No connection

Search Results

Crypto Score 32 Bearish

Wasabi Protocol Suffers $4.55 Million Exploit via Admin Key Compromise

Apr 30, 2026 10:37 UTC
ETH, BTC, USDC
Immediate term

A security breach involving a compromised deployer key led to the theft of $4.55 million from Wasabi Protocol's vaults. The incident underscores ongoing vulnerabilities in DeFi governance and the risks of single-key administrative control.

  • Loss of $4.55 million across Ethereum and Base networks
  • Compromised deployer EOA allowed unauthorized admin access
  • Malicious UUPS upgrades used to drain vault balances
  • Absence of multisig and timelock safeguards cited as primary failure
  • Users advised to revoke vault contract approvals

Wasabi Protocol, a perpetuals trading platform operating on Ethereum and Base, has been drained of approximately $4.55 million following the compromise of its administrative deployer key. The breach was identified by security firm Blockaid, which noted that the attacker gained control of an externally owned account (EOA) that held the sole admin role within the protocol's permission system. Once the attacker secured the deployer key, they granted themselves administrative privileges and utilized the UUPS upgradeability pattern to swap the protocol's underlying code. This allowed the attacker to replace the perp vaults and LongPool with malicious implementations designed to drain user balances. The exploit was made possible by a critical lack of security infrastructure; Wasabi had neither a multisig wallet nor a governance timelock to delay or authorize administrative changes. The theft affected multiple vaults across two networks. On Ethereum, compromised assets included wWETH, sUSDC, wBITCOIN, and wPEPE. On Base, the attacker targeted sUSDC, wWETH, sBTC, sVIRTUAL, sAERO, and sBRETT. Users holding Wasabi LP tokens have been urged to immediately revoke all active approvals to the vault contracts to mitigate further risk. This incident is part of a broader trend of DeFi instability. Total losses for 2026 have now exceeded $770 million across more than 30 incidents, with April alone seeing a significant spike in activity. The Wasabi attack closely mirrors previous exploits, such as the Drift Protocol breach, where the absence of governance timelocks and the reliance on single-key setups led to massive capital outflows.

Sign up free to read the full analysis

Create a free account to unlock full AI-curated market articles, personalized alerts, and more.

Share this article

Stay Ahead of the Markets

Join thousands of traders using AI-powered market intelligence. Get personalized insights, real-time alerts, and advanced analysis tools.

Home
Terminal
AI Chat
Markets
Profile