Base DeFi Vault Drained for $6M via Whitelist Flaw
- DeFi
- Security

An unidentified DeFi vault on Base lost $6M on October 4 when an access control bug in the whitelist allowed an attacker to drain funds. The exploit highlighted simple permission failures rather than complex smart contract logic. CT noted the incident as another reminder that basic security oversights continue to cost users millions.
Incident Details
- Type
- PROTOCOL EXPLOIT
- Funds Lost
- $6M
- Status
- Total loss
Funds taken with no immediate recovery reported