Wasabi Protocol Hack: 5M$ Cross-Chain Attack
DeFi derivatives platform Wasabi Protocol suffered a cross-chain attack, with hackers stealing assets worth more than 5 million dollars. PeckShield confirmed that the incident spread across Ethereum, Base, Berachain, and BLAST detailed analysis networks. According to Blockaid and CertiK, the attacker infiltrated Wasabi‘s deployer wallet with a compromised admin key, upgraded core systems, and drained the funds. As a result, liquidity pools from LongPool, ShortPool, and Vault contracts were targeted. The attacker’s Tornado Cash-linked accounts gained access to admin roles. Stolen Assets and Hackers Traces Security firms PeckShield, Blockaid, CertiK, BlockSec, and Cyvers reported the attacks traces in detail. Cyvers noted that the hacker withdrew assets like WETH, PEPE, MOG, USDC, ZYN, REKT, cbBTC, AERO, and VIRTUAL, converted them to ETH, bridged to Ethereum, and distributed them to various addresses. Blockaid emphasized that all Wasabi/Spicy LP-share tokens are at risk; underlying assets have been drained or still pose a danger.WETH and USDC: Main liquidity sourcesPEPE, MOG: Meme coin poolsOthers: ZYN, REKT, cbBTC Affected Protocols and User Warnings Virtuals Protocol announced that its own security remains intact while freezing Wasabi-backed margin deposits as a precaution. The Wasabi team announced on X that they have initiated an investigation and advised users to avoid interacting with contracts.