Blockaid reports $6M exploit on unnamed Base vault via whitelisted contract abuse.
Security & Exploits ·
Blockaid identified an ongoing exploit affecting a Base vault, with approximately $6M drained through exploitation of a whitelisted contract. The vault operator and specific whitelisted contract involved have not been publicly named.
The attack's mechanics relied on abuse of contract whitelisting—a common security practice where certain addresses are pre-approved to interact with vault funds or functions. By compromising or misusing a whitelisted contract, the attacker bypassed standard access controls and withdrew assets directly. Such exploits highlight the ongoing risk posed by overly permissive whitelist configurations and the importance of auditing contract interactions.
Key details remain unclear: the timeline of fund recovery efforts, whether the whitelisted contract was misconfigured or deliberately manipulated, and the broader exposure of similar vaults using comparable whitelist setups have not been disclosed. The status of ongoing investigation and any user compensation are also unknown.