#Gate廣場五月交易分享 【Wasabi Protocol Losses Approximately $900k in an Attack】



According to the security incident update released by Wasabi Protocol, attackers exploited a Spring Boot Actuator configuration vulnerability in its AWS infrastructure to steal control of the EVM smart contract private keys, resulting in the theft of about $4.8 million in user funds and $900k in protocol treasury funds, totaling approximately $5.7 million in losses. The attack chain began with a public server whose Actuator heap dump was unprotected by a password, allowing attackers to obtain credentials for another server and control the smart contract private keys. The incident only affected EVM deployments, including some vaults on Ethereum, Base, Blast, and Berachain; Solana deployments and Prop AMM were not affected. The team has not yet confirmed a user compensation plan and will update the investigation progress on the Discord community.
ETH1.27%
BLAST2.94%
BERA4.29%
SOL2.13%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin