Wasabi Protocol Loses $4.5 Million Due to Admin Key Breach

The DeFi space continues to experience significant losses, with Wasabi Protocol being the latest victim, losing approximately $4.55 million on Thursday due to a compromised deployer key. According to security firm Blockaid, the attack was carried out using an externally owned account called wasabideployer.eth, which had sole admin privileges. The attackers upgraded the perp vaults and Long Pool to malicious implementations, draining the balances. This exploit bears resemblance to the Drift Protocol hack, where North Korea-linked attackers used a compromised admin key to drain $285 million from the Solana-based perpetuals exchange. The lack of timelock or multisig protection on Wasabi Protocol allowed the attackers to execute their plan without delay. The Universal Upgradeable Proxy Standard (UUPS) was used to replace the contract's logic with malicious code, enabling the attackers to steal funds. Blockaid's exploit detection system identified the ongoing admin-key compromise exploit, and users holding Wasabi LP tokens were advised to revoke active approvals to the vault contracts. This incident is part of a larger trend of DeFi losses, with over $605 million lost across at least 12 incidents in the past month, and a cumulative total of over $770 million in 2026. Other notable breaches this month include Kelp DAO, CoW Swap, Grinex, Resolv Labs, and Volo Protocol. The repeated use of similar tactics by attackers highlights the need for improved security measures, including timelocks and multisig protection, to prevent such incidents in the future.