Wasabi Protocol Loses $4.5 Million Due to Admin Key Breach

The DeFi sector continues to face significant losses, with Wasabi Protocol being the latest victim, losing approximately $4.55 million on Thursday after its deployer key was compromised, according to security firm Blockaid. This incident mirrors the Drift Protocol exploit, where attackers used a compromised admin key to drain $285 million from the Solana-based perpetuals exchange. The attack on Wasabi Protocol was carried out through an externally owned account called wasabideployer.eth, which held the sole ADMIN_ROLE in the protocol's permission system. Once the attacker gained access to the deployer key, they granted themselves admin privileges and upgraded Wasabi's perp vaults and Long Pool to malicious implementations, draining the balances. The exploit utilized the Universal Upgradeable Proxy Standard (UUPS), which allows a smart contract to change its underlying code while maintaining the same address. However, this standard also poses a risk if an attacker gains admin permissions, as they can replace the contract's logic with malicious code. Wasabi Protocol lacked a timelock or multisig to protect the admin role, leaving a single key in control of the protocol. The compromised contracts include Wasabi's wWETH, sUSDC, wBITCOIN, wPEPE, and Long Pool vaults on Ethereum, as well as its sUSDC, wWETH, sBTC, sVIRTUAL, sAERO, and sBRETT vaults on Base. Users holding Wasabi LP tokens were advised to revoke any active approvals to the vault contracts, as the underlying assets backing those tokens had been drained or remained at risk. This incident is part of a larger trend of DeFi losses, with over $605 million lost across at least 12 incidents in the past month. The cumulative DeFi loss total for 2026 has now surpassed $770 million, with April accounting for the majority of the figure.