Wasabi Protocol Updates Progress on Security Incident Handling
TechFlame
2026-05-09 11:46
TechFlame2026-05-09 11:46
English
TechFlame News — Wasabi Protocol has released an update on a security incident, stating that an attacker exploited a Spring Boot Actuator configuration vulnerability in its AWS infrastructure to steal the private keys controlling its EVM smart contracts. The attacker then drained approximately $4.8 million in user funds and $900,000 from the protocol’s treasury, resulting in total losses of roughly $5.7 million. The attack chain began with a public-facing server used for analysis, whose Actuator heap dump was not properly password-protected. This allowed the attacker to obtain credentials for another server, ultimately gaining control of the smart contract private keys. The incident only affected EVM deployments, including certain vaults on Ethereum, Base, Blast, and Berachain, while Solana deployments and Prop AMM remained unaffected. No final update on user compensation has been provided yet, but the team has stated that "making all affected users whole" remains its top priority, and further investigation updates will be shared on its Discord community.