Wasabi Protocol Loses $4.5 Million Due to Compromised Admin Key

The DeFi sector continues to experience significant losses, with Wasabi Protocol being the latest casualty, having lost approximately $4.55 million on Thursday after its deployer key was compromised, according to security firm Blockaid. This incident is the latest in a series of DeFi losses, which have exceeded $605 million across at least 12 incidents this month. The attack bears a striking resemblance to the Drift Protocol exploit, where a compromised admin key was used to drain $285 million from the Solana-based perpetuals exchange. The exploit was carried out through an externally owned account called wasabideployer.eth, which held the sole admin role in Wasabi's permission system. Once the attacker gained access to the deployer key, they granted themselves admin privileges and called grantRole on the permission contract, allowing them to upgrade Wasabi's perp vaults and Long Pool to malicious implementations that drained the balances. The exploit relied on the Universal Upgradeable Proxy Standard (UUPS), which enables smart contracts to change their underlying code while maintaining the same address. However, this standard can be exploited if an attacker gains control of admin permissions, allowing them to replace the contract's logic with malicious code designed to steal funds. Wasabi's lack of timelock or multisig protection for the admin role made it vulnerable to this type of attack. A timelock would have forced a delay between the announcement and execution of admin actions, giving users time to react, while a multisig would have required multiple signers to approve changes. The affected contracts include Wasabi's wWETH, sUSDC, wBITCOIN, wPEPE, and Long Pool vaults on Ethereum, as well as its sUSDC, wWETH, sBTC, sVIRTUAL, sAERO, and sBRETT vaults on Base. Users holding Wasabi LP tokens have been advised to revoke any active approvals to the vault contracts, as the underlying assets backing those tokens have either been drained or remain at risk. This incident is part of a larger trend of DeFi exploits, with the cumulative loss total for 2026 exceeding $770 million across over 30 reported incidents. The majority of these losses have occurred in April, with smaller breaches affecting CoW Swap, Grinex, Resolv Labs, and Volo Protocol, among others. Despite the repeated warnings and lessons learned from these incidents, the next exploit often occurs before the necessary measures are implemented. Wasabi has yet to issue a public statement regarding the incident.