GoPlus: A vault contract on the Base chain was attacked, resulting in losses of approximately $6 million, with $31.7 million in assets still at risk.
October 5th, according to a disclosure by the GoPlus security team, an unclaimed treasury contract on the Base chain was attacked. The attacker added a malicious contract to the lending whitelist through a Safe multisig, withdrew 1,783 aBaswstETH, and redeemed approximately 1,783 wstETH on Aave V3, resulting in a loss of about $6 million.
It is reported that the attack stemmed from a failure in multisig governance and access control. The project team had not executed any Safe transactions for this treasury contract for 25 days before the attack, possibly due to a social engineering attack or internal collusion; the Aave core contracts and the Base chain itself were not affected. As of press time, approximately $31.7 million in assets remain at risk in the attacked treasury.