Spheric News Blog Crypto Base vault’s $6M exploit exposes a disclosure gap: Immunefi
Crypto

Base vault’s $6M exploit exposes a disclosure gap: Immunefi



A $6 million exploit at an unidentified Base vault has exposed a gap in vulnerability reporting, according to Immunefi’s head of security, with roughly $31.7 million remaining in the vault at the time of the incident briefing.

Summary

  • About $6 million in wstETH was taken after a malicious contract gained access to the vault.
  • Seven Safe signers remained unidentified, with no public team response more than 24 hours later.
  • Immunefi’s security chief said approved addresses could take vault assets without putting up collateral.
  • Magalhães said a bug bounty could have caught the flaw, but anonymity complicated whitehat action.

Gonçalo Magalhães, head of security at Immunefi, told crypto.news that the vault’s unidentified operators left a whitehat researcher with few options to address its whitelist weakness without risking legal trouble.

In the incident briefing accompanying his comments, the weakness had been identified the previous week, but the researcher had no clear disclosure channel. More than 24 hours after the attack, the briefing said no team had publicly claimed the vault, acknowledged the loss, or announced remediation.

Base vault permissions allowed withdrawals without collateral

TokenPost reported that the attacker used a Safe multisignature wallet to add a malicious contract to the vault’s lending whitelist. According to its account, the contract then withdrew 1,783 aBaswstETH and redeemed the tokens through Aave V3 for about 1,783 wstETH.

Under Magalhães’ assessment, restricting access to approved addresses gave the appearance of protection because attackers would normally struggle to enter the whitelist. Once an address received approval, however, the vault allowed it to take assets without providing collateral, he said.

“But considering any whitelisted address could take the vault’s aBaswstETH with no collateral needed, it actually becomes a major vulnerability.”

The security chief described the whitelist itself as insufficient protection against that withdrawal capability. His explanation focused on what an approved address could do with the funds after gaining access, rather than simply whether access was restricted.

Before the exploit, the vault had gone 25 days without executing a Safe transaction, according to TokenPost. The publication mentioned social engineering and collusion as possible explanations for the access change, while stating that neither had been established.

With seven Safe signers still unidentified in the incident briefing, Magalhães called on the people controlling the wallet to identify themselves and respond. He said their continued silence warranted suspicion, without presenting that concern as proof of involvement in the theft.

An unnamed vault left the whitehat without clear protection

For the researcher who found the weakness, Magalhães said the lack of an identified operator complicated any attempt to intervene safely.

“Considering this is an unidentified vault, a whitehat can hardly perform any action with guarantee not to leave them in legal trouble.”

In his comments, the problem was not limited to finding a technical flaw. Magalhães also questioned the vault’s unknown ownership and the approval that allowed a threat actor onto its whitelist, saying both raised suspicions about its creators.

On Sep. 21, Immunefi CEO Mitchell Amador addressed private disclosure and authorization following the Liquid Network exploit. Amador said researchers should report weaknesses privately, preferably through a defined bounty program, rather than move user funds and negotiate payment afterward.

In that incident, unidentified actors returned 3,400 BTC but retained 598.5 BTC, according to the report. Blockstream rejected their claim of responsible disclosure and refused their demand for a 10% bounty.

Amador said protocols should establish rescue conditions before an emergency, including the actions a researcher may take and the reward terms. The report also described Immunefi’s Whitehat Safe Harbor framework as a way to set those conditions in advance.

Bug bounties could catch flaws that audits miss

Asked whether a bounty alone would necessarily have prevented the Base attack, Magalhães said the security community would probably have identified the contract’s withdrawal problem through a program.

“A bug bounty could definitely have stopped this attack, since it’s probable the security community would have found this flaring problem in the smart contract.”

In an Aug. 10 report on July’s bug bounty results, Immunefi said researchers received $2.32 million for confirmed vulnerabilities during the month. Confirmed and paid reports increased 18% from June, while the company said its programs prevented 374 threats.

The same report cited Immunefi’s comparison of 1,178 audits by tier-1 firms and 58 competitive audits. According to the company, competitions found an average of 6.2 serious vulnerabilities per engagement, compared with 1.5 in private audits.

Beyond contract logic, Magalhães pointed to infrastructure and key compromises as evidence that security checks must cover additional routes into user funds.

On July 20, a report on signer and infrastructure risks cited Hacken’s finding that those failures accounted for 88.3% of roughly $764 million stolen during the second quarter. Among 1,427 tracked projects, Hacken found that only 4% combined audits, active bug bounties and third-party monitoring.

Hacken also identified 14 exploited projects that had completed audits. According to its report, failures included signer devices, administrator keys, bridge validators, and backend systems outside the code covered by conventional reviews.

U.S. prosecutions show the stakes of unauthorized withdrawals

In the United States, the Justice Department has prosecuted a security engineer who exploited decentralized exchanges and negotiated over the return of stolen assets.

In December 2023, federal prosecutors announced that Shakeeb Ahmed had pleaded guilty to computer fraud after hacking two exchanges and obtaining more than $12 million. According to the department, Ahmed agreed to return funds to one exchange except for $1.5 million if it did not report the attack to law enforcement.

In the separate Nirvana Finance attack, prosecutors said the protocol offered Ahmed a bounty of up to $600,000 to return the stolen assets. He demanded $1.4 million instead, reached no agreement, and kept the approximately $3.6 million he had taken, according to the Justice Department.



Source link

Exit mobile version