Wasabi Protocol Loses $4.5 Million Due to Admin Key Breach
The DeFi sector continues to suffer significant losses, with Wasabi Protocol being the latest victim, losing approximately $4.55 million on Thursday after its deployer key was compromised, according to security firm Blockaid. This breach bears a striking resemblance to the $285 million Drift Protocol exploit earlier this month, where attackers utilized a compromised admin key to drain funds from the Solana-based perpetuals exchange. The Wasabi Protocol hack, which occurred on both Ethereum and Base, was made possible by the attackers gaining access to the deployer key, which held the sole admin role in the permission system. Without a timelock or multisig in place to protect the admin role, the attackers were able to grant themselves admin privileges and upgrade the perp vaults and Long Pool to malicious implementations, resulting in the draining of balances. The exploit relied on the Universal Upgradeable Proxy Standard (UUPS), which allows smart contracts to change their underlying code while maintaining the same address. However, this standard also poses a significant risk if an attacker gains control of admin permissions, as they can replace the contract's logic with malicious code designed to steal funds. The lack of security measures, such as timelocks or multisig, has been a common theme in recent DeFi breaches, including the Drift Protocol and Kelp DAO incidents. Users holding Wasabi LP tokens have been advised to revoke any active approvals to the vault contracts, as the underlying assets backing those tokens have either been drained or remain at risk. The cumulative DeFi loss total for 2026 has now surpassed $770 million, with April accounting for the majority of this figure. The frequency and severity of these breaches highlight the need for improved security measures and greater awareness of potential vulnerabilities in the DeFi sector.