← Radar

Incident case file

Sign in to watch

Wasabi Protocol — Deployer Admin Key Compromise / UUPS Proxy Upgrade Drain

Incident date April 30, 2026

0 views

Funds movingEthereumBaseBlastBerachainPrivate key leakCluster: WASABI-MULTICHAIN-2026-04

Estimated loss

$5M

Victims identified

12
Victim group joining is coming soon.

Investigation

25%

Facts and investigation

Attacker: 0x02228b0afcdbEdf8180D96Fc181Da3AF5DD1d1ab

Funds moved to: Consolidated in ETH; inter-chain bridging; distributed across multiple addresses; partial routing via Tornado Cash. deployer EOA: 0x5c629f8c0b5368f523c85bfe79d2a8efb64fb0c8 (wasabideployer.eth)
Malicious upgrade tx: 0x985b4cde1075c67841d0f9fd897da34c9da53d77f6e23b5a19653ebff4a6fac1. Compromised vaults: wWETH, sUSDC, sREKT, wPEPE, wMog, wBITCOIN, sZYN (Ethereum); sUSDC, wWETH, sBTC/cbBTC, sVIRTUAL, sAERO, sBRETT, sWELL, sSKI (Base).

Timeline: April 30, 2026, ~07:48 UTC — Hypernative, Blockaid, Cyvers detect exploit in real time. Attacker had compromised wasabideployer.eth, sole holder of ADMIN_ROLE with zero timelock and no multisig. Called grantRole → ADMIN_ROLE transferred to attacker helper contract → UUPS proxy upgrades executed on 7–8 WasabiVault proxies + WasabiLongPool across Ethereum, Base, Blast, and Berachain → malicious implementation drains all vault collateral via fake strategyDeposit() calls. Largest single loss: 840.9 WETH (>$1.9M). ~10:30 UTC — Official Wasabi tweet. Virtuals Protocol freezes Wasabi-powered margin deposits. Berachain Foundation pauses Wasabi reward vaults and stops BGT emissions. FBI contacted, SEAL 911 engaged.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)