Wasabi Hack
What happened
On April 30, 2026, an attacker took control of the Wasabi Protocol deployer wallet, wasabideployer.eth. That one externally owned account held ADMIN_ROLE over every upgradeable Wasabi vault. The attacker used it to upgrade the contracts and drain vaults and pools on Ethereum, Base, Berachain and Blast.
rekt.news puts total losses at $5.9 million. Early estimates were lower: Blockaid's figure was about $4.55 million for Ethereum and Base, and Halborn cited about $5 million. The largest single withdrawal was 840.9 WETH from the Ethereum WETH vault.
The attacker converted most of the stolen tokens to ETH, split it across five wallets, and sent four of them through Tornado Cash within days. Wasabi posted its first warning about two hours after the drain and brought in SEAL-911 and Blockaid. On May 1 it said the breach was contained and credentials rotated, and it offered the attacker a negotiated resolution on-chain.
There was no compensation plan or published post-mortem when rekt.news wrote its report.
How it happened
- The attacker obtained the private key of
wasabideployer.eth, the deployer EOA with soleADMIN_ROLE. How the key was obtained is unknown. - They deployed a malicious orchestrator contract and a fake strategy contract on all four chains.
- The deployer called
grantRole()to give the orchestratorADMIN_ROLE. The access-control framework supported a delay before a new role becomes usable, but it was set to zero, so the role worked immediately. - The orchestrator ran UUPS upgrades that swapped the vault and LongPool logic for malicious implementations while keeping the same contract addresses.
- It called
strategyDeposit()to move vault assets into the fake strategy, which has no whitelist check, then calleddrain()to send them to the attacker. The attacker swapped the tokens to ETH and sent it through five wallets, mostly into Tornado Cash.
Protocol details
Evidence
- report @CertiKAlert incident report x.com
- report @peckshield incident report x.com
- report @wasabi_protocol incident report x.com
- report Wasabi Protocol - Rekt rekt.news
- analysis DeFiLlama defillama.com
- analysis Crypto hacks continue as Wasabi Protocol drained of $4.5 million in admin key compromise coindesk.com
- analysis The Block: Wasabi multi-chain exploit theblock.co
- analysis Explained: The Wasabi Protocol Hack (April 2026) halborn.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.