
According to blockchain security firms, Wasabi Protocol has suffered a significant multi-chain exploit worth more than $5 million. The attack affected multiple blockchain networks including Ethereum, Base, and Blast. As reported by crypto.news, the incident represents a sharp rise in DeFi exploits reported this month, adding to the growing security concerns in the decentralized finance sector. The compromised address, 0x5c629f8c0b5368f523c85bfe79d2a8efb64fb0c8, was the sole admin key controlling Wasabi's Perpmanager contracts, with the attack beginning around 07:48 UTC and running for approximately two hours.
Security firms Blockaid, Cyvers, and Defimonalerts revealed that the attacker utilized a compromised admin key to gain privileged access through the Wasabi deployer wallet. According to Hypernative, the attacker reportedly used the compromised key to grant the ADMIN_ROLE to attacker-controlled contracts on Ethereum, Base, and Blast. A malicious contract then called strategyDeposit() on seven to eight WasabiVault proxies, passing a fake strategy that triggered a drain() function returning all collateral to the attacker. The attacker likely obtained the private key through phishing, malware, or direct theft, then abused the upgradeable proxy architecture to drain funds without triggering conventional security checks.
As reported by Cyvers, the attacker extracted multiple assets including WETH, PEPE, MOG, USDC, ZYN, REKT, cbBTC, AERO, and VIRTUAL. The largest single loss was reportedly 840.9 WETH, worth more than $1.9 million at the time of the attack. Other drained assets included sUSDC, sREKT, PEPE, MOG, NEIRO, ZYN, and bitcoin, along with Base-chain assets such as VIRTUAL, AERO, and cbBTC. The attacker then upgraded the Wasabilongpool on Ethereum and Base to a malicious implementation that swept remaining balances. Funds were consolidated into ETH, bridged where needed, and distributed across multiple addresses.
According to crypto.news, Wasabi Protocol acknowledged the issue and is currently investigating the exploit. The platform has not issued a public statement as of the latest available data. Virtuals Protocol, which powered margin deposits through Wasabi Protocol, moved quickly after the breach was detected, freezing all margin deposits and confirming its own security remained fully intact. The team warned users to avoid signing any Wasabi-related transactions and advised users with exposure to revoke all Wasabi approvals across Ethereum, Base, and Blast immediately using tools like Revoke.cash, Etherscan, and Basescan. Users should monitor the official @wasabi_protocol account and security firm feeds for updates.
This incident occurs during what security experts describe as one of the worst months for DeFi security. As reported by crypto.news, more than $600 million has been drained from DeFi protocols across roughly a dozen confirmed incidents in April 2026. The month opened with attackers draining approximately $285 million from Drift Protocol on Solana in under 20 minutes using governance manipulation and oracle abuse. A second major blow came around April 18 when a Layerzero bridge exploit hit KelpDAO on Ethereum, draining roughly $292 million in rsETH and triggering over $10 billion in downstream contagion across lending platforms. The Wasabi Protocol exploit adds to this concerning trend, with the pattern across nearly every incident pointing toward admin key compromises, bridge weaknesses, and upgradeable proxy risks that audits alone cannot protect against.