Wasabi Protocol hacked: $5M+ lost in admin key breach

Wasabi Protocol lost over $5M after its admin key was compromised, allowing attackers to upgrade contracts and drain funds across several blockchains. All Wasabi LP tokens are compromised; users should revoke approvals now.

Wasabi Protocol, a DeFi platform focused on leveraged trading, suffered a major security breach after its admin key was compromised. The attacker exploited the deployer key to upgrade core smart contracts to malicious versions, enabling them to drain liquidity pools on Ethereum, Base, Berachain, and Blast networks. Security experts estimate losses between $4.5 million and $5 million, with about 25% of the protocol’s total value locked (TVL) lost within hours. The exploit involved replacing the logic of critical contracts, allowing unauthorized withdrawals of multiple assets. All Wasabi LP tokens are now considered compromised, and users are strongly advised to revoke any approvals to Wasabi’s vault contracts. This incident highlights ongoing vulnerabilities in DeFi platforms, especially those relying on single-key admin controls without protections like timelocks or multisig wallets. Wasabi Protocol has urged users to avoid interacting with its contracts until further notice.

Related Tokens

Related News