Wasabi Protocol Loses $4.5 Million to Hackers Due to Admin Key Breach

The DeFi sector continues to suffer significant losses, with Wasabi Protocol being the latest victim, losing around $4.55 million to hackers who compromised its deployer key. According to security firm Blockaid, the attack occurred on Thursday and is similar to the Drift Protocol exploit earlier this month, where a compromised admin key was used to drain $285 million from the Solana-based perpetuals exchange. The Wasabi Protocol hack is the latest in a series of incidents that have resulted in over $605 million in DeFi losses across at least 12 incidents this month. The attackers used an externally owned account called wasabideployer.eth, which held the sole admin role in Wasabi's permission system, to gain control and drain the funds. The exploit relied on the Universal Upgradeable Proxy Standard, which allows smart contracts to change their underlying code without changing their address. However, this standard also allows attackers to replace the contract's logic with malicious code if they gain admin permissions. Wasabi Protocol lacked a timelock or multisig to protect the admin role, making it vulnerable to the attack. The affected contracts include Wasabi's wWETH, sUSDC, wBITCOIN, wPEPE, and Long Pool vaults on Ethereum, as well as its sUSDC, wWETH, sBTC, sVIRTUAL, sAERO, and sBRETT vaults on Base. Users holding Wasabi LP tokens have been urged to revoke any active approvals to the vault contracts to prevent further losses. This incident is part of a larger trend of DeFi exploits, with the cumulative loss total for 2026 exceeding $770 million across over 30 reported incidents. Other recent breaches include CoW Swap, Grinex, Resolv Labs, and Volo Protocol, highlighting the need for improved security measures in the DeFi sector.