Invest1 publisher3 min readPublished
A newly whitelisted contract drained over $6 million in wstETH from a Base vault with seven unnamed signers
Security firms traced about 1,783 wstETH, worth more than $6 million, out of a Base vault on Oct. 4 whose owner is an anonymous 3-of-7 Safe. With Base and Aave's core contracts not blamed, the loss lands on a custody setup whose seven signers no one has publicly identified.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- A newly created contract was added to the vault's whitelist, borrowed Aave receipt tokens, moved them to an attacker-controlled contract and redeemed them for wstETH.
- The vault is an OpenZeppelin transparent proxy owned by a Safe that was created about 324 days before the drain.
- Security firms have not confirmed which authorization failed, and speculation about a compromised wallet remains unverified.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure With no protocol claiming the vault, it is unclear whether the loss falls on the seven signers or on outside depositors, and depositors have no named operator to ask for a post-mortem or repayment.
- constraint Until the whitelist failure is identified, other operators using Safe Proxy Factory 1.4.1 and standard OpenZeppelin proxies cannot rule a shared flaw in or out for their own vaults.
- cost If the 1,783 wstETH is sold, Bitcoin.com sees near-term pressure on wstETH's peg, a cost that lands on holders who had no stake in this vault.
- decision A 3-of-7 threshold only tells a depositor how many keys must sign; with 35 possible signing trios and no named signers, knowing who holds the keys becomes the diligence question.
Blockaid's tally stood at about $2.02 million at 09:21 UTC and passed $6 million roughly 40 minutes later [2]. Close to $4 million moved in those 40 minutes, about $100,000 a minute [1]. Exvul counted six outflows [6], so the average transfer was about 297 wstETH [2], or roughly $1 million [4]. The reported totals put wstETH at no less than about $3,365 a token [3].
Aave handled the exit. The draining contract borrowed 1,783.067 aBaswstETH, Aave's receipt token for wrapped staked ether deposited on Base, and redeemed it through Aave into about 1,783 wstETH [4]. Security firms have not said any core contracts were compromised, and Base itself was not hacked [7]. The step that went wrong came before Aave was involved: a newly created contract was added to the vault's own whitelist [5].
Who could edit that whitelist is where the public record stops. The vault is an OpenZeppelin transparent proxy owned by a Safe created about 324 days ago that needs three of seven signatures to act [9]. None of the seven signers has been identified, and no protocol has claimed the vault [8]. If the change went through that Safe, any of 35 different trios could have signed it [5]. Upgrade authority sits with a separate contract, a further layer between the vault and whoever ultimately controls it [10].
According to Bitcoin.com, investigators cannot yet tell whether the whitelist change came from stolen credentials, a white hacker, faulty permissions or another weakness [12]. Each answer puts the loss in a different place. Stolen signer keys make it a failure of key custody by people nobody can name. A white hacker leaves room for the 1,783 tokens to come back. A permission error in the vault's configuration is a bug in one operator's setup.
I think the evidence supports locating the risk in this vault's custody arrangement, or more precisely in the whitelist permission that arrangement was supposed to guard. The counter-case is specific. The Safe was deployed through Safe Proxy Factory 1.4.1, according to Basescan and Arkham Intelligence [11], and the vault sits on a standard OpenZeppelin proxy [9]. If a post-mortem traced the whitelist change to a flaw in either shared component, the exposure would reach every contract built the same way, and this view would be wrong. No one has published a confirmed account of a bug or a key compromise [14].
For anyone allocating money, the open question is whose wstETH this was. With no owner come forward, it is not known whether the tokens belonged to the signers themselves or to depositors who trusted them [8]. The wider market cost may come from the sale. Bitcoin.com reported that the risk to the broader system looks limited for now, but that selling the stolen wstETH could weigh on its peg in the short term [13].
What to watch
- A post-mortem showing whether the whitelist change came from stolen signer keys, a permission error in the vault, or a flaw in Safe Proxy Factory 1.4.1 or the OpenZeppelin proxy.
- Any team claiming the vault or identifying the seven signer addresses behind the 3-of-7 Safe.
- Whether the roughly 1,783 wstETH is sold on the market or returned, and how wstETH's peg behaves if it is sold.