Base Vault Multisig Drain Leaves Seven Signers Unidentified
About $6 million in wstETH was drained from an unclaimed vault on Base after its 3-of-7 Safe approved a new contract, and two days later no one has publicly identified the signers.

An unusual exploit on Coinbase's Base network is notable less for its size than for what remains unknown. On Sunday, October 4, 2026, about 1,783 wrapped staked ether (wstETH), worth roughly $6 million, was removed from a vault whose controlling multisig had just approved the attacker's contract. The Base vault multisig drain did not involve a bug in Base or in Aave's core contracts, investigators say, and in public reporting so far no protocol, fund or company has claimed the vault.
What happened
Security firm Blockaid raised the first public alert at about 09:21 UTC on October 4, when roughly $2.02 million had already left the vault, according to Bitcoin.com News. Within about 40 minutes the tally had passed $6 million. PeckShield, CertiK and ExVul converged on similar figures: 1,783.067 aBaswstETH, Aave's receipt token for wstETH supplied on Base, was borrowed from the vault and redeemed through Aave into the underlying wstETH. ExVul counted six outflows.
The mechanism ran through the vault's permission list. ChainReport said on-chain analysis shows the attacker's newly deployed contract was removed from the vault's whitelist at about 08:52 UTC and added back roughly a minute later. Both operations went through the controlling Safe with the required three valid owner signatures. Once whitelisted, the contract could access the vault's Aave V3 position and move the receipt tokens out.
The vault is an OpenZeppelin transparent proxy whose owner is a Safe created about 324 days ago that requires three of seven signatures to act. The Safe's address is visible on Basescan, but it carries no public protocol name, and none of the seven signer addresses has been tied to a person or organization by the firms tracking the incident, Bitcoin.com News reported.
After the drain, the funds started moving. Citing on-chain tracker PublicAML, ChainReport said the attacker obtained gas through Tornado Cash-linked activity, routed about 1,001 wstETH toward Lido's bridging infrastructure for transfer to Ethereum, and left about 782 wstETH on Base at the time of the tracker's snapshot.
Why it matters
The Base vault multisig drain is a reminder that a multisig is only as strong as the process behind each signature. A cryptographically valid transaction proves that the threshold was met, not that the signers understood or intended what they approved. "No public evidence currently establishes whether private keys were compromised, signers were deceived, the signing workflow was manipulated or another authorization failure occurred," ChainReport wrote. That leaves several possibilities open, from stolen keys to a manipulated signing interface to insider involvement, and none has been confirmed.
The sequence of the two whitelist changes is itself unusual. Removing a contract and adding it back a minute later, both with valid signatures, is not a typical administrative pattern, and investigators have not offered an explanation for it. Bitcoin.com News also noted that upgrade authority over the vault sits with a separate set of contracts, adding another layer between the vault and whoever ultimately controls it.
The incident also sharpens a distinction that matters to anyone using DeFi through managed vaults. Aave's contracts worked as designed; the loss came from a third-party vault's governance and permissioning layer built on top of Aave. "Using Aave inside a managed vault does not make the vault's own governance and authorization code part of Aave's security guarantees," ChainReport noted, comparing the case with the recent FlashLoopAdapter exploit, in which faulty module authentication exposed Safe wallets. Called It has covered related incidents, including the NEAR Intents exploit and the MetaMask Lido validator exit incident.
The vault reportedly still held about $31.7 million after the attack, according to public reporting cited by ChainReport, but that figure is not an additional confirmed loss. It does mean whoever controls the seven keys continues to control a significant position under the same permission structure. Bitcoin.com News said systemic risk appeared contained, though selling the stolen wstETH could put short-term pressure on its market price relative to ether.
What's next
Three questions remain. First, whether the vault's owner comes forward with a post-mortem explaining how the whitelist change was approved; none had been published in the reporting reviewed for this article, and no reimbursement plan has been announced. Second, where the roughly 1,001 wstETH routed through Lido's bridge ends up, given that on-chain trackers are watching it. Third, whether the remaining assets in the vault are secured or moved. Until the signers are identified, the Base vault multisig drain will remain a case study in how operational security, not code, can be the weakest point in DeFi.
This article is for information only and is not investment advice.