Wasabi Protocol Exploited for $5M via Compromised Admin Key Across Multiple Chains

ETH0.76%
USDC0.01%
PEPE1.67%
MOG1.27%

According to PeckShield, Blockaid, and CertiK, decentralized derivatives platform Wasabi Protocol was exploited for more than $5 million in a coordinated attack spanning Ethereum, Base, Berachain, and Blast. The breach was caused by a compromised admin key rather than a smart contract vulnerability. The attacker used the protocol’s deployer wallet to upgrade core contracts and drain funds across multiple vaults.

BlockSec reported that accounts funded through Tornado Cash were granted admin-level roles, enabling activity across Wasabi’s LongPool, ShortPool, and Vault contracts. Cyvers indicated the attacker extracted WETH, USDC, cbBTC, and memecoins including PEPE and MOG, subsequently consolidating funds into ether, bridging to Ethereum, and distributing across multiple addresses.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments