Wasabi Protocol exploited for $4.5M via transaction vulnerability.
Security & Exploits ·
Blockaid's exploit detection system identified an ongoing compromise of Wasabi Protocol's admin key across Ethereum and Base networks. The attacker used the Wasabi Deployer EOA to grant ADMIN_ROLE to a helper contract, which then performed a UUPS upgrade on the protocol's perp vaults and LongPool to a malicious implementation that drained user balances, resulting in losses of $4.5M.
The attack leveraged privileged access to execute contract upgrades that redirected funds from the affected pools. The compromise appears to have been detected during the exploit window, though the precise mechanism by which the admin key was initially compromised remains unclear from available disclosures.
The incident underscores risks associated with centralized admin key control in DeFi protocols. Questions remain regarding the scope of affected user positions, recovery prospects, and whether additional security breaches preceded or enabled the admin-key compromise.