Wasabi Protocol Suffers $4.5 Million Loss Due to Admin Key Breach
The DeFi space continues to experience significant losses, with Wasabi Protocol being the latest to fall victim to a major exploit. On Thursday, the platform, which operates on both Ethereum and Base, was drained of around $4.55 million after its deployer key was compromised, according to a report by security firm Blockaid. This incident follows a string of similar breaches, including the $285 million Drift Protocol hack, which also involved a compromised admin key. The attackers in the Wasabi Protocol incident utilized an externally owned account called wasabideployer.eth, which held the sole administrative role in the platform's permission system. By exploiting this key, the attackers were able to grant themselves admin privileges and upgrade the platform's perp vaults and Long Pool to malicious implementations, resulting in the theft of funds. The exploit relied on the Universal Upgradeable Proxy Standard (UUPS), which allows smart contracts to be modified without changing their address. However, this standard also poses a significant risk if an attacker gains control of admin permissions, as they can replace the contract's logic with malicious code. In this case, Wasabi Protocol lacked a timelock or multisig protection for its admin role, leaving a single key in control of the platform. The incident has resulted in the compromise of several contracts, including those for wWETH, sUSDC, wBITCOIN, and wPEPE on Ethereum, as well as sUSDC, wWETH, sBTC, sVIRTUAL, sAERO, and sBRETT on Base. Users holding Wasabi LP tokens have been advised to revoke any active approvals to the vault contracts to prevent further losses. This incident is the latest in a series of exploits that have resulted in significant losses for the DeFi space, with over $605 million lost in the past month alone. The cumulative loss for 2026 has now exceeded $770 million, with April accounting for the majority of this figure. Other recent breaches include those affecting CoW Swap, Grinex, Resolv Labs, and Volo Protocol. The common thread among these incidents is the exploitation of known vulnerabilities, highlighting the need for improved security measures to prevent such breaches in the future.