Wasabi Protocol Drained of $5 Million After Admin Key Compromise Spans Four Chains

1 month ago 18

Rommie Analytics

Another day, another DeFi protocol drained. Wasabi Protocol, a perpetuals trading platform operating across Ethereum, Base, Berachain, and Blast, lost between $4.5 million and $5.5 million on April 30 after an attacker compromised the deployer admin key and used it to systematically empty vault contracts across all four chains.

The attack was fast and methodical. Once the attacker had the admin key, they called grantRole on Wasabi's permission contract to give themselves full admin privileges with zero delay - no timelock, no waiting period. From there, according to The Block, they upgraded the protocol's perp vaults and Long Pool to malicious implementations that simply drained the balances.

What Got Hit

On Ethereum, the affected contracts included Wasabi's wWETH, sUSDC, wBITCON, wPEPE, and Long P...

Read Entire Article