Immunefi Security Chief: A certain Base treasury suffered a vulnerability exploit of approximately 6 million USD
Immunefi Security Chief Gonçalo Magalhães stated that an unnamed Base treasury suffered a vulnerability exploit of approximately 6 million dollars, while there were still about 31.7 million dollars in assets within the treasury at the time of the incident.
According to the briefing, the attacker added a malicious contract to the treasury's lending whitelist through a Safe multi-signature wallet, subsequently withdrawing 1,783 aBaswstETH, which were then exchanged for approximately 1,783 wstETH via AaveV3. Gonçalo Magalhães pointed out that the whitelist's restricted addresses appeared secure, but approved addresses could withdraw assets without collateral, constituting a vulnerability; this whitelist weakness had been discovered the previous week, but researchers lacked a clear disclosure channel. More than 24 hours after the incident, no team has publicly claimed responsibility or disclosed remedial measures.






