Wasabi Protocol Loses $4.5 Million in Apparent Admin Key Breach
The DeFi space continues to hemorrhage funds, with Wasabi Protocol becoming the latest victim after being drained of approximately $4.55 million on Thursday. According to security firm Blockaid, the exploit occurred when attackers compromised the protocol's deployer key, leveraging a playbook similar to the one used in the $285 million Drift Protocol breach earlier this month. The breach was made possible by the lack of a timelock or multisig on the admin key, allowing the attackers to grant themselves admin privileges and drain the funds without delay. The attackers utilized an externally owned account called wasabideployer.eth, which held the sole ADMIN_ROLE in Wasabi's permission system, to carry out the exploit. They then upgraded Wasabi's perp vaults and Long Pool to malicious implementations, draining the balances. The exploit relied on the Universal Upgradeable Proxy Standard (UUPS), which enables smart contracts to change their underlying code while maintaining the same address. However, this standard also introduces a significant risk if an attacker gains control of admin permissions, as they can replace the contract's logic with malicious code designed to steal funds. The lack of a timelock or multisig protecting the admin role left Wasabi vulnerable to the attack, with a single key holding full control over the protocol. Blockaid's exploit detection system identified the ongoing admin-key compromise exploit, which involved the Wasabi: Deployer EOA granting ADMIN_ROLE to an attacker helper contract. The compromised contracts include Wasabi's wWETH, sUSDC, wBITCOIN, wPEPE, and Long Pool vaults on Ethereum, as well as its sUSDC, wWETH, sBTC, sVIRTUAL, sAERO, and sBRETT vaults on Base. Users holding Wasabi LP tokens were advised to revoke any active approvals to the vault contracts, as the underlying assets backing those tokens had either been drained or remained at risk. The incident is the latest in a series of DeFi breaches, which have resulted in cumulative losses exceeding $770 million across more than 30 reported incidents in 2026. The majority of these losses have occurred in April, with smaller breaches hitting CoW Swap, Grinex, Resolv Labs, and Volo Protocol, among others. A common thread among these incidents is the exploitation of known vulnerabilities, with each producing similar post-mortem language about lessons learned, but the next exploit usually arriving before the lessons get implemented.