—
00:00
Money for You
Money for You
USD/RUB—
EUR/RUB—
Cryptocurrency

Base Vault Exploit Reveals Dangerous Disclosure Gap

An unidentified vault on the Base network lost $6 million in wstETH after a malicious contract bypassed security, exposing a critical failure in vulnerability reporting. With the vault’s operators remaining silent and anonymous, security researchers are left without a clear path to disclose flaws or intervene without facing potential legal consequences.

Base Vault Exploit Reveals Dangerous Disclosure Gap

The exploit occurred after an attacker utilized a Safe multisignature wallet to inject a malicious contract into the vault’s lending whitelist. According to Gonçalo Magalhães, head of security at Immunefi, the vault’s architecture created a false sense of security; while access was restricted to approved addresses, those addresses were granted the power to drain assets without providing any collateral. Once the malicious contract gained whitelist status, it successfully withdrew 1,783 aBaswstETH.

More than 24 hours after the incident, no team has claimed ownership of the vault or acknowledged the loss. This anonymity poses a significant barrier for whitehat hackers, who risk legal repercussions if they attempt to secure funds without a pre-established disclosure channel or bounty program. Magalhães noted that a formal bug bounty would likely have surfaced the flaw before it could be exploited, yet the lack of a recognizable entity to engage with paralyzed potential intervention. The incident highlights a growing trend where infrastructure and signer risks, rather than just smart contract logic, serve as the primary vectors for large-scale theft in the decentralized finance space.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!