A roughly $6 million exploit at an unidentified vault on Base has highlighted what Immunefi describes as a disclosure gap for security researchers when project operators are unknown and unresponsive.
Gonçalo Magalhães, head of security at Immunefi, said the vault lost about 1,783 wstETH after a malicious contract was added to its lending whitelist and then withdrew assets without posting collateral. At the time of the incident briefing, around $31.7 million was still held in the vault, while no team had publicly claimed responsibility for operating it or announced a fix more than 24 hours after the attack.
How the exploit unfolded
According to an account cited from TokenPost, the attacker used a Safe multisignature wallet to add a malicious contract to the vault’s lending whitelist. That contract then withdrew 1,783 aBaswstETH and redeemed the position through Aave V3 for about 1,783 wstETH.
The source article said the vault had gone 25 days without a Safe transaction before the exploit. TokenPost mentioned social engineering and collusion as possible explanations for how the whitelist change happened, but said neither theory had been established.
Why Immunefi says the design was vulnerable
Magalhães said the vault’s controls appeared safer than they were because access was limited to approved addresses. In his assessment, that safeguard broke down once an address made it onto the whitelist, since a whitelisted address could remove the vault’s aBaswstETH without needing to provide collateral.
His criticism focused on the permissions granted after approval rather than on the existence of a whitelist alone. In that setup, he said, the whitelist did not meaningfully protect assets if a malicious address could be added.
Disclosure problems for whitehats
Magalhães told crypto.news that a researcher had identified the weakness in the previous week, but the project’s anonymity left no clear path for responsible disclosure. He said that without an identified operator, a whitehat had few safe options to act and could risk legal trouble by intervening directly.
Immunefi’s security chief argued that a bug bounty program might have helped catch the flaw before it was exploited. In this case, however, the absence of a known team complicated any attempt to report or mitigate the issue before funds were taken.
Unanswered questions around the operators
The incident briefing said that more than 24 hours after the exploit, no operator had publicly claimed the vault, acknowledged the loss, or outlined remediation steps. It also said seven Safe signers remained unidentified.
Magalhães called on the people controlling the wallet to identify themselves and respond. He said their silence was reason for suspicion, while stopping short of presenting that as evidence that the operators were involved in the theft.
What is confirmed next
Based on the information in the briefing, the confirmed immediate situation is that the exploit has already removed about $6 million in wstETH-equivalent assets and that approximately $31.7 million remained in the vault at the time of Magalhães’ comments.
The key unresolved points are who controls the vault, how the malicious contract was approved for the whitelist, and whether any remediation will be announced. As of the source report, no public response from the vault’s operators had been made.
Source: crypto.news