logo

zkLend loses $9.5M in crypto heist, asks hacker to return 90%

ID: bd75be76-6bb7-5eb2-9e01-f180fa33d53e

STIX ID: report--bd75be76-6bb7-5eb2-9e01-f180fa33d53e

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-02-12

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

zkLend, a Starknet-based decentralized money-market protocol, was exploited via a rounding error in its smart contract mint() function allowing an attacker to drain approximately 3,600 ETH (~$9.5M). Starkware clarified the flaw was application-specific, the attacker attempted to launder funds via RailGun but was blocked, and zkLend publicly offered a 10% bounty if 90% (3,300 ETH) is returned; there is no attribution for the actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.