Wasabi Protocol Suffers $4.5 Million Loss Due to Admin Key Breach

The DeFi sector continues to experience significant losses, with Wasabi Protocol being the latest victim. The platform, which operates as a perpetuals trading platform on Ethereum and Base, was breached on Thursday, resulting in the theft of around $4.55 million. According to security firm Blockaid, the attackers compromised the deployer key, which had unrestricted access to the platform's permission system. This allowed the attackers to grant themselves admin privileges and upgrade the platform's perp vaults and Long Pool to malicious implementations, resulting in the drainage of funds. The breach bears similarities to the Drift Protocol exploit earlier this month, where attackers used a compromised admin key to steal $285 million. The lack of a timelock or multisig on the admin role at Wasabi Protocol made it vulnerable to such an attack. The Universal Upgradeable Proxy Standard (UUPS) used by the platform also played a role in the breach, as it allows smart contracts to change their underlying code without changing their address. However, this standard can be exploited by attackers if they gain admin permissions. The breach has resulted in the compromise of several contracts, including those for wWETH, sUSDC, wBITCOIN, and wPEPE on Ethereum, as well as sUSDC, wWETH, sBTC, and others on Base. Users holding Wasabi LP tokens have been advised to revoke any active approvals to the vault contracts to prevent further losses. This incident is the latest in a series of DeFi breaches, which have resulted in cumulative losses of over $770 million in 2026. The frequency and severity of these breaches highlight the need for DeFi platforms to implement robust security measures to protect user funds.