<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[How exactly did the attacker execute the exploit wasabi?]]></title><description><![CDATA[<p dir="auto"><img src="/forum/assets/uploads/files/1777623937853-cce92f5f-7487-4eca-bf9b-b225589363ac-image.png" alt="cce92f5f-7487-4eca-bf9b-b225589363ac-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">The attacker identified that wasabideployer.eth was the sole address holding ADMIN_ROLE in Wasabi's PerpManager AccessManager, with no timelock or multisig protection. By calling grantRole on the deployer externally owned account with zero delay, the attacker instantly elevated their orchestrator contract to admin status. With admin control secured, they used the protocol's UUPS upgrade mechanism to replace the legitimate vault implementations with a malicious version that drained user balances. The entire attack chain from admin access to fund drainage was made possible by a single unprotected key holding the most powerful permission in the system.</p>
]]></description><link>https://undeads.com/forum/topic/19311/how-exactly-did-the-attacker-execute-the-exploit-wasabi</link><generator>RSS for Node</generator><lastBuildDate>Sun, 03 May 2026 18:48:47 GMT</lastBuildDate><atom:link href="https://undeads.com/forum/topic/19311.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 01 May 2026 08:25:39 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to How exactly did the attacker execute the exploit wasabi? on Fri, 01 May 2026 10:56:00 GMT]]></title><description><![CDATA[<p dir="auto">A single EOA holding ADMIN_ROLE with no timelock, no multisig, and no delay on grantRole is not a sophisticated vulnerability, it is a governance architecture failure that any security review should have flagged as a critical risk before deployment.</p>
]]></description><link>https://undeads.com/forum/post/53262</link><guid isPermaLink="true">https://undeads.com/forum/post/53262</guid><dc:creator><![CDATA[madtrader]]></dc:creator><pubDate>Fri, 01 May 2026 10:56:00 GMT</pubDate></item></channel></rss>