DeFi protocol Wasabi hacked and more than USD 5 million stolen

Foto del autor

By TP

The team behind decentralized finance (DeFi) protocol Wasabi confirmed that its platform was hacked today, April 30: “We are aware of the issue and are actively investigating it. As a precaution, please do not interact with Wasabi contracts until further notice. Although the statement from Wasabi did not offer details, at the time of writing, as reported by security firms PeckShield, Blockaid, CertiK and BlockSec, the attacker drained up to USD 5.5 million on the Ethereum, Base, Berachain and Blast networks. The exploit occurred because the hacker managed to take administrative control of the protocol after compromising Wasabi’s main wallet, which is the account with the highest administrative permissions on the protocol. With the key in your possession, the attacker gave himself the administrator rolemodified the contracts that guard users’ funds and introduced a malicious version that transferred those funds to their own addresses. The researchers did not confirm how the attacker obtained the key to that Wasabi wallet. The developer known in X as Vadim added that the Wasabi contract worked exactly as designed and that the problem was not a bug in the code, but an architectural decision. The protocol concentrated administrative control in a single wallet, without requiring multiple signatures or a waiting period before executing critical changes. Anyone who obtained that key could modify the protocol instantly, without restrictions.

How were Wasabi users affected?

Wasabi allows you to deposit assets in liquidity vaults in exchange for returns. By doing so, the protocol delivers LP (liquidity provider) tokens, which function as digital receipts that represent the user’s participation in that vault and allow them to withdraw their capital plus accumulated profits. It was exactly those vaults that the attacker emptied by taking administrative control of the protocol, according to Blockaid analysts. The LP tokens that users keep in their wallets continue to show value on the screen, but according to Blockaid their redemption value is zero: the funds that backed them are no longer there.

Cryptocurrency operations in the Ethereum ecosystem.Transactions sent by the Wasabi attacker with which he perpetuated the hack. Source: etherscan. Vadim confirmed that, after the drain, the Wasabi team managed to revoke the attacker’s permissions, so a second attack by the same vector would not be possible. The stolen funds, however, remain in the attacker’s wallets. Finally, the Berachain team explained that “if you have funds in Wasabi, withdraw them now.” From the Blockaid team, for its part, recommend immediately revoking any active approval to Wasabi contracts to prevent the attacker from accessing additional funds.

0