Wasabi Protocol updates on security incident response: no final user compensation plan has been reached yet

robot
Abstract generation in progress

BlockBeats News, May 10 — Wasabi Protocol released an update on a security incident, stating that attackers exploited a Spring Boot Actuator configuration vulnerability in their AWS infrastructure to steal control of private keys for EVM smart contracts and stole approximately $4.8 million in user funds and $900k in protocol treasury funds from related contracts.

The attack chain began with a public server used for analysis, whose Actuator heap dump was not protected by a proper password, allowing attackers to obtain credentials for another server and ultimately gain control of the smart contract private keys. This incident only affected EVM deployments, including some vaults on Ethereum, Base, Blast, and Berachain. Deployments on Solana and Prop AMM were not affected.

Wasabi Protocol stated that they have not yet finalized a compensation plan for users, but “ensuring all affected users are compensated” remains the team’s top priority. They will provide updates on the investigation progress via their Discord community.

ETH0.56%
BLAST2.44%
BERA0.17%
SOL0.27%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin