Wasabi Protocol Loses $5M After Attacker Seizes Deployer Admin Key Across Three Chains

Wasabi Protocol Loses $5M After Attacker Seizes Deployer Admin Key Across Three Chains

N
News Editor 01
2026-07-09 15:52:13
Wasabi Protocol suffered a ~$5M exploit when an attacker compromised the deployer's admin private key, draining vaults and liquidity pools on Ethereum, Base, and Blast. The breach highlights single-point-of-failure risks in upgradeable proxy architectures. Virtuals Protocol froze deposits; users urged to revoke approvals.
Wasabi ProtocolDeFi securityhackadmin keyupgradeable proxy

On April 30, 2026, decentralized finance protocol Wasabi Protocol was severely compromised after an attacker gained control of the deployer's admin private key, stealing an estimated 4.5 to 5.5 million USD across three blockchains: Ethereum, Base, and Blast. The exploit exposed the critical vulnerability of upgradeable proxy contracts combined with centralized admin keys, where a single private key can control core contracts on multiple chains.

Attack Details: Single Point of Failure Leads to Full Compromise

The compromised address, 0x5c629f8c0b5368f523c85bfe79d2a8efb64fb0c8, held the sole admin key for Wasabi's Perpmanager contracts. The attacker used this key to grant ADMIN_ROLE to a malicious helper contract, then performed unauthorized UUPS proxy upgrades on WasabiVault proxies and the WasabiLongPool, ultimately draining all collateral and pool balances.

Security firm Hypernative issued high-severity alerts on all three chains; Blockaid, Cyvers, and Defimonalerts also detected abnormal activity in real time. Hypernative confirmed it is not a Wasabi customer but independently detected the breach and promised a full technical analysis. The attack began around 07:48 UTC and lasted approximately two hours.

Stolen Assets and Affected Pools

The attacker used a malicious contract to call strategyDeposit() on 7-8 WasabiVault proxies, passing a fake strategy that triggered a drain() function to extract all collateral. Subsequently, the WasabiLongPool on Ethereum and Base was upgraded to a malicious implementation that swept remaining balances. The largest single loss was 840.9 WETH (about $1.9M at the time), with other stolen assets including sUSDC, sREKT, PEPE, MOG, NEIRO, ZYN, bitcoin, and Base-chain assets such as VIRTUAL, AERO, and cbBTC. According to Defillama, Wasabi's total value locked (TVL) across all chains was approximately $8.5 million prior to the exploit.

Root Cause: Key Management Failure, Not Smart Contract Vulnerability

This was not a code-level bug (such as reentrancy or logic errors) but a classic key management failure. The attacker likely obtained the private key through phishing, malware, or direct theft, then abused the upgradeable proxy architecture to bypass normal security controls. The compromised key was the single admin key controlling the Perpmanager contracts, creating a single point of failure.

Industry Response and User Guidance

Virtuals Protocol, which enabled margin deposits via Wasabi, immediately froze all margin deposits after detecting the breach, confirming its own security fully intact. Trading, withdrawals, and agent activities on Virtuals continued uninterrupted. The team warned users not to sign any Wasabi-related transactions. As of the latest available data, Wasabi Protocol has not issued any public statement. The protocol previously underwent audits by Zellic and Sherlock, but this attack completely circumvented those protections.

Affected users are urged to immediately revoke all Wasabi approvals on Ethereum, Base, and Blast using tools like Revoke.cash, Etherscan, and Basescan; withdraw any remaining LP positions; and refrain from signing any Wasabi-related transactions until the team confirms key rotation and full contract integrity.

April 2026: A Nightmare Month for DeFi Security

The Wasabi incident is not isolated. In April 2026, DeFi protocols lost over $600 million across about a dozen confirmed incidents, making it one of the worst months in the industry's history. On April 1, attackers drained approximately $285 million from Solana's Drift Protocol in under 20 minutes through governance manipulation and oracle abuse. Around April 18, a Layerzero bridge exploit hit KelpDAO on Ethereum, stealing about $292 million in rsETH and causing over $10 billion in downstream contamination across lending platforms including Aave. Smaller attacks occurred throughout the month on Silo Finance, Cow Swap, Grinex, Rhea Finance, and Aftermath Finance.

The pattern across almost every incident is not code-level bugs but compromised admin keys, bridge vulnerabilities, and upgradeable proxy risks, exposing centralized control points that audits alone cannot defend against. The Wasabi situation remains ongoing. Users should monitor the official @wasabi_protocol account and security firm feeds for updates.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.