Wasabi Protocol Suffers $4.5 Million Loss Due to Admin Key Breach
The DeFi sector continues to experience significant losses, with Wasabi Protocol being the latest victim. On Thursday, the protocol, which operates as a perpetuals trading platform on Ethereum and Base, was drained of approximately $4.55 million after its deployer key was compromised, according to a report by security firm Blockaid. This incident is the latest in a series of DeFi losses totaling over $605 million across at least 12 incidents in the past month. The attack bears a striking resemblance to the Drift Protocol exploit, which occurred on April 1, where attackers used a compromised admin key to drain $285 million from the Solana-based perpetuals exchange. The breach was made possible by an externally owned account called wasabideployer.eth, which held the sole admin role in Wasabi's permission system. The attackers utilized this account to grant themselves admin privileges and then upgraded Wasabi's perp vaults and Long Pool to malicious implementations, resulting in the drainage of funds. The exploit leveraged the Universal Upgradeable Proxy Standard (UUPS), which allows smart contracts to change their underlying code without altering their address. Although UUPS is widely used for its convenience in fixing bugs without requiring user migration, it also poses a significant risk if an attacker gains control of admin permissions, as they can replace the contract's logic with malicious code designed to steal funds. According to Blockaid, Wasabi lacked a timelock or multisig to protect the admin role, leaving a single key with full control over the protocol. The absence of these security measures allowed the attackers to execute their plan without any delays or multiple signers required for approval. The compromised contracts include various vaults on both Ethereum and Base, and users holding Wasabi LP tokens have been advised to revoke any active approvals to the vault contracts to prevent further losses. This incident is part of a larger trend of DeFi exploits, with the cumulative loss for 2026 exceeding $770 million across more than 30 reported incidents. The majority of these losses have occurred in April, with smaller breaches affecting several other protocols, including CoW Swap, Grinex, Resolv Labs, and Volo Protocol. A common thread among these incidents is the exploitation of known vulnerabilities, highlighting the need for improved security measures to prevent such breaches in the future.