zkLend suffers cyber attack, losses up to $9 million

Source of this Article
BinBits 2 months ago 446

Fast-growing decentralized lending protocol, zkLend has suffered a cyber attack on the Starknet network. According to blockchain security outfit, Cyvers, the platform lost about $4.9 million to the hack.

🚨ALERT🚨@zkLend has suffered a $9.5M exploit on the Starknet network. Stolen funds were bridged to #Ethereum and laundered via #Railgun, but due to protocol policies, the funds were returned to the original address by #Railgun!
Deposit to #Railgun:… https://t.co/0muIH2TArY

— 🚨 Cyvers Alerts 🚨 (@CyversAlerts) February 12, 2025

Cyvers through a post via X on Wednesday provided insight into the attack. The firm revealed how the attackers bridged the funds to Ethereum before laundering it with Railgun. 

However, Cyvers explained how protocol rules made Railgun return the funds to the original address. An on-chain message to the hacker by zkLend revealed that the attack claimed more than $9 million from the lending protocol. 

The recent attack on zkLend further strengthened questions about the security of blockchain solutions. Hackers were on a rampage in 2024, stealing $2.3 billion through 165 attacks. 

The staggering figure reflects a 40% increase compared to the $1.69 billion looted from the industry in 2023. Heading into the new year, bad actors have stolen above $73 million across 19 exploits in January. 

Significantly, Phemex exchange contributed massively to the figure as a Binbits report revealed that the platform lost about $69 million to a cyber attack during the month. 

It is worth mentioning that the native token of zkLend, ZEND reacted to the hack. In the last 24 hours, the coin dipped by 17%, reflecting a lengthy downturn for ZEND. 

Before the hack, ZEND had been struggling to gain traction losing more than 48.7% of its value in the last 30 days. The recent attack on zkLend quenched hopes of a potential rebound for the token. 

zkLend offers bounty 

Meanwhile, zkLend is offering 10% of the stolen funds as a bounty to the hacker through an onchain message. The lending platform urged the attackers to return the stolen funds promising not to take any further legal action. 

To the hacker:

We understand that you are responsible for today’s attack on zkLend. You may keep 10% of the funds as a whitehat bounty, and send back the remaining 90%, or 3,300 ETH ($1,805.23) to be exact, to this Ethereum address: 0xCf31e1b97790afD681723fA1398c5eAd9f69B98C.

Upon… pic.twitter.com/piEVPDHZd4

— zkLend (@zkLend) February 12, 2025

The firm went on to emphasize that the deal is only valid till February 14, 2025, 00:00 UTC. Furthermore, zkLend revealed how it is working with law enforcement agencies to investigate the issue. 

Similarly, the protocol promises to track and prosecute the hackers if they fail to accept the offer. Additionally, in a post, the Starknet-based protocol said it is tracking the funds and exercising all available options to nail the hackers. 

zkLend said it is closely working with firms like Binance Security Team, Hypernative Labs, Starknet Foundation, Zero Shadow, and StarkWare. 

To our users:

We are actively tracking the funds and pursuing the identification of the hacker, in collaboration with @StarkWareLtd, the @StarknetFndn, @zeroshadow_io (formerly @chainalysis Incident Response), Binance Security Team, and @HypernativeLabs.

We are committed to…

— zkLend (@zkLend) February 12, 2025

Read More:

  • UK omits crypto staking under new investment law
  • IMF advises Kenya to amend crypto regulations
  • Hyperliquid debunks validators and centralization rumors

The post zkLend suffers cyber attack, losses up to $9 million appeared first on BinBits.



Facebook X WhatsApp LinkedIn Pinterest Telegram Print Icon


BitRss shares this Content always with Attribution-NonCommercial-ShareAlike 4.0 International (CC BY-NC-SA 4.0) License.

Read Entire Article


Screenshot generated in real time with SneakPeek Suite

BitRss World Crypto News | Market BitRss | Short Urls
Design By New Web | ScriptNet