Wasabi Protocol loses over $5 million in multi-chain exploit

Wasabi Protocol loses over $5 million in multi-chain exploit

N
News Editor 01
2026-07-22 15:00:13
Wasabi Protocol suffered a multi-chain exploit across Ethereum, Base, Berachain, and Blast, with losses topping $5 million. Security firms linked the attack to a compromised admin key used to upgrade contracts and drain funds.
Wasabi ProtocolDeFi securitymulti-chain exploitsmart contractson-chain security

Wasabi Protocol lost more than $5 million in a multi-chain exploit that hit Ethereum, Base, Berachain, and Blast. Blockchain security firms said the attack affected the DeFi derivatives platform across several deployments, with stolen funds later consolidated and moved on-chain.

Compromised admin key gave attacker contract control

PeckShield said the exploit targeted Wasabi Protocol on multiple networks. Blockaid and CertiK said the attacker used a compromised admin key tied to the Wasabi deployer wallet, which provided privileged access. With that access, the attacker upgraded core contracts and drained funds from the protocol.

BlockSec said early on-chain traces indicate that addresses with admin-linked roles were funded by accounts connected to Tornado Cash. Blockaid also warned that all Wasabi/Spicy LP-share tokens minted by the affected vaults should be treated as compromised.

Stolen assets were swapped and regrouped into ETH

According to Cyvers, the attacker extracted a range of assets, including WETH, PEPE, MOG, USDC, ZYN, REKT, cbBTC, AERO, and VIRTUAL. The firm said the stolen funds were then consolidated into ETH, bridged to Ethereum, and distributed across several addresses.

The flow suggests the incident was not limited to one isolated pool. It involved privileged access and contract changes across multiple chain deployments, widening the scope of exposure tied to Wasabi’s contracts.

Wasabi warns users to stop interacting with contracts

Wasabi Protocol said it was aware of the issue and investigating the exploit. The team told users not to interact with Wasabi contracts until further notice. In its statement, Wasabi said, “As a precaution, please do not interact with Wasabi contracts until further notice.”

Virtuals Protocol said its own security remains intact. Still, it froze margin deposits powered by Wasabi Protocol as a precautionary measure.

Attack lands during a heavy month for DeFi losses

The exploit comes in a month that has seen a sharp increase in DeFi security incidents. Reports cited in the source said more than 25 protocols have lost over $600 million in total, led by the $292 million Kelp DAO exploit. The Wasabi breach adds another major loss to that tally.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.