BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

Over $6M Reportedly Stolen From Base Multisig Vault

More than $6 million was reportedly stolen from an anonymous multisignature vault operating on Base, Coinbase's Ethereum layer-2 network, according to unconfirmed reports circulating as of Oc

AnonymousCryptoCompass newsroom
October 4, 2026
5 min read
NEWS
Over $6M Reportedly Stolen From Base Multisig Vault
CryptoCompass editorial visual for altcoins coverage.

More than $6 million was reportedly stolen from an anonymous multisignature vault operating on Base, Coinbase's Ethereum layer-2 network, according to unconfirmed reports circulating as of October 4, 2026. No transaction hash, attacker identity, or on-chain evidence has been independently verified at the time of publication, and the claim has not been attributed to a named security firm, protocol team, or blockchain forensics provider.

What the Reports Describe, and What They Do Not

The reported incident involves a multisignature vault holding in excess of $6 million, described as anonymous in that no publicly identified team, protocol, or individual has been linked to the address. The vault is said to have been deployed on Base, the Ethereum-compatible rollup developed by Coinbase, which has attracted significant DeFi activity since its August 2023 launch, as tracked by DeFiLlama's Base chain dashboard. For related coverage, see Revolut Data Leak: Personal Information Reportedly Exposed.

Crucially, the available reporting does not specify the assets held, the exploit path used, how many signers controlled the vault, which signers may have been compromised, or whether any funds have been frozen or recovered. The loss figure of more than $6 million should be treated as approximate pending on-chain confirmation, as exact amounts frequently shift as blockchain investigators trace related addresses. This mirrors the uncertainty seen in the Drift Protocol hack, where $285 million in reported losses required extensive forensic work before figures stabilized. For related coverage, see Solana Tokenized Stock Trading Hits Record $4.4B.

Why Multisig Vaults Reduce, But Do Not Eliminate, Theft Risk

Multisignature authorization requires multiple private keys to approve a transaction, distributing control so that no single compromised key can drain a wallet unilaterally. A 2-of-3 configuration, for example, demands that two of three designated signers approve any outgoing transfer before it executes on-chain.

Despite that design, multisig vaults remain vulnerable to social engineering, compromised signer devices, malicious contract upgrades, and flawed front-end interfaces that present fraudulent signing prompts. A theft of this reported scale would suggest that either multiple signers were simultaneously compromised, the vault's contract logic contained an exploitable flaw, or signers were deceived into authorizing a malicious transaction, though none of these vectors has been confirmed in the available reporting.

Similar incidents have demonstrated that multisig protections are only as strong as the operational security of each individual signer. When Humanity Protocol attackers converted stolen funds to USDC and deposited to KuCoin, the breach also bypassed controls designed to distribute risk across multiple parties.

What Remains Unverified and What to Watch

Several core facts remain open as of publication. No block explorer entry on Basescan has been publicly identified that corresponds to the reported drain, meaning the $6 million figure cannot yet be verified against an on-chain timestamp, sender address, or token breakdown. Without a transaction hash or vault address, independent researchers cannot confirm the amount, the authorization method used, or whether any funds remain in related wallets.

The identity of the vault's owners also remains unknown. An anonymous vault by definition has no publicly associated team, making notification, recovery coordination, and attribution significantly harder than in incidents involving named protocols. Readers should note that unnamed reports in the absence of a clearly attributed source, a named security firm, or an on-chain explorer link should be weighted accordingly.

Investigators and security researchers tracking the Base ecosystem will likely focus on whether any known multisig factory contracts, such as Safe (formerly Gnosis Safe), show anomalous activity around the reported date, and whether the drained assets have been routed through cross-chain bridges or decentralized exchanges. Prior incidents have shown that stolen funds move quickly; in the Bitget hack, attackers swapped more than $351 million in stolen ETH for BTC via THORChain within hours of the initial breach.

The next concrete milestones to watch are an on-chain address disclosure from a security firm such as Chainalysis, PeckShield, or Cyvers; a statement from any protocol or individual claiming the vault; and any exchange-level freeze requests that would indicate the stolen assets have been identified at a centralized venue. Until those data points surface, the reported $6 million figure and the theft claim itself remain unconfirmed. Coincu will update this article as verified on-chain evidence becomes available.

FAQ: Reported $6 Million Base Multisignature Vault Theft

What was reportedly stolen?

More than $6 million in unspecified assets held inside an anonymous multisignature vault on Base, according to unconfirmed reports. The exact token composition has not been disclosed.

Where was the vault located?

On Base, the Ethereum layer-2 network operated by Coinbase.

Has the theft been independently verified?

No. As of publication, no transaction hash, named security firm, protocol statement, or block explorer entry has been publicly linked to the reported incident.

What is a multisignature vault?

A smart contract wallet that requires approval from multiple private keys before any funds can move, intended to prevent single-point-of-failure theft.

Are specific users or protocols confirmed as affected?

No. The vault is described as anonymous, and no protocol, team, or individual has been named in connection with the reported loss.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

The post Over $6M Reportedly Stolen From Base Multisig Vault was initially published on Coincu.