- An attacker drained approximately $6 million, or 1,783 wstETH, from a vault deployed on the Base network on October 4, 2026
- On-chain data shows the exploit involved manipulation of a Safe multisig whitelist, which allowed the attacker to redirect the vault’s funds
- No team or protocol linked to the affected vault had issued an official statement at the time of writing, leaving key details about the vault’s operator unconfirmed
A vault deployed on the Base network lost approximately $6 million worth of wstETH, specifically 1,783 tokens, in an exploit that occurred on October 4, 2026, according to an on-chain transaction recorded at basescan.org.
The transaction data shows the attacker exploited a weakness in how the vault’s Safe multisig whitelist was configured, manipulating the list of addresses authorized to interact with the vault’s funds in order to redirect the wstETH holdings to an address under the attacker’s control. Safe, formerly known as Gnosis Safe, is among the most widely used multisig wallet infrastructure in DeFi, and whitelist-based access controls built on top of it are a common pattern for vaults and treasuries that want to restrict which addresses can trigger fund movements.
Whitelist manipulation exploits typically arise either from a flaw in the smart contract logic governing how addresses are added to or removed from the authorized list, or from a compromise of the signing keys needed to approve whitelist changes in the first place. Without an official statement from whichever team operates the affected vault, it remains unclear from public information alone which of these mechanisms, a contract-level vulnerability or a key compromise, allowed the attacker to tamper with the whitelist in this case.
wstETH, or wrapped staked ether, represents a liquid staking derivative that lets holders earn ethereum staking rewards while retaining a transferable token that can be used elsewhere in DeFi, including as collateral in lending protocols and vaults. Losses denominated in wstETH are economically equivalent to losing the underlying staked ether position, making this exploit comparable in severity to a direct ether-denominated hack of similar size.
The incident adds to a steady stream of DeFi exploits in 2026 targeting multisig and access-control infrastructure specifically, rather than purely targeting smart contract logic bugs in lending or trading protocols themselves. Security researchers have increasingly flagged whitelist and permission management systems as an underappreciated attack surface, since a single successful manipulation of an authorized address list can grant an attacker the same level of control over a vault’s funds that a legitimate, fully authorized signer would have, without needing to find a flaw anywhere else in the protocol’s code.
Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.
To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.












