Security· ★★★· bearish·

Base vault's $6M exploit exposes disclosure gap: Immunefi

  • —About $6 million in wstETH was drained from a Base vault via Aave V3
  • —The attacker whitelisted a malicious contract through a Safe multisig
  • —Roughly $31.7 million remained in the vault at the time of the briefing
  • —Seven Safe signers remain unidentified with no public team response after 24 hours
Why it matters: The case highlights how collateral-free whitelists and anonymous vault operators expose user funds and leave whitehat researchers without a safe disclosure path.
Source: crypto.news