Wasabi Protocol $5 Million Exploit Accelerates AI-Driven DeFi Hacker Theory
Wasabi Protocol suffered an admin-key compromise that drained over $5 million from its perpetuals vaults and LongPool across Ethereum, Base, Berachain, and Blast, on-chain security firms Blockaid and PeckShield reported. The attacker gained ADMIN_ROLE through the protocols deployer wallet, then upgraded the vaults to a malicious implementation that siphoned user balances. About $4.55 million had been extracted at last count, and the investigation remains active. Single-Key Failure Behind the Breach Blockaid traced the root cause to wasabideployer.eth, the only address holding ADMIN_ROLE in Wasabis PerpManager AccessManager. The attacker called grantRole on the deployer EOA with zero delay, instantly turning their orchestrator contract into an admin. “Were aware of an issue and are actively investigating. As a precaution, please do not interact with Wasabi contracts until further notice,” Wasabi Protocol urged users. From there, the attacker UUPS-upgraded perpetual vaults and the LongPool to a malicious implementation that drained balances. The deployer key remains live. Wasabi and Spicy LP-share tokens from affected vaults are flagged as compromised, with redemption value approaching zero. Blockaid noted the same attacker, orchestrator, and strategy bytecode tie this incident to earlier activity targeting Wasabi. The pattern echoes prior admin-key incidents and reflects single-EOA admin setups without timelocks or multisigs. PeckShield put the total losses past the