BPOI Banner
Crypto Hackers Stole Half as Much in August as They Did in July, Says Immunefi Crypto Hackers Stole Half as Much in August as They Did in July, Says Immunefi

DeFi Lending Platform zkLend Drained of $9.5 Million in Exploit

zkLend, a decentralized money lending platform on the Starknet blockchain, has fallen victim to a major exploit, with the hacker draining $9.5 million in crypto assets.

Blockchain security firm Cyvers confirmed that the stolen funds were initially bridged to Ethereum and funneled through the privacy protocol Railgun.

The funds were then redirected to the original address due to the protocol’s internal policies, Cyverse said on Monday.

Following the incident, zkLend paused all withdrawals and advised users to hold off on depositing or repaying loans while they investigated the incident.

The breach has raised alarm bells in the DeFi space, as it comes as a part of growing security concerns within the sector. Cybercriminals have already stolen over $110 million from blockchain projects this year, according to DeFiLlama data.

zkLend reached out to the hacker with an on-chain message offering a 10% “white hat” bounty in exchange for the return of the remaining funds—amounting to 3,300 ETH (roughly $8.78 million).

“Upon receiving the transfer, we agree to release from any and all liability regarding the attack,” the platform informed.

zkLend set a strict deadline of Feb. 14 for the hacker to comply, warning that legal action would be taken if the funds were not returned.

The lending platform said they are already working with law enforcement and several security firms—including StarkWare, Starknet Foundation, Binance Security—to trace the stolen funds and catch the hacker.

“This was one of the biggest hacks on Starknet if not the biggest in recent years,” Preetam Rao, CEO and Co-founder of web security firm QuillAudits, told Decrypt. “Good to see zkLend is being transparent throughout the situation also offered a bounty to the hacker.”

The root cause of the hack doesn’t seem to be in the proof system, but rather in the contract logic,” Rao said, noting his team is reviewing the incident to prevent similar issues in other protocols.

Speaking to Decrypt, Meir Dolev, Co-founder and CTO of Cyvers, noted: “This incident highlights security risks in DeFi lending and raises concerns about the safety of protocols on Starknet’s zero-knowledge rollup infrastructure.”

Unlike traditional coin mixers such as Tornado Cash, which pools and redistribute funds to obscure their origin, the zkLend hackers used Railgun which integrates privacy features directly into DeFi applications, ensuring users’ anonymity while interacting with the blockchain.

“We are committed to full transparency and will share a comprehensive post-mortem analysis as soon as it is completed,” the team tweeted, urging users to remain patient as they work through the incident.

At the Web3 Summit 2024, ImmuneFi founder Mitchell Amador shared his thoughts with Decrypt, calling DeFi hacking “an infinitely sustainable and viable business.” But he added that the crypto space is “unquestionably” getting safer.

DeFi hackers, he said, were “looking for more damage, more than ever—and their skills are also applicable in a number of different areas.”

