Wasabi Protocol Suffers $4.5 Million Loss Due to Admin Key Breach

The DeFi sector continues to experience significant losses, with Wasabi Protocol being the latest victim. On Thursday, the platform, which is built on Ethereum and Base, was drained of approximately $4.55 million after its deployer key was compromised, according to security firm Blockaid. This incident is the latest in a series of DeFi losses, totaling over $605 million across at least 12 incidents this month. The attack bears a striking resemblance to the Drift Protocol exploit, which occurred on April 1, where North Korea-linked attackers used a compromised admin key to drain $285 million from the Solana-based perpetuals exchange. The attackers gained control of the Wasabi protocol by exploiting an externally owned account called wasabideployer.eth, which held the sole admin role in the permission system. With access to the deployer key, the attackers granted themselves admin privileges and upgraded the perp vaults and Long Pool to malicious implementations, resulting in the draining of balances. The exploit relied on the Universal Upgradeable Proxy Standard, which allows smart contracts to change their underlying code without changing their address. However, the lack of a timelock or multisig protecting the admin role left the protocol vulnerable to attack. The incident highlights the need for DeFi platforms to implement robust security measures to prevent such breaches. The cumulative DeFi loss for 2026 has now exceeded $770 million, with April accounting for the majority of the losses. Other notable breaches this month include CoW Swap, Grinex, Resolv Labs, and Volo Protocol. The repeated incidents suggest that DeFi platforms are not learning from past mistakes, leaving them vulnerable to similar attacks.