logo

EraLend Incident Analysis

ID: 46a4097e-765f-5d0b-8cb9-e632affcf6c9

STIX ID: report--46a4097e-765f-5d0b-8cb9-e632affcf6c9

Feed Name: CertiK Blog

Threat Score
70/100

Date Published: 2023-07-25

Date Updated: 2026-06-11

...
...

On 25 July 2023 CertiK and EraLend reported a security incident in which an attacker (EOA 0xf1D07) exploited a read-only reentrancy vulnerability in a Syncswap-based price oracle via a flash loan on zkSync Era, causing approximately $2.7M in losses; stolen funds were traced to multiple EOAs and bridged to Ethereum, Arbitrum, and Optimism. The report includes attacker tracing, recommendations to avoid deposits, and broader statistics highlighting a rise in flash-loan and reentrancy attacks in 2023.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.