
Base vault's $6M exploit exposes disclosure gap: Immunefi
- —About $6 million in wstETH was drained from a Base vault via Aave V3
- —The attacker whitelisted a malicious contract through a Safe multisig
- —Roughly $31.7 million remained in the vault at the time of the briefing
- —Seven Safe signers remain unidentified with no public team response after 24 hours
Why it matters: The case highlights how collateral-free whitelists and anonymous vault operators expose user funds and leave whitehat researchers without a safe disclosure path.
Source: crypto.news