Wasabi Protocol Loses $4.5 Million Due to Apparent Admin Key Breach

The DeFi sector continues to experience significant losses, with Wasabi Protocol being the latest victim, having lost approximately $4.55 million on Thursday following a breach of its deployer key, as reported by security firm Blockaid. This incident is part of a series of DeFi losses totaling over $605 million across at least 12 incidents this month. The attack bears resemblance to the Drift Protocol exploit, where a compromised admin key was used to drain $285 million from the Solana-based perpetuals exchange. The Wasabi Protocol hack was facilitated through an externally owned account called wasabideployer.eth, which held the sole ADMIN_ROLE in the permission system. Once the attacker gained access to the deployer key, they granted themselves admin privileges and upgraded Wasabi's perp vaults and Long Pool to malicious implementations, resulting in the drainage of balances. The exploit leveraged the Universal Upgradeable Proxy Standard (UUPS), which allows smart contracts to change their underlying code without altering the address. However, this standard also poses a risk if an attacker gains admin permissions, as they can replace the contract's logic with malicious code. The absence of a timelock or multisig to protect the admin role was a critical vulnerability, as it allowed a single key to hold full control over the protocol. Blockaid's exploit detection system identified the ongoing admin-key compromise exploit, which involved the Wasabi: Deployer EOA granting ADMIN_ROLE to an attacker helper contract. This led to the UUPS-upgrade of perp vaults and LongPool to malicious contracts, compromising multiple vaults on Ethereum and Base. Users holding Wasabi LP tokens were advised to revoke active approvals to the vault contracts due to the risk of drained or compromised assets. This incident is part of a larger trend of DeFi exploits, with April alone accounting for the majority of the $770 million in cumulative losses across over 30 reported incidents. Other notable breaches this month include CoW Swap, Grinex, Resolv Labs, and Volo Protocol. A common thread among these incidents is the exploitation of known vulnerabilities, highlighting the need for improved security measures to prevent such losses.