An unidentified vault on Base lost more than $6 million on October 4, 2026, after a recently whitelisted contract was used to drain Aave-linked assets in six withdrawals. The attacker siphoned aBaswstETH receipt tokens and redeemed them for wstETH, although preliminary reporting described the amount as 1,783,067 aBaswstETH while the stated loss value and prior onchain estimates align with roughly 1,783 wstETH. Investigators have not determined what authorization weakness enabled the borrowing activity. Onchain evidence previously showed the vault's unidentified 3-of-7 Safe removing and restoring the attacker contract's whitelist access within one minute. The incident appears confined to the vault's access controls, with no confirmed compromise of Aave's core contracts or the Base network.