Wasabi Protocol Loses $4.5 Million Due to Admin Key Compromise

The DeFi sector continues to experience significant losses, with Wasabi Protocol being the latest victim. On Thursday, the platform, which operates on Ethereum and Base, was drained of around $4.55 million after attackers gained access to its deployer key, as reported by security firm Blockaid. This incident is part of a larger trend, with over $605 million lost in DeFi across at least 12 incidents this month. The mechanics of the attack involved an externally owned account called wasabideployer.eth, which held the sole admin role in Wasabi's permission system. Once the attackers obtained the deployer key, they granted themselves admin privileges and upgraded Wasabi's perp vaults and Long Pool to malicious implementations, draining the balances. The exploit utilized the Universal Upgradeable Proxy Standard (UUPS), which allows a smart contract to change its underlying code without changing its address. However, this standard also poses a risk if an attacker gains admin permissions, as they can replace the contract's logic with malicious code. Wasabi's lack of a timelock or multisig to protect the admin role made it vulnerable to this type of attack. The incident has resulted in compromised contracts, including Wasabi's wWETH, sUSDC, wBITCOIN, wPEPE, and Long Pool vaults on Ethereum, as well as its sUSDC, wWETH, sBTC, sVIRTUAL, sAERO, and sBRETT vaults on Base. Users holding Wasabi LP tokens have been advised to revoke any active approvals to the vault contracts due to the risk of drained or compromised assets. This incident is part of a larger pattern of DeFi losses, with over $770 million lost across more than 30 reported incidents in 2026. The majority of these losses have occurred in April, with smaller breaches affecting CoW Swap, Grinex, Resolv Labs, and Volo Protocol, among others. A common thread among these incidents is the lack of implementation of lessons learned from previous exploits, leaving the DeFi sector vulnerable to continued losses.