Wasabi Protocol was hit by a multi-chain exploit that drained more than $5 million from its contracts on Ethereum, Base, Berachain, and Blast. Security firms including PeckShield, Blockaid, and CertiK said the attack was not caused by a smart-contract bug, but by a compromised admin or deployer key that let the attacker gain privileged access, upgrade the protocol’s contracts, and move funds out of vaults and liquidity pools. The incident matters because it shows how a single key-management failure can compromise an upgradeable DeFi system across several chains at once. Reporting said the attacker used the admin access to grant roles to malicious contracts and trigger unauthorized proxy upgrades, while affected assets included WETH, USDC, cbBTC, and several memecoin positions; Wasabi warned users not to interact with its contracts while it investigated, and Virtuals Protocol said it froze margin deposits tied to Wasabi as a precaution.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Private Key

Comments