Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesStocksEarnInstitutionAI & More
An unidentified treasury has suffered a $60,000 multi-signature vulnerability attack, putting $317,000 at risk.

An unidentified treasury has suffered a $60,000 multi-signature vulnerability attack, putting $317,000 at risk.

MpostMpost2026/10/05 12:01
Show original
An unidentified treasury has suffered a $60,000 multi-signature vulnerability attack, putting $317,000 at risk. image 0

Security researchers have disclosed that an unidentified vault contract... An attacker exploited vulnerabilities in its whitelist and multisig control mechanisms, resulting in a loss of around $6 million for the blockchain. The incident was discovered on October 4, when blockchain security company Blockaid detected unusual withdrawals. Within about 40 minutes, the estimated loss soared from $20,200 to approximately $6 million.

According to data from GoPlus, PeckShield, CertiK, and Exvul, the attacker borrowed 1,783.067 aBaswstETH from the vault and exchanged these tokens for Aave receipts, receiving roughly 1,783 wstETH in return. aBaswstETH represents wrapped staked Ether supplied to the Aave Base market.

This attack was not caused by vulnerabilities in Aave's core lending contracts or the Base network. Investigators found that the theft was related to a failure in the vault’s multisig governance and access control mechanisms. A newly created contract was added to the vault’s borrowing whitelist via a Safe multisig transaction. Once whitelisted, this contract could borrow the vault’s Aave positions and redeem the underlying assets.

The vault’s operational owner was three Safe accounts created using Safe Proxy Factory 1.4.1. Seven signing addresses control these accounts, but their identities remain undisclosed. Investigators can trace on-chain transactions, but blockchain records alone cannot determine whether the whitelist update resulted from credential theft, social engineering, insider threat, or other governance failures.

Notably, in the 25 days leading up to the attack, the vault had not conducted any transactions, yet during the attack, two transactions were suddenly completed. This abrupt activity could indicate that signers' identities were compromised or that an insider approved the changes. So far, no security company has publicly confirmed which explanation is correct.

Unclaimed Ownership and Remaining Risk Exposure

The lack of known owners has complicated the response. No project team has publicly acknowledged the existence of this vault, nor have they announced a remediation plan or explained how the unauthorized whitelist addition was approved. The vault is an OpenZeppelin transparent proxy with separate upgrade permissions, which adds a layer of contract between asset holders and ultimate controllers.

Reportedly, roughly $317,000 in assets remained in the vault after the withdrawals. An unidentified on-chain user later sent a message to the attacker, encouraging them to extract the remaining funds and asking for a tip, but there has yet to be a publicly confirmed response.

At present, direct systemic risk appears limited, since Aave's Base deployment and its underlying blockchain were not affected. However, the event shows that risks from privileged management functions may outweigh those posed by the smart contracts they govern. If the identities of signers, transaction review procedures, and internal controls are weak, multisig approval alone does not guarantee security.

This incident has also raised concerns about wstETH liquidity. Dumping around 1,783 wstETH could exert short-term market pressure, though so far there is no indication of overall depegging risk for the receipt token. More details may emerge if the Safe signers, the vault's controlling organization, or the attacker reveal their identities publicly.

News Image 0
0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!

You may also like

US-India trade negotiations reach a stalemate, Indian Finance Minister: “The talks have reached a plateau,” with extremely limited room for concessions

Indian Finance Minister Nirmala Sitharaman stated on Monday that the negotiation process has been "tough and stringent", and both parties have now reached a "plateau", making it "extremely difficult" for either side to make further concessions or requests. However, she left room for flexibility, saying: "If there is still room for maneuver, both parties will pursue it." Last Friday, US Trade Representative Jamieson Greer said that the negotiations were in their "final stages", but emphasized that a final agreement was not "imminent".

华尔街见闻•2026/10/05 19:41

Raia Drogasil controlador stake slips R$ 11.23 million after September cash share sales

Raia Drogasil internal dealing filings for 09/2026 showed spot share sales by the majority shareholder, totaling 624,000 shares for R$ 12.63 million. Weighted average sale price for the majority shareholder’s spot trades was R$ 20.2389 per share. Executives also reported spot share sales of 50,000 shares for R$ 1,016,435 at a weighted average price of R$ 20.3287. Disclaimer: This news brief was created by Public Technologies (PUBT) using generative artificial intelligence. While PUBT strives to provide accurate and timely information, this AI-generated content is for informational purposes only and should not be interpreted as financial, investment, or legal advice. Raia Drogasil SA published the original content used to generate this news brief on October 05, 2026, and is solely responsible for the information contained therein.

Bitget•2026/10/05 19:40