Newsroom
4 October, 2026 / News / AI / Tags: vault, wsteth, proxy, aave, signer

A vault on Coinbase’s Layer 2 network suffered a security breach that removed more than $6 million in wrapped staked ether from a multisignature setup whose seven signers remain unidentified
Security researchers first detected unusual activity in a vault held on Base at 09:21 UTC. Initial outflows exceeded $2 million before climbing past the $6 million mark within roughly 40 minutes. Investigators traced the movement of approximately 1,783 wstETH, with losses continuing to accumulate across multiple steps.
Blockaid and other onchain analysts flagged the event as the incident progressed. The vault transferred assets that had been borrowed from it and then exchanged through Aave. No core protocols on Base or Aave suffered compromise, and the chain itself remained untouched.
Security firms including PeckShield, Certik and Exvul converged on the same assessment. The attacker added a new contract to the vault’s whitelist, borrowed aBaswstETH tokens, moved them to an attacker-controlled address and redeemed them through Aave for wstETH. Six outflows occurred in total, with the precise authorization failure still under review. The attacker-controlled address identified in reports is 0x0B5126...B034.
The vault itself operated as an OpenZeppelin transparent proxy whose owner contract pointed to a 3-of-7 Safe created roughly 324 days earlier. The Safe required three signatures to execute transactions, yet none of its seven signer addresses has been publicly disclosed by investigators. A separate upgrade authority added another layer between the proxy and the ultimate controllers.
One source noted the attack involved four transactions before the latest updates, with the process still unfolding at the time of initial reporting. The specific weakness enabling the whitelist change and token movement has not been confirmed as a compromise of any particular wallet or Aave position.
Onchain records show the drained proxy address as 0xD1895f2019c2152FC2b9022D57f19198c4CFCABC, with its Safe owner at 0x6b27512a5943Ed327f6cb6C3EC1f0398229f42C4. Basescan and Arkham Intelligence link the latter to Safe Proxy Factory 1.4.1. Yet neither the vault nor the Safe carries a public protocol name, and no human operators have stepped forward.
The absence of a known owner has drawn attention. Security teams mapped the full token trail and the machinery behind the drain, but the identities behind the seven signer addresses remain unknown. The stolen wstETH trail continues, raising questions about future peg pressure on the asset.
At the time of the reports, no protocol had claimed the vault, and no confirmed account of a bug, key compromise or other cause had emerged. The incident appears contained, though the mystery of the multisignature control adds an unusual layer to the case.









