Penzlyk.base.eth pfp
Penzlyk.base.eth

@penzlik

A Base vault lost 1,783 wstETH (~$6M) on Sunday and no team has claimed it. A new contract was whitelisted, about a minute later it borrowed the vault's Aave receipt tokens and redeemed them. Aave V3 and Base were not hacked. The weak layer is whoever edits the whitelist, reportedly a 3-of-7 Safe, approvals unexplained. Check who holds a vault's admin keys before depositing. Keys, social engineering or a signer saying yes?
0 reply
0 recast
1 reaction