Wasabi Protocol updates on security incident response progress: final user compensation plan has not yet been confirmed

robot
Abstract generation in progress

Deep Tide TechFlow News, May 09 — Wasabi Protocol released a security incident update, stating that attackers exploited a Spring Boot Actuator configuration vulnerability in their AWS infrastructure to steal private keys controlling EVM smart contracts, and stole approximately $4.8 million in user funds and $900k in protocol treasury funds from related contracts, with total losses of about $5.7 million.

The attack chain started from a public server used for analysis, whose Actuator heap dump was not protected by a proper password, allowing attackers to obtain credentials for another server, ultimately gaining control of the smart contract private keys. This incident only affected EVM deployments, including some vaults on Ethereum, Base, Blast, and Berachain; Solana deployments and Prop AMM were not affected. A final update on user compensation plans has not yet been provided, but “ensuring all affected users are compensated” remains the team’s top priority. Future updates on the investigation progress will be posted on the Discord community.

ETH0.62%
SOL0.98%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin