Wasabi Protocol Loses $4.5 Million Due to Apparent Admin Key Breach
The DeFi space continues to suffer significant losses, with Wasabi Protocol being the latest victim. On Thursday, the platform, which is built on Ethereum and Base and specializes in perpetuals trading, was drained of around $4.55 million after an attacker compromised its deployer key, as reported by security firm Blockaid. This incident follows a string of breaches this month, totaling over $605 million in losses across at least 12 incidents, including the Drift Protocol exploit on April 1, where North Korea-linked attackers used a compromised admin key to steal $285 million from the Solana-based perpetuals exchange. The attack on Wasabi Protocol was executed through an externally owned account called wasabideployer.eth, which held the sole admin role in the platform's permission system. Once the attacker gained access to the deployer key, they quickly assigned themselves admin privileges and upgraded Wasabi's perp vaults and Long Pool to malicious implementations, resulting in the draining of user balances. The exploit utilized the Universal Upgradeable Proxy Standard (UUPS), a widely used standard that allows smart contracts to change their underlying code without altering their address. However, this standard also poses a significant risk if an attacker gains control of admin permissions, as they can replace the contract's logic with malicious code designed to steal funds. According to Blockaid, Wasabi Protocol lacked a timelock or multisig to protect the admin role, leaving a single key with full control over the platform. This vulnerability allowed the attacker to execute the exploit without any delay or need for multiple approvals. The incident highlights the ongoing issue of DeFi platforms being repeatedly exploited due to similar vulnerabilities, with the cumulative loss for 2026 exceeding $770 million across over 30 reported incidents. Other notable breaches this month include CoW Swap, Grinex, Resolv Labs, and Volo Protocol, among others. Despite the repeated warnings and lessons learned from these incidents, the next exploit often occurs before any meaningful changes are implemented to prevent such attacks.