金色财经
金色财经|Oct 07, 2026 04:51
[Immunefi: A Base Vault Exploited for $6 Million, Exposing Disclosure Mechanism Gaps] According to a report by crypto.news on October 7, as cited by Jinse Finance, Immunefi's Head of Security, Gonçalo Magalhães, stated that an unnamed Base vault was exploited for approximately $6 million, exposing gaps in the vulnerability disclosure mechanism. At the time of the incident, the vault still held around $31.7 million in assets. According to the briefing, the attacker used a Safe multisig wallet to add a malicious contract to the vault's lending whitelist. The contract subsequently withdrew 1,783 aBaswstETH tokens, which were then swapped on AaveV3 for approximately 1,783 wstETH tokens. Magalhães pointed out that while whitelisting addresses may appear secure, any approved address can withdraw assets without collateral, constituting a significant vulnerability. This weakness in the whitelist was discovered a week prior, but researchers lacked a clear channel for disclosure. More than 24 hours after the incident, no team has publicly claimed responsibility or disclosed any remediation measures.
+5
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads