Wasabi Protocol Loses $4.5 Million in Apparent Admin Key Breach

The decentralized finance sector continues to experience significant losses, with Wasabi Protocol being the latest victim. On Thursday, the platform, which offers perpetual trading on Ethereum and Base, was drained of around $4.55 million after its deployer key was compromised, according to security firm Blockaid. This incident follows a string of breaches this month, including the $285 million Drift Protocol hack, which also involved a compromised admin key. The Wasabi Protocol attack used a similar tactic, exploiting the lack of a timelock or multisig protection on the admin role, allowing the attacker to grant themselves admin privileges and drain funds without delay. The vulnerability was facilitated by the Universal Upgradeable Proxy Standard (UUPS), which, while convenient for developers, poses significant risks if an attacker gains admin access. Without a timelock to enforce a waiting period or a multisig system requiring multiple approvals, the single key held full control, leaving the protocol exposed. Blockaid identified the exploit, which involved the Wasabi: Deployer EOA granting admin rights to an attacker-controlled helper contract. This contract then upgraded Wasabi's perp vaults and Long Pool to malicious versions, resulting in the theft of funds. The affected contracts include various vaults on both Ethereum and Base. Users with Wasabi LP tokens were advised to revoke approvals to the vault contracts to mitigate further risk. This incident is part of a larger trend of DeFi losses, which have exceeded $770 million across over 30 incidents this year, with April being particularly notable for the frequency and scale of these breaches. Other platforms, such as Kelp DAO, CoW Swap, Grinex, Resolv Labs, and Volo Protocol, have also fallen victim to significant losses. A common thread among these incidents is the exploitation of known vulnerabilities, highlighting the need for improved security practices, including the implementation of timelocks and multisig systems to protect against single-point failures. Wasabi Protocol has yet to release a public statement regarding the incident.