An anonymous vault on Base was attacked, with approximately 6000000 USD in losses, while 31700000 USD assets remain at risk
BIBIBI
AT A GLANCE
GoPlus said that an unclaimed vault on Base was attacked, with losses of approximately 6000000 USD, while approximately 31700000 USD in assets remain at risk.
Article
GoPlus: A vault contract on Base was attacked, with losses of approximately 6000000 USD, while 31700000 USD assets remain at risk
BlockBeats reported that October 5, according to disclosures by the GoPlus security team, an unclaimed vault contract on Base was attacked. The attacker used Safe multisig to add a malicious contract to the lending whitelist, withdrew 1783 aBaswstETH, and redeemed approximately V3 1783 wstETH on Aave, resulting in losses of approximately 6000000 USD.
The attack reportedly stemmed from failures in multisig governance and access controls. The project team had not executed a Safe transaction for the treasury contract for 25 days before the attack, suggesting a possible social engineering attack or internal collusion. The Aave core contracts and Base itself were not affected. As of press time, approximately 31700000 USD of the assets in the attacked vault remained at risk.
Original link https://m.theblockbeats.info/flash/370247
Key points
01
October 5, with BlockBeats citing disclosures from the GoPlus security team about the incident.
02
The target of the attack was an unclaimed vault contract on Base.
03
The report said that the attacker used Safe multisig to add a malicious contract to the lending whitelist.
04
The attacker withdrew 1783 aBaswstETH and, on Aave V3 redeemed approximately 1783 wstETH.
05
The report estimated the losses at approximately 6000000 USD。
06
As of press time, approximately 31700000 USD of the assets in the attacked vault remained at risk.
07
The report explicitly stated that the Aave core contracts and Base itself were not affected.
08
The report said that the project team had not executed a Safe transaction for the treasury contract for 25 days before the attack.
AI-assisted interpretation
The following is analysis, separate from reported facts. Verify important claims independently.
The issue occurred in a vault contract located on Base. According to the report, the attacker exploited permissions related to Safe multisig to add a malicious contract to the lending whitelist, then withdrew and redeemed assets. The report estimated the losses incurred at approximately 6000000 USD, while stating that approximately 31700000 USD in the vault could also be threatened. The vault was not publicly claimed by the project, and the report also said that the Aave core contracts and Base itself were not affected.
Why it matters to readers
The disclosed losses are substantial, and more vault assets remained at risk as of press time. The incident also shows that failures in multisig governance, whitelist management, and access controls can directly compromise the security of vault funds.
Beginners should distinguish between “a vault deployed on Base being attacked” and “Base itself being attacked.” They should also distinguish between the attack process using Aave V3 to redeem assets and damage to the Aave core contracts; the original text explicitly states that the latter two were not affected. Before participating in on-chain vaults, pay particular attention to multisig permissions, whitelist management, and access-control arrangements.
Risks and unknowns
The vault involved was not publicly claimed by the project, and its specific ownership cannot be confirmed from the original text.
The original text said that the attack may have involved social engineering or internal collusion, but did not confirm the specific cause.
Related Developments
Loading event timeline…
approximately 31700000 USD The assets were only described as being at risk as of press time; it is unknown whether they were subsequently transferred, protected, or continued to be extracted.
The original text did not state approximately 6000000 USD whether the losses had already been recovered.
The original text does not provide the attack address, malicious contract address, or complete flow of funds.
Related concepts
Vault contract
This term is not in the glossary yet. Browse related concepts in the glossary.