Tools Crypto Exploit Tracker exploit-0048
Exploit record
Wasabi Protocol
- Loss
- $5M
- Attack vector
- Private Key Compromise
- Chain
- Ethereum
- Sector
- Perps
What happened
Perpetuals platform Wasabi Protocol was drained of roughly $5 million (initially reported at $4.5 million) on 30 April 2026 after its deployer admin key was compromised.
The attacker used the compromised deployer key to call grantRole with zero delay, then upgraded Wasabi's perp vaults and Long Pool to malicious implementations, draining vaults across Ethereum, Base, Berachain and Blast, including wWETH, sUSDC, wBITCOIN and wPEPE pools. Reporting highlighted the absence of a timelock or multisig on the admin role as the key safeguard failure.
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026
