Loading...
[Wasabi Protocol Suffers Attack, Losing Approximately $5.7 Million] According to a security incident update released by Wasabi Protocol, attackers exploited a Spring Boot Actuator configuration vulnerability in its AWS infrastructure to steal private keys controlling EVM smart contracts. This resulted in the theft of approximately $4.8 million in user funds and $900,000 from the protocol's treasury, with total losses amounting to around $5.7 million. The attack chain began with a public-facing server whose Actuator heap dump was not password-protected, allowing attackers to obtain credentials for another server and gain control of the smart contract private keys. The incident only affected EVM deployments, including vaults on Ethereum, Base, Blast, and Berachain. Deployments on Solana and the Prop AMM were not impacted. The team has not yet confirmed a compensation plan for users and will provide updates on the investigation's progress via the Discord community.