DeFi leveraged trading protocol Wasabi Protocol was hit by a security exploit on April 30, with blockchain security firm CertiK reporting approximately $5.5 million in stolen funds. The attacker gained privileged role access through Wasabi's deployer wallet, then executed the attack.
Attack Vector: Exploited Admin Privileges
Initial investigations show the attacker capitalized on admin privileges left in the protocol's deployment contracts, taking control of the deployer wallet. Stolen funds have been distributed across multiple addresses: 0xb8Bb...70dB holds about $677,000, 0x6244...f906 holds about $1.1 million, with the rest scattered elsewhere. Such privilege-based exploits are not uncommon in DeFi.
Wasabi Protocol: Focus on Memecoin and NFT Leverage
Wasabi Protocol enables leveraged trading of memecoins and NFTs across Ethereum, Blast, and Base. In June 2024, it secured a $3 million seed round led by Electric Capital, with participation from Alliance, Memeland, and Pudgy Penguins CEO Luca Netz. The exploit has put user funds at risk.
No Official Response Yet
As of press time, the Wasabi Protocol team has not issued a public statement. CertiK continues to monitor the movement of stolen funds. The incident underscores the inherent risks of single-signature architectures and lax privilege management in DeFi.

