Wasabi Protocol Loses $4.5 Million Due to Admin Key Breach

The DeFi sector continues to experience significant financial losses, with Wasabi Protocol being the latest victim. On Thursday, the platform, which is built on Ethereum and Base and offers perpetuals trading, was drained of about $4.55 million after its deployer key was compromised, according to security firm Blockaid. This incident is the latest in a series of security breaches that have resulted in over $605 million in DeFi losses across at least 12 incidents this month. The attack bears a striking resemblance to the Drift Protocol exploit that occurred on April 1, where North Korea-linked attackers used a compromised admin key to steal $285 million from the Solana-based perpetuals exchange. The perpetrator of the Wasabi Protocol hack utilized an externally owned account called wasabideployer.eth, which held the sole ADMIN_ROLE in Wasabi's permission system. This account, controlled by a private key, enabled the attacker to gain admin privileges and upgrade Wasabi's perp vaults and Long Pool to malicious implementations, resulting in the drainage of balances. The exploit relied on the Universal Upgradeable Proxy Standard (UUPS), which allows a smart contract to modify its underlying code while retaining the same address. Although UUPS is widely used for its convenience in fixing bugs without requiring user migration, it also poses a significant risk if an attacker gains control of admin permissions, as they can replace the contract's logic with malicious code designed to steal funds. Unfortunately, Wasabi had no timelock or multisig in place to protect the admin role, leaving a single key with full control over the protocol. As a result, users holding Wasabi LP tokens were advised to revoke any active approvals to the vault contracts, as the underlying assets backing those tokens were either drained or remained at risk. This incident is part of a larger trend of security breaches in the DeFi sector, with cumulative losses exceeding $770 million across over 30 reported incidents in 2026. Other notable breaches this month include CoW Swap, Grinex, Resolv Labs, and Volo Protocol. Despite the repeated warnings and lessons learned from these incidents, the sector continues to experience significant financial losses due to similar vulnerabilities.