🚨 GoPlus Security Alert: On Base, a vault contract that no project team has publicly claimed was hit. 1,783.067 aBaswst | Hanami
🚨 GoPlus Security Alert: On Base, a vault contract that no project team has publicly claimed was hit. 1,783.067 aBaswstETH was taken out, then redeemed on Aave V3 for about 1,783 wstETH. Loss is roughly $6 million.
The vault holds a position on Aave V3 Base, sized in the tens of millions. Aave’s core lending contracts and Base itself were not attacked.
https://basescan.org/tx/0x03f02973736beb1a49bba22fa84430993ca1c100697ee1bcfc33ea8025d9e001
🔍 Root Cause:
multisig governance and access-control failure. The exploit contract (0xcdFE9130…) was added to the vault’s borrow allowlist through a Safe multisig. The Safe flow may have been socially engineered or phished, or this was insider collusion. The team had not executed any Safe transaction for 25 days. These two were executed suddenly.
Most concerning: about $31.7 million in assets is still sitting in the vault, at risk. Someone even sent the attacker an on-chain message pushing them to withdraw the rest and asking for a tip. Still zero response and zero announcement from the project team.
Attacked vault: 0xD1895f2019c2152FC2b9022D57f19198c4CFCABC
Attacker: 0x0B5126e1bc27C0de77e02e97945760A674EdB034
Related addresses: 0xcdFE91301356da873562EF513828a60dba1F569d 0xC73448432a05deeA5Ea18a07D3b5d9ccf6297f8D
Malicious authorization (Safe execution): https://basescan.org/tx/0xed265fc80e4abe42d72d6bfd1623c89dd2d12f544d53d4ca2c9c3d0fefbf2810
Attack transaction (first borrow, 1 aBaswstETH): https://basescan.org/tx/0x0ec75c3be1f55bb08a92421796675e051993cdb6cbc38d5e33cc2b7f6ef2f491
Attack transaction (Aave redemption, 1,783.067 wstETH): https://basescan.org/tx/0x557bfd0e8530fd3e089748ccaabaa7837877f7578b13a377008474f2e367ee8c