Key Takeaways
- Blockaid and several onchain investigators flagged the Base vault Oct. 4 as losses climbed beyond $6 million.
- Aave converted 1,783 aBaswstETH into wstETH, but its core contracts aren’t blamed.
- Base records point to a 3-of-7 Safe whose owners still haven’t been identified.
The $6 Million Vault Nobody Has Claimed
At 09:21 UTC on Oct. 4, Blockaid spotted what looked like an exploit unfolding on a vault held on Base, Coinbase’s Ethereum layer two (L2) protocol. At that time, about $2.02 million was already gone. Roughly 40 minutes later, the loss had blown past $6 million, with security firms tracing about 1,783 wstETH out of a vault.
Then came the stranger part. No protocol claimed the vault. Its apparent controller is a 3-of-7 Safe whose seven signers remain unidentified, leaving a multimillion-dollar crime scene without a publicly known owner.
Six Outflows, One Freshly Whitelisted Contract
Peckshield, Certik and Exvul converged on roughly the same tally. The security firms said 1,783.067 aBaswstETH was borrowed from the vault and redeemed through Aave on Base into about 1,783 wstETH.
In plain English, the tokens initially taken were Aave receipt tokens representing wrapped staked ether deposited on the L2 Base. A newly created contract was added to the vault’s whitelist, borrowed those receipt tokens, moved them to an attacker-controlled contract and redeemed them through Aave for the underlying wstETH.
Exvul counted six outflows. The precise authorization failure, however, remains unconfirmed. Security firms haven’t said that any core contracts were compromised, and this wasn’t a hack of Base chain itself. Speculation about a compromised wallet or a particular Aave position remains just that.
A Seven-Signer Safe With No Name
Onchain records make the mystery harder to ignore. The drained vault is an Openzeppelin transparent proxy whose owner points to a Safe created about 324 days ago. That Safe requires three of seven signatures to act, but it carries no public protocol name, and none of its seven signer addresses has been publicly identified by the security firms tracking the incident.
Upgrade authority is separate, adding another layer of contracts between the vault and whoever ultimately controls it. For now, the operating owner visible onchain is the anonymous 3-of-7 Safe. The drained proxy is 0xD1895f2019c2152FC2b9022D57f19198c4CFCABC, while its Safe owner is 0x6b27512a5943Ed327f6cb6C3EC1f0398229f42C4. Basescan and Arkham Intelligence identify the latter as a Safeproxy created through Safe Proxy Factory 1.4.1.
That distinction matters for understanding what investigators actually know. They can see the vault, its owner contract, the seven signing addresses and the token trail. What they can’t see is the human organization behind those addresses, or whether the whitelist change came from stolen credentials, a white hacker, faulty permissions or another unknown weakness. No public team has stepped forward to fill in the blank.
Systemic risk appears contained for now, though unloading the stolen wstETH could put near-term pressure on its peg. What remains is a curious tableau, with roughly $6 million gone, onchain investigators able to trace the machinery behind the drain, and seven signer addresses sitting in plain sight. Yet the people controlling those addresses remain conspicuously absent from the story.
This story is still developing. No protocol has claimed the vault, and no one has published a confirmed account of a bug or key compromise. More details will be added as new information emerges.


