Vavada Banner
BTC $77,381.00 (+1.70%)
ETH $2,285.05 (+1.16%)
XRP $1.38 (+0.41%)
BNB $618.11 (+0.21%)
SOL $84.10 (+1.14%)
TRX $0.33 (+0.39%)
DOGE $0.11 (+1.51%)
HYPE $40.40 (+2.54%)
LEO $10.32 (-0.56%)
ADA $0.25 (+1.08%)
BCH $443.57 (-0.31%)
XMR $384.89 (+1.35%)
LINK $9.18 (+0.61%)
ZEC $349.85 (+5.29%)
CC $0.15 (-1.15%)
XLM $0.16 (-0.25%)
LTC $55.27 (-0.47%)
M $3.20 (-6.14%)
AVAX $9.13 (-0.20%)
HBAR $0.09 (-0.48%)

Wasabi Protocol Loses $4.55M in Latest DeFi Exploit

Twitter icon  •  Published 1 hour ago on May 1, 2026  •  Nikolas Sargeant

DeFi's struggle to secure itself continues as Wasabi Protocol, a perpetuals trading platform on Ethereum and Base, was drained of approximately $4.55 million in a hack on Thursday.

Wasabi Protocol Loses $4.55M in Latest DeFi Exploit

TL;DR

  • Wasabi Protocol lost $4.55M in a hack after attackers compromised its deployer key, exploiting a single-key admin setup.
  • The breach mirrors the Drift Protocol exploit and highlights the DeFi industry's ongoing security struggles.

Wasabi Protocol Drained of $4.5 Million 

DeFi's struggle to secure itself continues as Wasabi Protocol, a perpetuals trading platform on Ethereum and Base, was drained of approximately $4.55 million in a hack on Thursday.

The security breach, linked to a compromised deployer key, mirrors the earlier Drift Protocol exploit from April 1, where North Korea-linked attackers stole $285 million.

The attack, identified by Blockaid, occurred when the attackers gained control of Wasabi’s deployer key and manipulated the protocol’s permissions.

By taking control of an externally owned account (EOA), they granted themselves admin privileges and upgraded the platform’s vaults and Long Pool to malicious versions. This allowed the attacker to drain the funds stored in Wasabi’s various vaults across Ethereum and Base.

The exploit leveraged the Universal Upgradeable Proxy Standard (UUPS), allowing the attackers to replace the smart contract’s code while keeping the same address. UUPS, often used for fixing bugs without disrupting users, becomes a vulnerability when an attacker controls admin permissions.

Wasabi’s lack of safeguards—such as a timelock or multisig—left the protocol exposed, granting full control to a single key. The attack compromised several of Wasabi's vaults, including assets like wWETH, wBITCOIN, and sUSDC. Users holding Wasabi LP tokens were urged to revoke approvals to the affected contracts.

The Wasabi breach is part of a larger pattern in DeFi, with over $770 million lost in 2026 across more than 30 incidents. These attacks often share a common theme: the exploitation of single-key admin setups and the absence of proper governance measures like timelocks or multisig setups. As a result, the lessons from these attacks often come too late to prevent the next breach.

 
Polymarket Partners with Chainalysis to Tackle Insider Trading and Boost Market Integrity
Next article Polymarket Partners with Chainalysis to Tackle Insider Trading and Boost Market Integrity
Nikolas Sargeant

Nik is a content and public relations specialist with an ever-growing interest in Crypto. He has been published on several leading Crypto and blockchain based news sites. He is currently based in Spain, but hails from the Pacific Northwest in the US.