3-of-7 multisig—ended up losing to the “1 minute.”
A Base vault that nobody has claimed up to now was drained: on 10/4, about 1783 wstETH were withdrawn (a packaged version of Lido staked $ETH ), roughly $6 million 💀
Piecing together the on-chain post-mortems from several security firms (Blockaid / CertiK / PeckShield / ExVul / GoPlus):
1️⃣ A newly deployed contract was added to the vault’s whitelist. It was used to borrow aBaswstETH, then redeemed on Aave V3 back into wstETH, and transferred to the attacker’s address.
2️⃣ ExVul timeline: the vault owner’s Safe removed this contract from the whitelist at 08:52 UTC, then added it back at 08:53 UTC—both transactions used valid signatures from existing signers. About 70 seconds later, the first loan was executed.
3️⃣ GoPlus assessment: the multisig governance plus access control failed. The team hadn’t touched this Safe in the 25 days leading up to the attack. Social engineering or an insider is possible. No one compromised Aave’s core contracts or the Base chain itself.
4️⃣ GoPlus figure: about $31.7 million worth of assets in the vault are at risk. I haven’t yet found a second independent source for this number, so treat it as a reference for now.
My take:
This wasn’t a contract bug—it was a “human” bug. Multisigs only ensure the “right number of people sign,” not that “the people signing are awake.”
3/7 sounds pretty safe, but all 7 signers are anonymous, they were inactive for 25 days, and the whitelist was revoked and restored within a minute… This storyline deserves review more than the exploit itself.
For project teams still using Safe to manage funds: before signing, check the calldata—don’t just look at Telegram.
Screening without education: DYOR. Not investment advice.
Source: public disclosures by Blockaid / CertiK / PeckShield / ExVul / GoPlus; reports by CryptoTimes, Bitcoin.com News, TokenPost
#Base #DeFi security
A Base vault that nobody has claimed up to now was drained: on 10/4, about 1783 wstETH were withdrawn (a packaged version of Lido staked $ETH ), roughly $6 million 💀
Piecing together the on-chain post-mortems from several security firms (Blockaid / CertiK / PeckShield / ExVul / GoPlus):
1️⃣ A newly deployed contract was added to the vault’s whitelist. It was used to borrow aBaswstETH, then redeemed on Aave V3 back into wstETH, and transferred to the attacker’s address.
2️⃣ ExVul timeline: the vault owner’s Safe removed this contract from the whitelist at 08:52 UTC, then added it back at 08:53 UTC—both transactions used valid signatures from existing signers. About 70 seconds later, the first loan was executed.
3️⃣ GoPlus assessment: the multisig governance plus access control failed. The team hadn’t touched this Safe in the 25 days leading up to the attack. Social engineering or an insider is possible. No one compromised Aave’s core contracts or the Base chain itself.
4️⃣ GoPlus figure: about $31.7 million worth of assets in the vault are at risk. I haven’t yet found a second independent source for this number, so treat it as a reference for now.
My take:
This wasn’t a contract bug—it was a “human” bug. Multisigs only ensure the “right number of people sign,” not that “the people signing are awake.”
3/7 sounds pretty safe, but all 7 signers are anonymous, they were inactive for 25 days, and the whitelist was revoked and restored within a minute… This storyline deserves review more than the exploit itself.
For project teams still using Safe to manage funds: before signing, check the calldata—don’t just look at Telegram.
Screening without education: DYOR. Not investment advice.
Source: public disclosures by Blockaid / CertiK / PeckShield / ExVul / GoPlus; reports by CryptoTimes, Bitcoin.com News, TokenPost
#Base #DeFi security