Wasabi Protocol Suffers $4.5 Million Loss Due to Apparent Admin Key Breach
The decentralized finance sector continues to experience significant losses, with Wasabi Protocol being the latest victim, losing approximately $4.55 million on Thursday after its deployer key was compromised, according to security firm Blockaid. This incident follows a string of breaches this month, totaling over $605 million in losses across at least 12 incidents. The attack bears resemblance to the Drift Protocol exploit, where a compromised admin key was used to drain $285 million from the Solana-based exchange. The mechanics of the attack involved an externally owned account, wasabideployer.eth, holding the sole ADMIN_ROLE in Wasabi's permission system, which was exploited by the attackers to gain admin privileges and drain balances. The exploit relied on the Universal Upgradeable Proxy Standard (UUPS), which allows smart contracts to change their underlying code without changing their address, but also poses a risk if an attacker gains admin permissions. The lack of a timelock or multisig to protect the admin role was cited as a key factor in the breach. Blockaid's exploit detection system identified the ongoing admin-key compromise, which involved the Wasabi: Deployer EOA granting ADMIN_ROLE to an attacker helper contract, leading to the UUPS-upgrade of perp vaults and LongPool to malicious implementations. Users holding Wasabi LP tokens were advised to revoke any active approvals to the vault contracts due to the risk of drained or compromised assets. This incident is part of a larger trend of DeFi exploits, with the cumulative loss total for 2026 exceeding $770 million across over 30 reported incidents, highlighting the need for improved security measures to prevent such breaches.