Crypto hacks continue as Wasabi Protocol drained for $4.5 million in admin key compromise
Summary
Wasabi Protocol, a perpetuals trading platform on Ethereum and Base, was drained of approximately $4.55 million after attackers compromised its deployer key. The exploit involved an externally owned account (EOA) holding the sole ADMIN_ROLE, which the attacker used to grant themselves admin privileges without delay. This allowed them to upgrade Wasabi's vaults to malicious implementations, draining user balances. The hack highlights a vulnerability in UUPS upgradeability when not protected by timelocks or multisig, a weakness also seen in recent exploits like Drift Protocol's $285 million breach. This incident contributes to significant DeFi losses in April, with cumulative losses for 2026 now exceeding $770 million.
(Source:CoinDesk)