Deprecated multisig retained owner privileges.
Attacker wallets funded and staged ahead of the access control exploit against BaseLend.
$18.6M drained from BaseLend on Base via Access Control.
CertiK flagged the anomalous transactions and published an initial alert.
BaseLend paused affected contracts or withdrawals and began tracing outbound flows.
Stolen assets followed through mixers, bridges, and exchange deposit addresses.
$7.5M of $18.6M recovered (40%); the remainder is still unaccounted for.
Remaining funds monitored across chains with exchange partners notified.