{"investigation":{"slug":"wasabi","entity_name":"Wasabi Protocol","trust_score":18,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"Wasabi Protocol is a decentralized perpetual futures and leveraged trading platform for memecoins and long-tail assets, deployed on Ethereum, Base, Berachain, and Blast. On April 30, 2026, the protocol suffered a critical multi-chain exploit in which a compromised admin deployer key was used to execute malicious UUPS proxy upgrades across core contracts, draining over $5 million in user funds. Security firm BlockSec reported that the attacker's wallets had been funded via Tornado Cash, and on-chain investigator ZachXBT publicly criticized the protocol for single-EOA admin control, absence of a timelock or multisig, and alleged misappropriation of project funds on influencer marketing.","sections":[{"content":"Wasabi Protocol is a decentralized finance (DeFi) platform focused on perpetual futures and leveraged trading of memecoins, NFTs, and other long-tail crypto assets. The protocol operates across Ethereum, Base, Berachain, and Blast. In June 2024, Wasabi raised $3 million in a seed round led by Electric Capital, with additional participation from Alliance, Memeland, Spencer Ventures, Pudgy Penguins CEO Luca Netz, Magic Eden co-founder Zhouxun Yin, angel investor Santiago Santos, and several crypto influencer figures including Cygaar, Zagabond, DCF God, and Bob Loukas. At the time of the exploit, the protocol had expanded from a six-person team and was planning to grow further. Wasabi Protocol should not be confused with Wasabi Wallet, a separate Bitcoin CoinJoin privacy tool.","heading":"Overview and Background","sources":[],"severity":"medium"},{"content":"On April 30, 2026, Wasabi Protocol was drained of over $5 million across Ethereum, Base, Berachain, and Blast in what security researchers classified as an admin key compromise. The attack was executed via a single externally owned account (EOA) identified as wasabideployer.eth, which held the sole ADMIN_ROLE in the protocol's access control framework. An attacker gained control of the deployer private key and used it to grant ADMIN_ROLE privileges to a malicious smart contract under their control. The attacker-controlled contract then performed Universal Upgradeable Proxy Standard (UUPS) upgrades on the protocol's core contracts — including the LongPool, ShortPool, perpetual vaults, and main Vault contracts — replacing their underlying logic with malicious implementations while preserving the original contract addresses. This allowed the attacker to drain liquidity and user funds from all pools across all four chains. Stolen assets included WETH, PEPE, MOG, USDC, ZYN, REKT, cbBTC, AERO, and VIRTUAL tokens. Following the exploit, the attacker consolidated the stolen assets into ETH and bridged the funds to Ethereum mainnet for distribution across multiple addresses. The attacker's primary address was identified as 0x02228b0afcdbEdf8180D96Fc181Da3AF5DD1d1ab. Security firm Halborn confirmed the root cause was not a smart contract vulnerability but rather inadequate private key security and governance design. The protocol offered no timelock delay on admin actions and no multisig requirement, meaning the single compromised key was sufficient to seize full protocol control.","heading":"April 2026 Multi-Chain Exploit","sources":[],"severity":"medium"},{"content":"Blockchain security firm BlockSec, via its Phalcon monitoring system, reported that preliminary on-chain traces suggest the wallets granted ADMIN_ROLE-related privileges during the exploit had previously been funded via Tornado Cash, the sanctioned Ethereum transaction mixer. According to BlockSec's public alert, these Tornado Cash-funded accounts actively participated in transactions across Wasabi Protocol's LongPool, ShortPool, and Vault contracts during the attack sequence. This connection is assessed as indicating premeditation, as the attacker used a privacy tool to obscure the origin of funds used to prepare and execute the exploit. The Tornado Cash connection has not been independently verified by regulatory authorities in available sources, but the BlockSec finding is treated as a credible on-chain intelligence indicator given the firm's established reputation in DeFi security monitoring.","heading":"Tornado Cash Funding Connections","sources":[],"severity":"medium"},{"content":"On-chain investigator ZachXBT publicly criticized Wasabi Protocol following the exploit, focusing on two areas. First, he questioned the security architecture, specifically why a single EOA held protocol-wide administrative authority without basic safeguards such as a multisig wallet or a DAO-governed admin role. ZachXBT argued this single point of failure was indefensible given industry norms in 2026. Second, ZachXBT alleged that the protocol had misappropriated