Wasabi Protocol Suffers $4.5 Million Loss Due to Admin Key Breach
The decentralized finance sector continues to experience significant losses, with Wasabi Protocol being the latest victim. On Thursday, the platform, which offers perpetuals trading on Ethereum and Base, was drained of around $4.55 million after its deployer key was compromised, according to security firm Blockaid. This incident is the latest in a series of DeFi losses, which have totaled over $605 million across at least 12 incidents this month. The attack bears a striking resemblance to the Drift Protocol exploit, which occurred on April 1 and resulted in the loss of $285 million. In the Wasabi Protocol breach, the attackers utilized an externally owned account called wasabideployer.eth, which held the sole admin role in the platform's permission system. By gaining access to the deployer key, the attackers were able to grant themselves admin privileges without any delay by calling grantRole on the permission contract. Subsequently, they upgraded Wasabi's perp vaults and Long Pool to malicious implementations, resulting in the draining of balances. The exploit leveraged the Universal Upgradeable Proxy Standard, which allows a smart contract to modify its underlying code while retaining the same address. Although this standard is widely used for its convenience in fixing bugs without requiring user migration, it also poses a significant risk if an attacker gains control of admin permissions. In the case of Wasabi Protocol, the lack of a timelock or multisig to protect the admin role proved to be a critical vulnerability. A timelock would have introduced a delay between the announcement and execution of admin actions, providing users with a window to respond. Similarly, a multisig would have required multiple signers to approve changes, thereby preventing a single key from holding absolute control over the protocol. The compromised contracts include Wasabi's wWETH, sUSDC, wBITCOIN, wPEPE, and Long Pool vaults on Ethereum, as well as its sUSDC, wWETH, sBTC, sVIRTUAL, sAERO, and sBRETT vaults on Base, according to Blockaid. Users holding Wasabi LP tokens have been advised to revoke any active approvals to the vault contracts, as the underlying assets backing those tokens have either been drained or remain at risk. This incident is part of a larger trend of DeFi exploits, which have resulted in cumulative losses exceeding $770 million across more than 30 reported incidents in 2026. The majority of these losses have occurred in April, with smaller breaches affecting CoW Swap, Grinex, Resolv Labs, and Volo Protocol, among others. A common thread among these incidents is the exploitation of known vulnerabilities, with each post-mortem analysis highlighting the importance of implementing lessons learned. However, the next exploit often occurs before these lessons can be fully implemented. Wasabi Protocol has yet to issue a public statement regarding the incident.