Adapter Vault Drain Hack
What happened
On October 4, 2026, an unnamed Aave v3 adapter vault on Base was drained of 1,783.07 wstETH (~$6.0 million USD). The attacker withdrew the Aave interest-bearing tokens (aBaswstETH), redeemed them for wstETH, and initiated cross-chain bridging to Ethereum.
The incident occurred via admin key compromise or unauthorized privilege execution rather than a smart contract code bug in Base or Aave core protocol. The attacker seeded gas via Tornado Cash on Ethereum and bridged 0.05 ETH to Base address 0x0B51...B034. The attacker deployed an unverified contract (0xcdfe...569d).
Shortly after, the vault's governing 3-of-7 Safe multisig (0x6b27...) executed a transaction calling __setWhitelist__ to approve the attacker's contract. The whitelisted contract executed six consecutive pulls to drain 1,783.07 aBaswstETH from the adapter, redeemed the tokens for underlying wstETH on Aave v3, and transferred 1,001 wstETH into the native Base-to-Ethereum withdrawal queue while leaving 782.07 wstETH sitting on Base in address 0xC734...7f8D. An additional ~11,760 aWETH remaining in the adapter was left untouched.
Target Adapter Contract: 0xd1895f20…cfcabc
Owner Safe Address (3-of-7): 0x6b27512a…9f42C4
Attacker Deployer Address: 0x0B5126e1…EdB034
Attacker Whitelisted Contract: 0xcdfe9130…1f569d
Fund Destination Address: 0xC7344843…297f8D
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.