Wasabi Protocol Loses $4.5 Million in Apparent Admin Key Breach

The DeFi sector continues to suffer significant losses, with Wasabi Protocol being the latest victim. On Thursday, the platform, which is built on Ethereum and Base for perpetuals trading, was drained of around $4.55 million after its deployer key was compromised, according to security firm Blockaid. This incident follows a string of similar breaches, including the Drift Protocol exploit on April 1, where $285 million was stolen from the Solana-based perpetuals exchange by North Korea-linked attackers using a compromised admin key. The attack on Wasabi Protocol was carried out through an externally owned account called wasabideployer.eth, which held the sole admin role in the platform's permission system. Once the attackers gained access to the deployer key, they quickly granted themselves admin privileges and upgraded Wasabi's perp vaults and Long Pool to malicious implementations, resulting in the draining of balances. The exploit leveraged the Universal Upgradeable Proxy Standard (UUPS), which allows smart contracts to change their underlying code without altering their address. However, this standard also poses a significant risk if an attacker gains admin permissions, as they can replace the contract's logic with malicious code designed to steal funds. Blockaid noted that Wasabi lacked a timelock or multisig to protect the admin role, leaving a single key in control of the entire protocol. The compromised contracts include various vaults on both Ethereum and Base, and users holding Wasabi LP tokens have been advised to revoke any active approvals to the vault contracts to prevent further losses. This incident is part of a larger trend of DeFi exploits, with over $605 million lost across at least 12 incidents in the past month alone, highlighting the need for improved security measures in the DeFi space.