Wasabi Protocol Suffers $4.5 Million Loss Due to Admin Key Breach
The DeFi sector continues to experience significant losses, with Wasabi Protocol being the latest victim, losing around $4.55 million due to a breach of its deployer key, as reported by security firm Blockaid. This incident follows a string of similar attacks, including the Drift Protocol breach, which resulted in a $285 million loss. The Wasabi Protocol hack was carried out by exploiting the deployer key, which had unrestricted access to the protocol's permission system, allowing the attackers to grant themselves admin privileges and drain the funds. The attack was facilitated by the Universal Upgradeable Proxy Standard (UUPS), which enables smart contracts to be modified without changing their address. However, this standard also poses a significant risk if an attacker gains control of the admin permissions, as they can replace the contract's logic with malicious code. The lack of a timelock or multisig protection on the admin role made it possible for the attackers to carry out the exploit without any delays or additional approvals. Blockaid's analysis revealed that the compromised contracts include various vaults on both Ethereum and Base, putting users' assets at risk. As a result, users are advised to revoke any active approvals to the vault contracts to prevent further losses. This incident is part of a larger trend of DeFi exploits, with over $605 million lost across at least 12 incidents in the past month alone. The cumulative loss for 2026 has now exceeded $770 million, with the majority of these losses occurring in April. The repeated nature of these exploits highlights the need for improved security measures, such as timelocks and multisig protections, to prevent such incidents in the future.