Base vault’s $6M exploit exposes a disclosure gap: Immunefi

A $6 million exploit at an unidentified Base vault has exposed a gap in vulnerability reporting, according to Immunefi’s head of security, with roughly $31.7 million remaining in the vault at the time of the incident briefing.

Gonçalo Magalhães, head of security at Immunefi, told crypto.news that the vault’s unidentified operators left a whitehat researcher with few options to address its whitelist weakness without risking legal trouble.

In the incident briefing accompanying his comments, the weakness had been identified the previous week, but the researcher had no clear disclosure channel. More than 24 hours after the attack, the briefing said no team had publicly claimed the vault, acknowledged the loss, or announced remediation.