Wasabi Protocol hack — April 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | April 30, 2026 |
| Target type | Decentralised exchange |
| Loss | $4,550,000Published estimates range $4,550,000 to $5,000,000Price at time of incident |
| Method | Private key compromiseCompromise of the protocol's deployer account, wasabideployer.eth, a single externally owned account that held ADMIN_ROLE. The key was used to call grantRole and hand ADMIN_ROLE to an attacker-controlled helper contract with no waiting period, which then executed UUPS proxy upgrades on the Wasabi vault proxies and the long pool, replacing the implementations with versions that swept the underlying balances. CoinDesk describes the admin role as having had no timelock or multisig protecting it; The Block reports a role-change delay mechanism existed but had been set to zero. |
| Chains | Ethereum, Base, Blast, Other |
| Outcome | Unresolved |
What happened
On 30 April 2026 an attacker took control of the deployer account behind Wasabi Protocol, a decentralised perpetual-futures platform for long-tail assets and memecoins, and used it to drain the protocol's vaults. This is Wasabi Protocol, unrelated to the Wasabi Wallet Bitcoin project.
The deployer address, wasabideployer.eth, was a single externally owned account holding ADMIN_ROLE. Whoever held the key called grantRole to hand ADMIN_ROLE to an attacker-controlled helper contract with no waiting period, then pushed UUPS proxy upgrades onto the Wasabi vault proxies and the long pool, replacing the implementations with versions that swept the balances. CoinDesk, citing Blockaid, reported that no timelock or multisig protected the admin role; The Block reported that a delay mechanism for admin role changes existed but had been set to zero, and that preliminary traces suggested the admin-related roles were granted to Tornado Cash-funded accounts. Affected vaults included wWETH, sUSDC, wBITCOIN, wPEPE and the long pool on Ethereum, and sUSDC, wWETH, sBTC, sVIRTUAL, sAERO and sBRETT on Base. PeckShield also reported activity on Berachain and Blast. Assets taken included WETH, USDC, PEPE, MOG, cbBTC, AERO and VIRTUAL. The proceeds were consolidated into ETH, bridged to Ethereum and split across multiple addresses.
Published totals differ. CoinDesk, citing Blockaid, put the loss at about $4.55 million. PeckShield, cited by The Defiant, put it above $5 million, and The Block reported the same range from security firms. Wasabi has not published its own accounting.
Wasabi told users not to interact with its contracts and engaged SEAL 911 and Blockaid. Blockaid warned that all Wasabi and Spicy LP-share tokens minted by the affected vaults should be treated as compromised. Weeks later Wasabi said its post-mortem was still in progress and that no final user compensation plan existed.
Sources
- CoinDeskSecondary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- The DefiantSecondary · retrieved 2026-08-01
- CoinCuAggregator · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Wasabi Protocol hack — April 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/wasabi-protocolhttps://itokenly.com/hacks/wasabi-protocolPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.