Wasabi Protocol Exploit Drains $5M Across Ethereum, Base and Blast After Deployer Key Compromise Exposes Critical Admin Access Risks
Attackers used stolen admin key to upgrade contracts, drain WETH and tokens, raising DeFi security concerns and prompting urgent user warnings worldwide

Wasabi Protocol Hack Drains $5M Across Multiple Chains
Wasabi Protocol experienced a major security breach that resulted in losses exceeding $5 million across several blockchain networks, including Ethereum, Base, and Blast. The exploit, which unfolded early Thursday, has been attributed not to a flaw in smart contract logic, but to the compromise of a deployer externally owned account (EOA) — a critical administrative key with elevated privileges over the protocol’s core infrastructure.
Key Details of the Exploit
According to blockchain security firms such as PeckShield and Blockaid, the attacker gained control of the deployer key and used it to execute unauthorized administrative actions. These included granting ADMIN_ROLE permissions to a malicious contract and upgrading core protocol components, including vaults and liquidity pools, via upgradeable proxy patterns.
Hypernative detected the exploit at approximately 07:48 UTC and categorized it as high severity. The attack persisted for nearly two hours, during which multiple vaults and pools were drained. The attacker leveraged functions such as strategyDeposit to redirect user collateral and manipulated the WasabiLongPool contract by upgrading it to a malicious implementation.
Assets Affected and Fund Movements
The stolen assets spanned multiple tokens, with the largest single outflow totaling approximately 840.9 WETH — valued at over id="armcp-prerender-content".9 million. Other compromised assets included sUSDC, PEPE, MOG, NEIRO, and cbBTC. Following the exploit, the attacker consolidated funds into ETH and distributed them across various addresses, some of which were linked to Tornado Cash — a privacy tool often used to obfuscate transaction trails.
Before the breach, Wasabi Protocol’s total value locked (TVL) was estimated at around $8.5 million, based on data from DeFiLlama. This indicates that a significant portion of the protocol’s liquidity was impacted.
Root Cause: Key Compromise, Not Code Vulnerability
Importantly, investigators have emphasized that the exploit did not stem from a vulnerability in Wasabi’s smart contracts. Instead, the breach was caused by a compromised private key associated with the deployer EOA. This allowed the attacker to bypass standard security mechanisms and directly manipulate contract behavior through privileged access.
This type of attack highlights a critical risk in decentralized finance (DeFi): centralized points of control, such as admin keys, can become single points of failure if not properly secured through measures like multi-signature wallets or hardware isolation.
Official Response and User Guidance
Wasabi Protocol acknowledged the incident and issued a warning to users via its official channels, advising them not to interact with any Wasabi contracts until further notice. The team stated that an investigation is ongoing and that updates will be shared as more information becomes available.
In response to the incident, Virtual’s Protocol — which integrates with Wasabi — has frozen margin deposits مرتبط with the affected contracts. The team confirmed that its own systems remain secure but urged users to avoid signing any transactions связанными with Wasabi.
Users are strongly encouraged to take precautionary steps, including revoking token approvals and monitoring wallet activity for any unauthorized transactions.
Broader Industry Context
This incident adds to a growing list of high-profile DeFi exploits in April, a month that has seen over $606 million in losses across the sector. Notably, earlier in the month, Drift Protocol — operating on the Solana network — suffered a $285 million breach. Around April 18, another exploit involving KelpDAO and LayerZero resulted in losses of approximately $292 million.
These events underscore persistent security challenges in the DeFi ecosystem, particularly around access control and key management. As protocols continue to evolve, robust operational security practices — including key rotation, multi-signature governance, and real-time monitoring — are essential to mitigate systemic risks.
Source: https://www.cryptotimes.io/2026/04/30/wasabi-proto