An unidentified treasury has suffered a $60,000 multi-signature vulnerability attack, putting $317,000 at risk.
Security researchers have disclosed that an unidentified vault contract... An attacker exploited vulnerabilities in its whitelist and multisig control mechanisms, resulting in a loss of around $6 million for the blockchain. The incident was discovered on October 4, when blockchain security company Blockaid detected unusual withdrawals. Within about 40 minutes, the estimated loss soared from $20,200 to approximately $6 million.
According to data from GoPlus, PeckShield, CertiK, and Exvul, the attacker borrowed 1,783.067 aBaswstETH from the vault and exchanged these tokens for Aave receipts, receiving roughly 1,783 wstETH in return. aBaswstETH represents wrapped staked Ether supplied to the Aave Base market.
This attack was not caused by vulnerabilities in Aave's core lending contracts or the Base network. Investigators found that the theft was related to a failure in the vault’s multisig governance and access control mechanisms. A newly created contract was added to the vault’s borrowing whitelist via a Safe multisig transaction. Once whitelisted, this contract could borrow the vault’s Aave positions and redeem the underlying assets.
The vault’s operational owner was three Safe accounts created using Safe Proxy Factory 1.4.1. Seven signing addresses control these accounts, but their identities remain undisclosed. Investigators can trace on-chain transactions, but blockchain records alone cannot determine whether the whitelist update resulted from credential theft, social engineering, insider threat, or other governance failures.
Notably, in the 25 days leading up to the attack, the vault had not conducted any transactions, yet during the attack, two transactions were suddenly completed. This abrupt activity could indicate that signers' identities were compromised or that an insider approved the changes. So far, no security company has publicly confirmed which explanation is correct.
Unclaimed Ownership and Remaining Risk Exposure
The lack of known owners has complicated the response. No project team has publicly acknowledged the existence of this vault, nor have they announced a remediation plan or explained how the unauthorized whitelist addition was approved. The vault is an OpenZeppelin transparent proxy with separate upgrade permissions, which adds a layer of contract between asset holders and ultimate controllers.
Reportedly, roughly $317,000 in assets remained in the vault after the withdrawals. An unidentified on-chain user later sent a message to the attacker, encouraging them to extract the remaining funds and asking for a tip, but there has yet to be a publicly confirmed response.
At present, direct systemic risk appears limited, since Aave's Base deployment and its underlying blockchain were not affected. However, the event shows that risks from privileged management functions may outweigh those posed by the smart contracts they govern. If the identities of signers, transaction review procedures, and internal controls are weak, multisig approval alone does not guarantee security.
This incident has also raised concerns about wstETH liquidity. Dumping around 1,783 wstETH could exert short-term market pressure, though so far there is no indication of overall depegging risk for the receipt token. More details may emerge if the Safe signers, the vault's controlling organization, or the attacker reveal their identities publicly.

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Indonesian Rupiah: Limited relief, challenging backdrop – OCBC
Buying Wind in the Cryptocurrency Market! Significant Activity in Bitcoin, Ethereum, and Solana! Here are the Details…
Hulamin says Paul Baloyi resigns as independent non-executive director
Hulamin said independent non-executive director Paul Baloyi resigned, effective Oct. 2, 2026. Disclaimer: This news brief was created by Public Technologies (PUBT) using generative artificial intelligence. While PUBT strives to provide accurate and timely information, this AI-generated content is for informational purposes only and should not be interpreted as financial, investment, or legal advice. Hulamin Ltd. published the original content used to generate this news brief via SENS, the regulatory disclosure system operated by the Johannesburg Securities Exchange (JSE) (Ref. ID: S604350), on October 05, 2026, and is solely responsible for the information contained therein.
US Stock Move | Pneumococcal vaccine achieves late-stage clinical trial target, Vaxcyte (PCVX.US) opens more than 50% higher
On Monday, Vaxcyte (PCVX.US) soared more than 50% at the open and was up approximately 53% at the time of writing, with a market capitalization of 12.8 billions USD.
