Owner Safe transactions on Base, read by this registryOn-chain · retrieved 2026-10-04

Changes to this entry

  • Recorded on the day of the attack. The amount is the 1,783.067 aBaswstETH that left the vault, read by this registry from the chain and valued at the wstETH price of those minutes. The vault's owner has not been identified and the way the whitelist change was signed is unexplained, so the entity, vector and outcome are provisional.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Unidentified Base vault (Aave V3 wstETH position) hack — October 2026", iTokenly, accessed 2026-10-04, https://itokenly.com/hacks/base-vault-wsteth-october-2026
https://itokenly.com/hacks/base-vault-wsteth-october-2026

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.