Wasabi Protocol Suffers $4.5 Million Loss Due to Admin Key Breach
The DeFi sector continues to experience significant financial losses, with the Wasabi Protocol being the latest victim. On Thursday, the protocol, which operates as a perpetuals trading platform on Ethereum and Base, was drained of around $4.55 million after its deployer key was compromised, according to security firm Blockaid. This incident is the latest in a series of attacks that have resulted in over $605 million in losses across at least 12 incidents within the past month. The mechanics of the attack involved an externally owned account called wasabideployer.eth, which held the sole admin role in Wasabi's permission system. Once the attackers gained access to the deployer key, they granted themselves admin privileges without delay by calling grantRole on the permission contract. Subsequently, a helper contract was used to upgrade Wasabi's perp vaults and Long Pool to malicious implementations, resulting in the drainage of balances. The exploit relied on the Universal Upgradeable Proxy Standard, which allows smart contracts to change their underlying code while retaining the same address. However, this standard also poses a risk if an attacker gains control of admin permissions, as they can replace the contract's logic with malicious code designed to steal funds. In this case, Wasabi lacked a timelock or multisig to protect the admin role, leaving a single key in control of the protocol. The compromised contracts include various vaults on both Ethereum and Base, and users holding Wasabi LP tokens have been advised to revoke any active approvals to the vault contracts. This incident is part of a larger trend of exploits within the DeFi sector, with multiple incidents occurring in recent weeks, including the Drift Protocol breach, which resulted in a loss of $285 million. The cumulative loss for the DeFi sector in 2026 has now exceeded $770 million across over 30 reported incidents, with the majority of these losses occurring in April. The repeated nature of these incidents highlights the need for improved security measures, such as timelocks and multisig protocols, to prevent similar breaches in the future.