Edited by Stacy Elliott.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



Source link

Vismaya V

https://decrypt.co/305590/defi-lending-platform-zklend-9-million-exploit

2025-02-12 16:06:10

bitcoin
Bitcoin (BTC) $ 82,208.03 0.45%
ethereum
Ethereum (ETH) $ 1,561.56 1.85%
tether
Tether (USDT) $ 0.999685 0.00%
xrp
XRP (XRP) $ 2.01 0.91%
bnb
BNB (BNB) $ 583.02 1.13%
solana
Solana (SOL) $ 118.20 3.69%
usd-coin
USDC (USDC) $ 1.00 0.00%
dogecoin
Dogecoin (DOGE) $ 0.158008 1.34%
tron
TRON (TRX) $ 0.236788 1.97%
cardano
Cardano (ADA) $ 0.624791 0.89%
staked-ether
Lido Staked Ether (STETH) $ 1,558.67 1.94%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 82,240.03 0.79%
leo-token
LEO Token (LEO) $ 9.41 0.14%
chainlink
Chainlink (LINK) $ 12.50 1.34%
avalanche-2
Avalanche (AVAX) $ 18.83 4.76%
usds
USDS (USDS) $ 1.00 0.01%
hedera-hashgraph
Hedera (HBAR) $ 0.172358 1.03%
stellar
Stellar (XLM) $ 0.235089 0.65%
the-open-network
Toncoin (TON) $ 2.92 1.80%
sui
Sui (SUI) $ 2.17 1.73%
shiba-inu
Shiba Inu (SHIB) $ 0.000012 0.61%
wrapped-steth
Wrapped stETH (WSTETH) $ 1,872.15 1.58%
mantra-dao
MANTRA (OM) $ 6.40 4.30%
bitcoin-cash
Bitcoin Cash (BCH) $ 302.28 3.00%
litecoin
Litecoin (LTC) $ 76.08 3.47%
polkadot
Polkadot (DOT) $ 3.52 0.98%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999067 0.03%
bitget-token
Bitget Token (BGB) $ 4.28 0.19%
ethena-usde
Ethena USDe (USDE) $ 0.998891 0.03%
hyperliquid
Hyperliquid (HYPE) $ 14.98 6.72%
weth
WETH (WETH) $ 1,560.16 1.75%
pi-network
Pi Network (PI) $ 0.60514 1.83%
whitebit
WhiteBIT Coin (WBT) $ 27.92 0.20%
monero
Monero (XMR) $ 202.06 1.49%
wrapped-eeth
Wrapped eETH (WEETH) $ 1,660.50 1.77%
okb
OKB (OKB) $ 53.20 0.21%
uniswap
Uniswap (UNI) $ 5.21 1.09%
dai
Dai (DAI) $ 1.00 0.01%
susds
sUSDS (SUSDS) $ 1.05 0.15%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 82,205.03 0.42%
aptos
Aptos (APT) $ 4.76 4.66%
pepe
Pepe (PEPE) $ 0.000007 1.69%
ondo-finance
Ondo (ONDO) $ 0.881828 5.23%
gatechain-token
Gate (GT) $ 21.95 0.39%
tokenize-xchange
Tokenize Xchange (TKX) $ 31.54 1.15%
near
NEAR Protocol (NEAR) $ 2.05 0.64%
internet-computer
Internet Computer (ICP) $ 4.95 0.63%
crypto-com-chain
Cronos (CRO) $ 0.08665 0.22%
blackrock-usd-institutional-digital-liquidity-fund
BlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00 0.00%
mantle
Mantle (MNT) $ 0.689224 0.09%
bitcoin
Bitcoin (BTC) $ 82,208.03 0.45%
ethereum
Ethereum (ETH) $ 1,561.56 1.85%
tether
Tether (USDT) $ 0.999685 0.00%
xrp
XRP (XRP) $ 2.01 0.91%
bnb
BNB (BNB) $ 583.02 1.13%
solana
Solana (SOL) $ 118.20 3.69%
usd-coin
USDC (USDC) $ 1.00 0.00%
dogecoin
Dogecoin (DOGE) $ 0.158008 1.34%
tron
TRON (TRX) $ 0.236788 1.97%
cardano
Cardano (ADA) $ 0.624791 0.89%
staked-ether
Lido Staked Ether (STETH) $ 1,558.67 1.94%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 82,240.03 0.79%
leo-token
LEO Token (LEO) $ 9.41 0.14%
chainlink
Chainlink (LINK) $ 12.50 1.34%
avalanche-2
Avalanche (AVAX) $ 18.83 4.76%
usds
USDS (USDS) $ 1.00 0.01%
hedera-hashgraph
Hedera (HBAR) $ 0.172358 1.03%
stellar
Stellar (XLM) $ 0.235089 0.65%
the-open-network
Toncoin (TON) $ 2.92 1.80%
sui
Sui (SUI) $ 2.17 1.73%
shiba-inu
Shiba Inu (SHIB) $ 0.000012 0.61%
wrapped-steth
Wrapped stETH (WSTETH) $ 1,872.15 1.58%
mantra-dao
MANTRA (OM) $ 6.40 4.30%
bitcoin-cash
Bitcoin Cash (BCH) $ 302.28 3.00%
litecoin
Litecoin (LTC) $ 76.08 3.47%
polkadot
Polkadot (DOT) $ 3.52 0.98%
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999067 0.03%
bitget-token
Bitget Token (BGB) $ 4.28 0.19%
ethena-usde
Ethena USDe (USDE) $ 0.998891 0.03%
hyperliquid
Hyperliquid (HYPE) $ 14.98 6.72%
weth
WETH (WETH) $ 1,560.16 1.75%
pi-network
Pi Network (PI) $ 0.60514 1.83%
whitebit
WhiteBIT Coin (WBT) $ 27.92 0.20%
monero
Monero (XMR) $ 202.06 1.49%
wrapped-eeth
Wrapped eETH (WEETH) $ 1,660.50 1.77%
okb
OKB (OKB) $ 53.20 0.21%
uniswap
Uniswap (UNI) $ 5.21 1.09%
dai
Dai (DAI) $ 1.00 0.01%
susds
sUSDS (SUSDS) $ 1.05 0.15%
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 82,205.03 0.42%
aptos
Aptos (APT) $ 4.76 4.66%
pepe
Pepe (PEPE) $ 0.000007 1.69%
ondo-finance
Ondo (ONDO) $ 0.881828 5.23%
gatechain-token
Gate (GT) $ 21.95 0.39%
tokenize-xchange
Tokenize Xchange (TKX) $ 31.54 1.15%
near
NEAR Protocol (NEAR) $ 2.05 0.64%
internet-computer
Internet Computer (ICP) $ 4.95 0.63%
crypto-com-chain
Cronos (CRO) $ 0.08665 0.22%
blackrock-usd-institutional-digital-liquidity-fund
BlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00 0.00%
mantle
Mantle (MNT) $ 0.689224 0.09%