Back to dashboard
Thursday, May 21, 2026 at 08:02 UTC

BaseLend

Deprecated multisig retained owner privileges.

Partial
Funds stolen
$18.60M
Recovered
$7.50M40%
Still outstanding
$11.10M
Chain
Base
Category
DeFi
Attack vector
Access Control
Reported by
CertiK
Incident ID
e17

Exploit & recovery timeline

  1. May 21, 2026 · 06:02 UTC
    Attack preparation

    Attacker wallets funded and staged ahead of the access control exploit against BaseLend.

  2. May 21, 2026 · 08:02 UTC
    Exploit executed

    $18.6M drained from BaseLend on Base via Access Control.

  3. May 21, 2026 · 09:02 UTC
    Detected by CertiK

    CertiK flagged the anomalous transactions and published an initial alert.

  4. May 21, 2026 · 12:02 UTC
    Protocol response

    BaseLend paused affected contracts or withdrawals and began tracing outbound flows.

  5. May 22, 2026 · 08:02 UTC
    Funds traced

    Stolen assets followed through mixers, bridges, and exchange deposit addresses.

  6. May 28, 2026 · 08:02 UTC
    Partial recovery

    $7.5M of $18.6M recovered (40%); the remainder is still unaccounted for.

  7. Jun 20, 2026 · 08:02 UTC
    Investigation continues

    Remaining funds monitored across chains with exchange partners notified.