Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesStocksEarnInstitutionAI & More
An unidentified treasury has suffered a $60,000 multi-signature vulnerability attack, putting $317,000 at risk.

An unidentified treasury has suffered a $60,000 multi-signature vulnerability attack, putting $317,000 at risk.

MpostMpost2026/10/05 12:01
Show original
An unidentified treasury has suffered a $60,000 multi-signature vulnerability attack, putting $317,000 at risk. image 0

Security researchers have disclosed that an unidentified vault contract... An attacker exploited vulnerabilities in its whitelist and multisig control mechanisms, resulting in a loss of around $6 million for the blockchain. The incident was discovered on October 4, when blockchain security company Blockaid detected unusual withdrawals. Within about 40 minutes, the estimated loss soared from $20,200 to approximately $6 million.

According to data from GoPlus, PeckShield, CertiK, and Exvul, the attacker borrowed 1,783.067 aBaswstETH from the vault and exchanged these tokens for Aave receipts, receiving roughly 1,783 wstETH in return. aBaswstETH represents wrapped staked Ether supplied to the Aave Base market.

This attack was not caused by vulnerabilities in Aave's core lending contracts or the Base network. Investigators found that the theft was related to a failure in the vault’s multisig governance and access control mechanisms. A newly created contract was added to the vault’s borrowing whitelist via a Safe multisig transaction. Once whitelisted, this contract could borrow the vault’s Aave positions and redeem the underlying assets.

The vault’s operational owner was three Safe accounts created using Safe Proxy Factory 1.4.1. Seven signing addresses control these accounts, but their identities remain undisclosed. Investigators can trace on-chain transactions, but blockchain records alone cannot determine whether the whitelist update resulted from credential theft, social engineering, insider threat, or other governance failures.

Notably, in the 25 days leading up to the attack, the vault had not conducted any transactions, yet during the attack, two transactions were suddenly completed. This abrupt activity could indicate that signers' identities were compromised or that an insider approved the changes. So far, no security company has publicly confirmed which explanation is correct.

Unclaimed Ownership and Remaining Risk Exposure

The lack of known owners has complicated the response. No project team has publicly acknowledged the existence of this vault, nor have they announced a remediation plan or explained how the unauthorized whitelist addition was approved. The vault is an OpenZeppelin transparent proxy with separate upgrade permissions, which adds a layer of contract between asset holders and ultimate controllers.

Reportedly, roughly $317,000 in assets remained in the vault after the withdrawals. An unidentified on-chain user later sent a message to the attacker, encouraging them to extract the remaining funds and asking for a tip, but there has yet to be a publicly confirmed response.

At present, direct systemic risk appears limited, since Aave's Base deployment and its underlying blockchain were not affected. However, the event shows that risks from privileged management functions may outweigh those posed by the smart contracts they govern. If the identities of signers, transaction review procedures, and internal controls are weak, multisig approval alone does not guarantee security.

This incident has also raised concerns about wstETH liquidity. Dumping around 1,783 wstETH could exert short-term market pressure, though so far there is no indication of overall depegging risk for the receipt token. More details may emerge if the Safe signers, the vault's controlling organization, or the attacker reveal their identities publicly.

News Image 0
0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!

You may also like

Chevron names Jeff Gustavson CFO in senior leadership reshuffle

Chevron set senior leadership changes effective Jan. 1, 2027, reshaping strategy, finance, Oil, Products & Gas, New Energies. Mark Nelson shifts from executive vice president of Oil, Products & Gas to lead Strategy and Business Development. Eimear Bonner moves from chief financial officer to president, Oil, Products & Gas. Jeff Gustavson becomes chief financial officer, moving from president of New Energies. Brent Gros takes over New Energies, moving from president of Offshore, adding oversight of Chevron’s AI strategy. Disclaimer: This news brief was created by Public Technologies (PUBT) using generative artificial intelligence. While PUBT strives to provide accurate and timely information, this AI-generated content is for informational purposes only and should not be interpreted as financial, investment, or legal advice. Chevron Corporation published the original content used to generate this news brief via Business Wire (Ref. ID: 20261005366851) on October 05, 2026, and is solely responsible for the information contained therein.

Bitget•2026/10/05 13:06

BUZZ-TeraWulf doubles power capacity at Kentucky data center campus; stock price rises

October 5 - ** Data center developer TeraWulf (WULF.O) saw its shares rise 3.2% to $16 in pre-market trading ** TeraWulf signed a revised agreement with Kentucky Power, a subsidiary of American Electric Power (AEP.O), to increase the contracted power capacity at its Muskie Data Campus in eastern Kentucky from 500 megawatts to 1 gigawatt ** The agreement advances the planned delivery timeline for the campus' second phase, a 500-megawatt project, from 2030 to 2029, subject to approval by the Kentucky Public Utilities Commission and depending on Kentucky Power's construction schedule ** The agreement is expected to provide $100 million in winter electricity bill credits for Kentucky Power’s residential customers, funded by TeraWulf, over the first 10 years of the contract ** As of the last close, the company’s share price had risen 34.8% so far this year.

路透社•2026/10/05 12:51