Wasabi Protocol says no final user compensation plan has been announced as its security incident response continues, leaving users waiting for clearer next steps.Read more...
This story is only covered by news sources that have yet to be evaluated by the independent media monitoring agencies we use to assess the quality and reliability of news outlets on our platform. Learn more here.
ChainCatcher reports that Wasabi Protocol has released a security incident update, stating that attackers exploited a configuration vulnerability in its AWS infrastructure's Spring Boot Actuator to steal private keys controlling EVM smart contracts and steal approximately $4.8 million in user funds and $900,000 in protocol vault funds. The attack chain originated from a public server used for analysis, whose Actuator heap dump was not properly p…