Wasabi Protocol Loses $4.5 Million to Hackers After Admin Key Compromise
The decentralized finance sector continues to experience significant losses, with Wasabi Protocol being the latest victim. On Thursday, the platform, which operates as a perpetuals trading platform on Ethereum and Base, was drained of around $4.55 million after its deployer key was compromised, according to security firm Blockaid. This incident marks the latest in a series of DeFi losses, which have exceeded $605 million across at least 12 incidents this month. The mechanics of the attack involved an externally owned account called wasabideployer.eth, which held the sole ADMIN_ROLE in Wasabi's permission system. The attacker gained access to the deployer key and granted themselves admin privileges with zero delay by calling grantRole on the permission contract. A helper contract was then used to upgrade Wasabi's perp vaults and Long Pool to malicious implementations, resulting in the draining of balances. The exploit relied on the Universal Upgradeable Proxy Standard (UUPS), which allows a smart contract to change its underlying code while maintaining the same address. However, the lack of a timelock or multisig protecting the admin role left the protocol vulnerable to attack. The absence of these security measures allowed a single key to hold full control over the protocol. The compromised contracts include Wasabi's wWETH, sUSDC, wBITCOIN, wPEPE, and Long Pool vaults on Ethereum, as well as its sUSDC, wWETH, sBTC, sVIRTUAL, sAERO, and sBRETT vaults on Base. Users holding Wasabi LP tokens have been advised to revoke any active approvals to the vault contracts, as the underlying assets backing those tokens have either been drained or remain at risk. This incident is part of a larger trend of DeFi exploits, which have resulted in significant losses this month. The cumulative DeFi loss total for 2026 has now surpassed $770 million across more than 30 reported incidents. Other notable breaches this month include CoW Swap, Grinex, Resolv Labs, and Volo Protocol. The common thread among these incidents is the exploitation of known vulnerabilities, highlighting the need for improved security measures in the DeFi sector.