BREAKING
Oct 5Someone Just Drained $6 Million From a Vault on Base. Nobody Will Say Whose Vault It Was●Oct 4Blast Pulled In $2 Billion Before It Even Had a Chain. Now It's Switching the Chain Off Because It Can't Cover the Bills●Oct 3Someone Stole Less Than $1,000 From MetaMask's Validators. MetaMask Is Pulling $1.4 Billion of ETH Out of Staking Because of It●Oct 2The SEC Just Told Fund Managers They Can Hold Your Crypto Keys Themselves. The Catch: Every Quarter They Have to Write Down That Nobody Else Will●Oct 1Two Appeals Courts Just Said Kalshi Sports Bets Are Gambling. The CFTC, Run by One Man, Is Rewriting the Dictionary So They Aren't.●Sep 30Two Weeks After Its Engineers Were Charged Over HYPE Perps, Robinhood Says It Will Sell HYPE Perps to Every American●Sep 29Senate Investigators Checked 846 Sanctioned Iran Wallets. 84% of Them Ran on Tether●Sep 2853 Memecoins on Robinhood Chain Turned Out to Be One Crew. They Took $18.4M, and Each Rug Paid for the Next●Sep 27KelpDAO Is Suing LayerZero for the $292M Hack. Its Evidence: LayerZero Signed Off on the Exact Setup That Got Drained●Sep 26The SEC Is About to Be Two People. 'Crypto Mom' Hester Peirce Just Quit, and Nobody Has Been Nominated to Replace Her●Oct 5Someone Just Drained $6 Million From a Vault on Base. Nobody Will Say Whose Vault It Was●Oct 4Blast Pulled In $2 Billion Before It Even Had a Chain. Now It's Switching the Chain Off Because It Can't Cover the Bills●Oct 3Someone Stole Less Than $1,000 From MetaMask's Validators. MetaMask Is Pulling $1.4 Billion of ETH Out of Staking Because of It●Oct 2The SEC Just Told Fund Managers They Can Hold Your Crypto Keys Themselves. The Catch: Every Quarter They Have to Write Down That Nobody Else Will●Oct 1Two Appeals Courts Just Said Kalshi Sports Bets Are Gambling. The CFTC, Run by One Man, Is Rewriting the Dictionary So They Aren't.●Sep 30Two Weeks After Its Engineers Were Charged Over HYPE Perps, Robinhood Says It Will Sell HYPE Perps to Every American●Sep 29Senate Investigators Checked 846 Sanctioned Iran Wallets. 84% of Them Ran on Tether●Sep 2853 Memecoins on Robinhood Chain Turned Out to Be One Crew. They Took $18.4M, and Each Rug Paid for the Next●Sep 27KelpDAO Is Suing LayerZero for the $292M Hack. Its Evidence: LayerZero Signed Off on the Exact Setup That Got Drained●Sep 26The SEC Is About to Be Two People. 'Crypto Mom' Hester Peirce Just Quit, and Nobody Has Been Nominated to Replace Her●
BTC -- --%
ETH -- --%
Fear & Greed F&G 70 Greed
ESC
Type to search articles
Someone Just Drained $6 Million From a Vault on Base. Nobody Will Say Whose Vault It Was
BREAKING

Someone Just Drained $6 Million From a Vault on Base. Nobody Will Say Whose Vault It Was

On Sunday morning, more than $6 million left a DeFi vault on Base in about 40 minutes.

A day later, there’s still no public answer to the most basic question: whose vault was it?

The vault was controlled by a 3-of-7 Safe multisig. All seven signers are anonymous. No protocol, team, or fund has come forward to say the money was theirs. The security firms tracking the drain haven’t named the owner either.

What Happened

The timeline from security firms on October 4:

  • ~09:21 UTC: Blockaid flagged an active attack on a Base vault, with about $2.02 million already gone.
  • ~09:40 UTC: The losses passed $6 million.
  • Total: roughly 1,783 wstETH (Lido’s wrapped staked ETH) traced out of the vault to an attacker address starting 0x0B5126.

Blockaid described the method: “a brand-new contract was added to the vault’s whitelist, then borrowed aBaswstETH from the vault and sent the aTokens to the attacker’s contract.”

aBaswstETH is the receipt token Aave gives you when you supply wstETH on Base. The attacker took those receipts and redeemed them through Aave V3 for the underlying wstETH. Exvul counted six separate outflows.

Blockaid, PeckShield, CertiK, Exvul and Spot On Chain all tracked the incident and landed on the same rough loss figure.

Base Wasn’t Hacked. Aave Wasn’t Hacked. So What Was?

Every report so far agrees on what didn’t break:

  • Base, Coinbase’s L2, was not compromised.
  • Aave’s core contracts have not been blamed. Aave was just where the attacker cashed out the receipts.

The problem was at the vault level, specifically who got onto the whitelist and how. Per TokenPost, the malicious contract was added through the vault’s Safe multisig. That means either the attacker got enough of the seven signers to approve it, or something else in the signing setup went wrong.

Which one is still unknown. TokenPost reports that social engineering or collusion were raised as possible explanations, but neither has been established. Nobody has confirmed whether keys were compromised, signers were tricked into approving a bad transaction, or the failure was something else.

Two other details from TokenPost’s reporting:

  • The vault hadn’t executed a Safe transaction in 25 days before the attack.
  • Roughly $31.7 million in assets were still at risk when the incident was disclosed on October 5.

Seven Signers, Zero Names

A 3-of-7 multisig sounds safe on paper. You need three separate people to sign off before anything moves.

That only helps if you know who those seven people are and how they protect their keys. Here, the public knows neither. The Safe has no protocol name attached, its signer addresses haven’t been tied to anyone, and the owner hasn’t spoken.

So depositors and anyone exposed to that $31.7 million have nobody to hold accountable and nobody giving updates.

DeFi has gone through this before. Big losses in the last few years came less from broken smart contracts and more from signing processes: keys, multisig ceremonies, and the people pressing “approve.” This one fits that pattern, though the cause here hasn’t been confirmed.

It’s also not the only Safe-related incident this week. On October 2, SlowMist reported that an Aave v3 Loop Safe Module had been compromised, with about 114 ETH lost across two Safe wallets.

Why This Matters for Crypto Jobs

Every vault with hundreds of millions in it runs on a few people signing transactions. When that fails and nobody owns it publicly, it’s an operations failure as much as a code failure. Teams are hiring for exactly that gap:

  • Signer ops and key management. People who can design multisig setups, rotate keys, run signing ceremonies, and make sure a whitelist change doesn’t get approved blindly. Teams are paying well for “boring” opsec.
  • Transaction simulation and monitoring. Blockaid caught this one live. Firms like Blockaid, Hypernative and others need engineers who can spot a weird admin transaction before the money moves, not after.
  • Incident response. Tracing funds, coordinating with exchanges for freezes, and writing post-mortems. Security firms put out timelines within minutes on Sunday; that work needs people.
  • Smart contract auditors who look at access control, not just math. “Who can add to the whitelist, and what stops them” is an audit question.

If you’re a dev at a protocol with a multisig, ask your team: who are our signers, how do they verify what they sign, and what happens if three of them get fooled on a Sunday morning?

Want to be on the team that catches the next one? Browse open Web3 security, auditing and protocol engineering roles at Cryptogrind and get hired where the hiring is happening.

How did this hit?

Discussion

Comments are powered by GitHub. Sign in with your GitHub account to chime in.

Related jobs on Cryptogrind

View all

Looking for your next crypto role?

Browse hundreds of Web3 and crypto positions on Cryptogrind — from smart contract engineers to DeFi analysts.

Browse jobs