project funds on influencer marketing campaigns, specifically citing payments to a prominent crypto key opinion leader (KOL) known as Kook. ZachXBT alleged these expenditures diverted resources that should have been allocated to development and security auditing. No specific payment amounts for influencer fees have been publicly disclosed. ZachXBT's criticisms were widely reported in crypto media as representing broader governance and financial management failures at the protocol.","heading":"ZachXBT Investigation and Criticism","sources":[],"severity":"medium"},{"content":"Multiple independent security firms, including Halborn, BlockSec (Phalcon), and Blockaid, assessed the Wasabi Protocol exploit as a governance and operational security failure rather than a smart contract code vulnerability. Identified deficiencies include: (1) The protocol's ADMIN_ROLE was controlled by a single externally owned account (wasabideployer.eth) with no co-signers. (2) The timelock delay for admin actions was set to zero, despite the underlying access control framework supporting timelock configuration. (3) No multisig wallet (such as Gnosis Safe) was employed for admin key management. (4) The UUPS upgrade pattern, while standard, was left unprotected by any governance delay, making a full protocol takeover possible in a single transaction once the key was compromised. Security researchers noted the design mirrored the Drift Protocol exploit on Solana (April 1, 2026, $285 million), in which North Korea-linked attackers similarly used a compromised admin key. The Wasabi attacker's identity and affiliation have not been publicly attributed by law enforcement or regulatory bodies as of the time of writing.","heading":"Security Architecture Failures","sources":[],"severity":"medium"},{"content":"Wasabi Protocol raised $3 million in seed funding in June 2024 led by Electric Capital, a prominent crypto venture firm. The participation of high-profile angel investors and crypto influencers in the seed round raised questions post-exploit about whether investor due diligence extended to operational security review. The exploit occurred during a particularly severe month for DeFi security, with April 2026 recording over $600 million in total DeFi losses across more than 25 incidents. Wasabi's losses of over $5 million represented a small fraction of the monthly total but were notable given the protocol's relatively modest size and its Electric Capital backing.","heading":"Investor and Market Context","sources":[],"severity":"medium"}],"timeline":[{"date":"2024-06-18","event":"Wasabi Protocol raises $3 million seed round led by Electric Capital, with participation from Alliance, Memeland, and several prominent crypto investors and influencers.","source":"","source_url":"https://www.theblock.co/post/300465/memecoin-leverage-trading-protocol-wasabi-funding"},{"date":"2026-04-30","event":"Wasabi Protocol suffers a multi-chain admin key compromise exploit. Attacker uses compromised wasabideployer.eth key to grant ADMIN_ROLE to a malicious contract and execute UUPS upgrades on core contracts across Ethereum, Base, Berachain, and Blast, draining over $5 million.","source":"","source_url":"https://www.halborn.com/blog/post/explained-the-wasabi-protocol-hack-april-2026"},{"date":"2026-04-30","event":"BlockSec Phalcon system alerts on $5.15M in abnormal Wasabi Protocol fund movements, reporting that preliminary traces link Tornado Cash-funded accounts to the ADMIN_ROLE grants used in the attack.","source":"","source_url":"https://x.com/Phalcon_xyz/status/2049772035736539516"},{"date":"2026-04-30","event":"CoinDesk reports the exploit as an apparent admin key compromise, estimating $4.5 million drained. The Block puts the figure at over $5 million based on multi-chain totals from security firms.","source":"","source_url":"https://www.coindesk.com/tech/2026/04/30/wasabi-protocol-drained-for-usd4-5-million-in-apparent-admin-key-compromise"},{"date":"2026-04-30","event":"ZachXBT publicly criticizes Wasabi Protocol's single-EOA admin architecture and alleges project funds were spent on influencer marketing (including KOL Kook) rather than security infrastructure.","source":"","source_url":"https://bitcoinworld.co.in/wasabi-hack-zachxbt-criticism/"},{"date":"2026-05","event":"Halborn publishes a technical post-mortem confirming root cause as private key security failure and governance design, not exploitable smart contract code. Attacker address 0x02228b0afcdbEdf8180D96Fc181Da3AF5DD1d1ab identified.","source":"","source_url":"https://www.halborn.com/blog/post/explained-the-wasabi-protocol-hack-april-2026","date_original":"2026-05-01"}],"sources_used":[],"source_tags":["zachxbt"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet","created_at":"2026-05-04T16:04:56.29474+00:00","updated_at":"2026-08-29T01:35:09.61+00:00"}}