BlockBeats news, October 5th, according to a disclosure by the GoPlus security team, an unclaimed treasury contract on the Base chain was attacked. The attacker added a malicious contract to the lending whitelist via Safe multisig, withdrew 1,783 aBaswstETH, and redeemed approximately 1,783 wstETH on Aave V3, resulting in a loss of about $6 million.
It is reported that the attack stemmed from a failure in multisig governance and access control. The project team had not executed any Safe transactions on the treasury contract for 25 days prior to the attack, possibly due to a social engineering attack or internal collusion; the Aave core contracts and the Base chain itself were not affected. As of press time, approximately $31.7 million in assets within the attacked treasury remain at risk.

