Article

GoPlus: A vault contract on Base was attacked, with losses of approximately 6000000 USD, while 31700000 USD assets remain at risk

BlockBeats reported that October 5, according to disclosures by the GoPlus security team, an unclaimed vault contract on Base was attacked. The attacker used Safe multisig to add a malicious contract to the lending whitelist, withdrew 1783 aBaswstETH, and redeemed approximately V3 1783 wstETH on Aave, resulting in losses of approximately 6000000 USD.

The attack reportedly stemmed from failures in multisig governance and access controls. The project team had not executed a Safe transaction for the treasury contract for 25 days before the attack, suggesting a possible social engineering attack or internal collusion. The Aave core contracts and Base itself were not affected. As of press time, approximately 31700000 USD of the assets in the attacked vault remained at risk.

Original link https://m.theblockbeats.info/flash/370247