Wasabi Protocol, a perpetuals trading platform on Ethereum and Base, lost approximately $4.55 million on April 30, 2026, after attackers compromised its deployer key and exploited admin privileges to drain funds across multiple chains including Ethereum, Base, Berachain, and Blast. The attacker used the wasabideployer.eth account, which held sole ADMIN_ROLE permissions with no timelock or multisig protection, to grant themselves admin access and upgrade vault contracts to malicious implementations that extracted balances from wWETH, sUSDC, wBITCOIN, and other vaults. Security firms PeckShield, Blockaid, and CertiK confirmed the exploit, which follows a devastating pattern of similar attacks including Drift Protocol's $285 million loss and Kelp DAO's $292 million breach earlier in April 2026. The incident contributes to over $770 million in total DeFi losses across more than 30 incidents in 2026, with April alone accounting for $605 million across at least 12 breaches, highlighting systemic vulnerabilities in single-key admin configurations.
Story comments
Loading comments…