ZkLend was hacked and lost nearly $10,000, offering a 10% bonus in the hope that the hackers would return the funds

Decentralization借貸protocol zkLend encountered a hacker attack on February 12, with losses of up to 9 million dollars. The protocol offered a 10% reward to the attacker and will waive their legal responsibility if the remaining funds are returned before February 14.

zkLend was hacked for 9 million US dollars, and hacker funds were laundered through Railgun

According to the report of the blockchain security team SlowMist (SlowMist), the lending project zkLend on the Starknet chain was attacked by hackers, resulting in a loss of 9 million dollars.

SlowMist Security Alert

The lending project @zkLend on the Starknet chain was attacked today, with more than $9 million in assets lost!

The SlowMist security team found that the core reason for this attack lies in the safeMath library adopted by the market contract. When… pic.twitter.com/S3P73E4uxu

— SlowMist (@SlowMist_Team) February 12, 2025

The core reason for this attack lies in the safeMath program used in the market contract. When performing division calculations, direct division (direct division) is used, causing a vulnerability in rounding down when calculating the actual quantity of zToken to be burned during withdrawal operations. Attackers may exploit this vulnerability to illegally profit.

The team stated, "Please closely monitor the status of your assets on zkLend, and temporarily suspend deposits and other operations related to zkLend to avoid potential losses."

Subsequently, another cybersecurity company Cyvers also pointed out:

The attacker will transfer the stolen funds to the Ethereum blockchain and launder them through the privacy service Railgun. However, due to Railgun's protocol policy, these funds are eventually returned to the original address.

(What is RAILGUN? Privacy Pools: a new approach to innocent proof)

zkLend offers 10% bonus negotiation to hackers

After the attack, zkLend immediately issued a statement negotiating with the hackers for a 10% bonus, claiming that if the remaining funds are returned before February 14, all legal responsibilities will be waived.

We know that you are the mastermind behind today's attack on zkLend. You can keep 10% of the funds as a white hat hacker reward and return the remaining 90%, which is approximately 3,300 ETH.

At the same time, zkLend also stated that they have cooperated with security companies and law enforcement agencies. If they do not receive a response within 14 days, they will take further action to investigate and prosecute the attackers.

The affected users angrily criticized the team for allowing the funds to flow out

In response, victim user 0xYANGZAI expressed his dissatisfaction with StarkNet's official inaction on social media X, questioning whether there was insider involvement:

After being stolen for 12 hours, they still allowed the transfer of 1,800 ETH across the L2 and L1 cross-chain bridge, which inevitably raises suspicions of self-theft.

He said that he plans to go to Hong Kong to report the case this week, and calls on other victims to take action together, while urging an investigation into the DEX and CEX that have interacted with the hacker's address.

Hacker attacks are rampant in the field of encryption.

Looking back at Chainalysis' 2024 security incident report, the stolen funds have grown by about 21% compared to the same period last year, reaching $2.2 billion. Although the majority of stolen funds come from Decentralization finance (DeFi) services, the primary targets for theft in the second and third quarters are still centralized services.

In 2024, private key leaks are the main reasons for cryptocurrency theft (43.8%), with a large portion seemingly related to the rampant activities of North Korean hackers. They have successively infiltrated many cryptocurrency companies and disrupted their networks.

It is reported that the amount stolen by North Korean hackers from various crypto projects reached an all-time high, reaching $1.34 billion, accounting for 61% of the total amount stolen for the year.

(ZachXBT exposes North Korean hacker criminal network, posing as developer infiltration team to embezzle funds: earning $500,000 per month)

With the increasingly serious security issues of cryptocurrencies, the prevention of self-security awareness is particularly important.

This article zkLend was hacked and lost nearly tens of millions of dollars, offering a 10% bonus in hopes of hackers returning the funds first appeared on ChainNews ABMedia.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)