Wasabi protocol on Base suffered an exploit where a malicious actor upgraded a contract; whitehat bot recovered $8000 in tokens via an unprotected sweep function.
Security & Exploits ·
A malicious actor exploited the Wasabi protocol on Base by upgrading a WasabiLongPool contract to drain funds from the system. In response, a whitehat bot identified that the upgraded contract contained an unprotected sweep() function lacking access controls, which allowed recovery of approximately $8,000 in various tokens. The recovered funds were subsequently returned to the affected team, as documented in a transaction on Base.
The exploit succeeded because the contract upgrade introduced the vulnerability—a public function with no permission restrictions that enabled token recovery. The whitehat intervention prevented a total loss by leveraging this oversight in the malicious upgrade.
It remains unclear what volume of funds the initial attack extracted, whether Wasabi deployed additional safeguards following the incident, or if the broader protocol suffered further losses beyond what the whitehat recovered.