Wasabi Protocol Loses $4.5 Million in Apparent Admin Key Breach

The DeFi sector continues to suffer significant losses, with Wasabi Protocol being the latest victim, losing approximately $4.55 million on Thursday due to a compromised deployer key, as reported by security firm Blockaid. This incident closely resembles the Drift Protocol exploit, where North Korea-linked attackers utilized a compromised admin key to drain $285 million from the Solana-based perpetuals exchange. The attack was made possible through an externally owned account called wasabideployer.eth, which held the sole admin role in Wasabi's permission system. Upon gaining access to the deployer key, the attackers granted themselves admin privileges and upgraded Wasabi's perp vaults and Long Pool to malicious implementations, resulting in the draining of balances. The exploit relied on the Universal Upgradeable Proxy Standard (UUPS), which allows a smart contract to change its underlying code while maintaining the same address. However, the lack of a timelock or multi-signature protection on the admin role left the protocol vulnerable to attack. Blockaid's exploit detection system identified the ongoing admin-key compromise exploit, and users holding Wasabi LP tokens were advised to revoke any active approvals to the vault contracts. This incident is part of a larger trend of DeFi losses, with over $605 million lost across at least 12 incidents in the past month, and a cumulative total of over $770 million lost in 2026.