Base Vault Breach Drains 1,783 WstETH Worth $6M After Approved Access
An attacker stole roughly 1,783 wrapped staked Ether, worth about $6 million, from an unidentified Base Vault on Oct. 4.
Key Takeaways
- An attacker stole roughly 1,783 wrapped staked Ether worth about $6 million from an unidentified Base Vault on Oct. 4
- Whitelist access controls became the entry point for the breach involving the Base Vault
- The attacker appears to have bypassed or acquired approval before withdrawing the wstETH
- No recovery has been confirmed, and the Base Vault’s operators have not issued a public statement identifying themselves
The breach hit an unidentified Base Vault running on Base, the Ethereum (ETH) layer-2 network incubated by Coinbase (COIN). Whitelist access controls, which restrict addresses that can use a vault’s privileged functions, became the entry point.
The wstETH token represents staked Ether wrapped into a tradable form, letting holders earn staking rewards while using the asset elsewhere in decentralized finance.
Losing whitelist status should block unapproved addresses from touching vault funds, but the attacker appears to have bypassed or acquired approval before withdrawing the wstETH.
Base Vault Exploit Highlights Access-control Risks
Base has grown into one of the largest layer-2 networks by activity since Coinbase launched it in 2023. Built on the Optimism (OP) stack, it lets the exchange settle transactions more cheaply than directly on Ethereum.
Also Read: AI Regulation Approved To Ban Solo AI Job Decisions In California
Its scale attracts legitimate DeFi deployments and attackers hunting for vault misconfigurations.
The $6 million theft is modest against the network’s total value locked but fits a pattern this year of mid-size L2 vault exploits targeting access-control logic rather than smart contract bugs.
The exploit comes less than two months after Blast, a rival layer-2 network, shut down entirely following a 98% collapse in assets from its $2 billion peak, underscoring uneven L2 vault security across the sector.
Whitelist-based attacks differ from flash-loan attacks or reentrancy bugs because they target permissioning layers, often the weakest link in otherwise audited code.
No recovery has been confirmed, and the Base Vault’s operators have not issued a public statement identifying themselves.
On-chain trackers will likely identify destination wallets within hours, a step that sometimes precedes negotiated returns in smaller DeFi incidents. Whether Base’s broader ecosystem faces contagion risk depends on how isolated the vault was from other protocols.
Read Next: Coinbase Ventures Backs A $90M Bet On Fixing Prediction Markets
