
A vault operating on Base has been hit by an exploit that drained approximately 1,783 wrapped staked Ether (wstETH), worth around $6 million, adding another security incident to Coinbase’s Ethereum layer-2 ecosystem.
Blockchain security firm PeckShield flagged an address beginning with 0x0B5126…B034 as having taken 1,783 wstETH on Oct. 4. A separate analysis attributed to Spot On Chain put the losses at approximately $6 million, sharply higher than an earlier estimate of roughly $2 million.
Blockaid, which detected the exploit while it was still unfolding, said a newly created contract was added to the vault’s whitelist before borrowing aBaswstETH and transferring the resulting aTokens to an attacker-controlled contract. The security firm initially estimated losses at $2.02 million across roughly four transactions before updating the figure to more than $6 million, warning that the attack was still ongoing at the time of its latest update.
Blockaid also identified three exploiter addresses and published an example exploit transaction on BaseScan, alongside the contract for the token it said was being abused.

However, the incident should not be characterized as a hack of Coinbase itself or the Base blockchain. Available evidence indicates that a vault deployed on Base was compromised.
Early analysis indicates that the attack centered on the vault’s whitelist mechanism.
According to Spot On Chain analysis cited by PANews, the attacker was able to add a new contract to the vault’s whitelist. They subsequently borrowed a BasstETH from the vault and transferred the assets to an attacker-controlled contract.
The attacker’s address was identified as 0x0B5126…B034.
The incident initially appeared considerably smaller. Early reports put losses at approximately $2.02 million across four transactions while the attack was still unfolding. The estimate later climbed to around $6 million as approximately 1,783 wstETH became involved.
Spot On Chain’s assessment, as reported by PANews, suggested that systemic risk remained limited. However, it warned that selling the stolen wstETH could temporarily place pressure on liquid staking token markets.
One point remains less certain: while reports confirm the assets were moved into attacker-controlled infrastructure, available evidence reviewed for this story does not yet establish that the entire $6 million was successfully bridged away from Base. This matters when assessing potential recovery options.
The latest incident comes barely five weeks after another major attack on a protocol operating on Base.
On Aug. 27, decentralized lending protocol Moonwell suffered an estimated $8.7 million exploit involving its MAMO Core Market.
That attack used a very different method. Security researchers said the attacker manipulated the collateral value of the relatively illiquid MAMO token before borrowing valuable assets against the artificially inflated collateral. Moonwell responded by effectively freezing new borrowing across its Base Core Markets while investigating the incident.
The two incidents highlight different vulnerabilities in DeFi infrastructure. Moonwell’s losses centered on collateral valuation and market manipulation, while preliminary analysis of Sunday’s vault exploit points toward access controls and contract whitelisting.
Neither, based on currently available evidence, indicates that Base’s underlying Layer 2 infrastructure itself was compromised.
The Base vault attack also follows a $3.87 million exploit of NEAR Intents just days earlier.
Between Sept. 30 and Oct. 1, an attacker drained roughly $3.87 million in USDT from a BNB Chain vault used by NEAR Intents. Bitquery found that the attacker first tested the system with small withdrawals before extracting funds through five larger withdrawals.
The stolen assets were then fragmented across dozens of wallets and moved through several routes. Bitquery found that around 76% had been converted into Bitcoin at some point during its investigation, while approximately $802,000 was sent to KuCoin deposit addresses.
NEAR Intents subsequently said the vulnerability had been patched and pledged to compensate affected users; later reports said the exploiter returned the stolen assets.
For Base, the latest $6 million loss therefore adds to a broader run of attacks targeting the applications built on major blockchain networks rather than necessarily compromising the chains themselves.
The immediate question now is whether the unidentified vault team can trace or recover the 1,783 wstETH and, more importantly, how an attacker obtained sufficient permissions to whitelist a malicious contract in the first place.
Check your email to confirm
We sent a confirmation link to . Confirm it to activate your Kyroo cashback — you can do this anytime.
You're in! Taking you to {partner} in ...