Wasabi Protocol Loses $4.5 Million to Hackers Due to Admin Key Breach

The decentralized finance sector continues to experience significant losses, with Wasabi Protocol being the latest victim of a major hack. On Thursday, the platform, which operates on Ethereum and Base, was drained of approximately $4.55 million after attackers gained access to its deployer key, according to security firm Blockaid. This incident is the latest in a series of breaches that have resulted in over $605 million in losses across 12 incidents in the past month. The attack bears similarities to the Drift Protocol exploit, which occurred on April 1 and saw North Korea-linked attackers use a compromised admin key to steal $285 million from the Solana-based perpetuals exchange. The hack was made possible due to the lack of a timelock or multisig, allowing the attackers to gain admin privileges and drain the funds. The attackers used an externally owned account called wasabideployer.eth, which held the sole admin role in Wasabi's permission system, to grant themselves admin privileges and upgrade the perp vaults and Long Pool to malicious implementations. The exploit relied on the Universal Upgradeable Proxy Standard, which allows smart contracts to change their underlying code while maintaining the same address. However, this standard also poses a risk if an attacker gains control of admin permissions, as they can replace the contract's logic with malicious code. In this case, the attackers were able to drain the balances due to the lack of protective measures. Blockaid's exploit detection system identified the ongoing admin-key compromise exploit, which resulted in the compromise of several contracts, including Wasabi's wWETH, sUSDC, wBITCOIN, wPEPE, and Long Pool vaults on Ethereum, as well as its sUSDC, wWETH, sBTC, sVIRTUAL, sAERO, and sBRETT vaults on Base. Users holding Wasabi LP tokens were advised to revoke any active approvals to the vault contracts to prevent further losses. The incident highlights the need for robust security measures, including timelocks and multisig, to prevent such breaches. The cumulative DeFi loss total for 2026 has now exceeded $770 million, with April accounting for the majority of the losses. Other notable breaches this month include CoW Swap, Grinex, Resolv Labs, and Volo Protocol, among others. Despite the repeated warnings and lessons learned, the next exploit often occurs before the necessary measures are implemented. Wasabi Protocol has yet to issue a public statement on the incident.