Wasabi Hack

Reported loss $5.5M
Base Berachain Blast Ethereum
Access Control

What happened

On April 30, 2026, an attacker took control of the Wasabi Protocol deployer wallet, wasabideployer.eth. That one externally owned account held ADMIN_ROLE over every upgradeable Wasabi vault. The attacker used it to upgrade the contracts and drain vaults and pools on Ethereum, Base, Berachain and Blast.

rekt.news puts total losses at $5.9 million. Early estimates were lower: Blockaid's figure was about $4.55 million for Ethereum and Base, and Halborn cited about $5 million. The largest single withdrawal was 840.9 WETH from the Ethereum WETH vault.

The attacker converted most of the stolen tokens to ETH, split it across five wallets, and sent four of them through Tornado Cash within days. Wasabi posted its first warning about two hours after the drain and brought in SEAL-911 and Blockaid. On May 1 it said the breach was contained and credentials rotated, and it offered the attacker a negotiated resolution on-chain.

There was no compensation plan or published post-mortem when rekt.news wrote its report.

How it happened

  1. The attacker obtained the private key of wasabideployer.eth, the deployer EOA with sole ADMIN_ROLE. How the key was obtained is unknown.
  2. They deployed a malicious orchestrator contract and a fake strategy contract on all four chains.
  3. The deployer called grantRole() to give the orchestrator ADMIN_ROLE. The access-control framework supported a delay before a new role becomes usable, but it was set to zero, so the role worked immediately.
  4. The orchestrator ran UUPS upgrades that swapped the vault and LongPool logic for malicious implementations while keeping the same contract addresses.
  5. It called strategyDeposit() to move vault assets into the fake strategy, which has no whitelist check, then called drain() to send them to the attacker. The attacker swapped the tokens to ETH and sent it through five wallets, mostly into Tornado Cash.

Protocol details

Classification Exchange (DEX) / Key Compromise
Protocol Type Exploit/Access control
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.