Adapter Vault Drain Hack

Reported loss $6.0M
Access Control

What happened

On October 4, 2026, an unnamed Aave v3 adapter vault on Base was drained of 1,783.07 wstETH (~$6.0 million USD). The attacker withdrew the Aave interest-bearing tokens (aBaswstETH), redeemed them for wstETH, and initiated cross-chain bridging to Ethereum.

The incident occurred via admin key compromise or unauthorized privilege execution rather than a smart contract code bug in Base or Aave core protocol. The attacker seeded gas via Tornado Cash on Ethereum and bridged 0.05 ETH to Base address 0x0B51...B034. The attacker deployed an unverified contract (0xcdfe...569d).

Shortly after, the vault's governing 3-of-7 Safe multisig (0x6b27...) executed a transaction calling __setWhitelist__ to approve the attacker's contract. The whitelisted contract executed six consecutive pulls to drain 1,783.07 aBaswstETH from the adapter, redeemed the tokens for underlying wstETH on Aave v3, and transferred 1,001 wstETH into the native Base-to-Ethereum withdrawal queue while leaving 782.07 wstETH sitting on Base in address 0xC734...7f8D. An additional ~11,760 aWETH remaining in the adapter was left untouched.

Target Adapter Contract: 0xd1895f20…cfcabc

Owner Safe Address (3-of-7): 0x6b27512a…9f42C4

Attacker Deployer Address: 0x0B5126e1…EdB034

Attacker Whitelisted Contract: 0xcdfe9130…1f569d

Fund Destination Address: 0xC7344843…297f8D

Protocol details

Classification Yield Aggregator
Protocol Type Exploit/Access control

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.