Wasabi Protocol exploit drains over $5M across multiple chains. Security firms link attack to admin key compromise, urging users to revoke approvals as investigationsWasabi Protocol exploit drains over $5M across multiple chains. Security firms link attack to admin key compromise, urging users to revoke approvals as investigations

Wasabi Protocol Exploit Drains Over $5M Across Multiple Chains As Admin Key Compromise Suspected

2026/04/30 19:47
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com
Wasabi Protocol Exploit Drains Over $5M Across Multiple Chains As Admin Key Compromise Suspected

Web3 security incident has affected Wasabi Protocol across multiple blockchains, with on-chain activity indicating losses exceeding $5 million on networks including Ethereum, Base, Berachain, and Blast, according to Web3 security services provider PeckShield. 

Security monitoring firm Phalcon offered a preliminary analysis suggesting that accounts previously funded through Tornado Cash were later assigned ADMIN_ROLE-related permissions and participated in flows involving WasabiLongPool, WasabiShortPool, and WasabiVault contracts. The findings were shared for public visibility, with calls for further clarification regarding fund transfers and administrative role changes.

Separately, blockchain security platform Blockaid reported that a deployer externally owned account was used to grant administrative privileges to an attacker-associated contract, which then executed upgrade actions through a UUPS mechanism, replacing vault and perpetual pool implementations with malicious versions that drained user balances.

Blockaid further assessed that all Wasabi and related liquidity provider share tokens issued by the affected vaults should be considered compromised, as the underlying collateral had been drained or placed at risk while the deployer key remained active. The report noted that while token balances may still display nominal value, actual redemption value had effectively dropped to zero or was rapidly declining. Contracts cited as impacted included multiple vaults such as wWETH, sUSDC, wBITCOIN, and wPEPE on Ethereum, as well as sUSDC, wWETH, sBTC, sVIRTUAL, sAERO, and sBRETT vaults on Base, according to the security assessment.

On-chain analyst Cos raised concerns over the structure of control within the protocol, estimating losses above $4.5 million and highlighting that a single externally owned account appeared to govern multiple upgradeable vaults without multisignature protection, timelock mechanisms, or DAO-based oversight. Independent investigator ZachXBT similarly questioned the absence of standard security safeguards, suggesting that a leaked private key may have enabled the exploit.

Exploit Triggers Investigation And Precautionary Measures Across Wasabi Partner Networks

In response to the incident, Wasabi Protocol stated that an investigation was underway and advised users not to interact with its contracts until further notice, with additional updates promised as more information becomes available.

Berachain, one of the affected networks, also issued a warning advising users to withdraw funds immediately, estimating that approximately $50,000 in user funds on its network could be affected. Users were directed to revoke permissions using revoke.cash, while reward vault operations were temporarily paused as a precaution.

Virtuals Protocol separately stated that its own systems remained secure but confirmed that it had suspended margin deposits integrated with Wasabi infrastructure as a precautionary measure.

Users holding Wasabi liquidity provider tokens were broadly advised to revoke any active approvals tied to vault contracts, given that the collateral backing these instruments had been drained or remained at risk.

Wasabi Protocol operates as a perpetuals trading platform on Ethereum and Base, offering leveraged trading, token swaps, and yield features with leverage of up to 20x. The protocol is designed so that leveraged positions are backed by underlying assets held in custody rather than synthetic exposure, with ETH positions reportedly collateralized by actual ETH held within the system.

The post Wasabi Protocol Exploit Drains Over $5M Across Multiple Chains As Admin Key Compromise Suspected appeared first on Metaverse Post.

CHZ +28%! Will History Repeat?

CHZ +28%! Will History Repeat?CHZ +28%! Will History Repeat?

0-fee opening long & short. Be ready for any move!

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

任天堂(7974)株価予想2026:Switch 2値上げで¥6,994へ調整、平均目標株価¥10,282との乖離を分析

任天堂(7974)株価予想2026:Switch 2値上げで¥6,994へ調整、平均目標株価¥10,282との乖離を分析

任天堂(7974)は現在 ¥6,994(2026年6月22日時点)、当社判断は『中立』(やや強気寄り)。Switch 2の値上げと来期の減益・減配計画を嫌気し、任天堂 株価は6月に年初来安値圏まで水準を切り下げた。しかしアナリストの平均目標株価は¥10,282と現値から4割超のアップサイドを示し、ゲーム機の世代交代という構造的テーマは健在だ。本稿では任天堂(7974)の株価について、Switch
Share
MEXC Japan2026/06/25 14:04
2026 World Cup Group K Standings: Colombia, Portugal and Qualification Scenarios

2026 World Cup Group K Standings: Colombia, Portugal and Qualification Scenarios

The latest 2026 World Cup Group K standings have created a clear but still important final-round picture. Colombia lead the group with 6 points after beating Uzbekistan 3-1 and DR Congo 1-0, which has already secured their place in the Round of 32. Portugal sit second with 4 points after drawing 1-1 with DR Congo and then beating Uzbekistan 5-0. DR Congo are third with 1 point, while Uzbekistan are fourth with 0 points after two defeats. Times of India reported that Colombia qualified after the 1-0 win over DR Congo, while SB Nation noted that Portugal’s 5-0 win over Uzbekistan changed the qualification picture dramatically.
Share
MEXC NEWS2026/06/25 14:13
Crypto Market Drops as Fear Grows and Major Assets Decline

Crypto Market Drops as Fear Grows and Major Assets Decline

Crypto market falls 2.53% as Bitcoin ($BTC) and Ethereum (ETH) drop, while investor fear rises and NFT sales surge sharply despite DeFi slowdown
Share
Blockchainreporter2026/04/02 18:20

World Cup Combo: Aim for 200x

World Cup Combo: Aim for 200xWorld Cup Combo: Aim for 200x

Combine up to 20 World Cup matches in one order