Unclaimed Base treasury vault contract exploited, roughly $6 million lost
AI Market Summary
A Base-chain treasury Safe multisig was compromised, enabling an attacker to whitelist a malicious lending contract and drain 1,783 aBaswstETH, then redeem ~1,783 wstETH on Aave V3 for roughly $6M. While Aave core contracts and Base were not impacted, the incident highlights governance and access-control weaknesses around integrations and whitelists. With ~$31.7M reportedly still at risk in the treasury, near-term risk sentiment may weigh on DeFi protocols and related tokens.
Impact level
● Medium
Affected assets
AAVE/USDT-0.66%
AI Insight · AAVE/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
ChainCatcher reported that GoPlus' security team found a treasury vault contract on the Base chain, which had not been publicly claimed by the project team, was compromised. The attacker used a Safe multisig to add a malicious contract to the lending whitelist, then withdrew 1,783 aBaswstETH and redeemed about 1,783 wstETH on Aave V3, causing losses of around $6 million.
GoPlus said the incident was driven by weaknesses in multisig governance and access controls. The project team had not executed any Safe transactions involving the treasury contract for 25 days before the exploit, raising the possibility of social engineering or insider collusion. Aave's core contracts and the Base network were not affected. As of publication, roughly $31.7 million in assets remain at risk in the compromised treasury.