← Back to list

The $9.5M zkLend Heist: A Hacker’s Precision, A DeFi Dilemma

In the dynamic and often unpredictable realm of decentralized finance (DeFi), the quest for robust security is an ongoing battle. Recently…

Deven Chhajed · 2025-04-03 03:31 · 0 claps · 3.8 min read
#zklend #defi-exploits #defi-security #smart-contract-hacking
Open on Medium ↗
Wiki topics: CRY · Crypto & Web3 🔒 · Cybersecurity 🥊 · Combat Sports

The $9.5M zkLend Heist: A Hacker’s Precision, A DeFi Dilemma

In the dynamic and often unpredictable realm of decentralized finance (DeFi), the quest for robust security is an ongoing battle. Recently, zkLend, a DeFi lending protocol built on Starknet, found itself at the center of a devastating exploit. A subtle yet critical rounding error bug led to an attacker siphoning approximately $9.5 million worth of Ethereum (3,600 ETH) from the platform.

However, what makes this incident even more intriguing is zkLend’s response — a public plea to the hacker, offering a 10% bounty in exchange for returning the remaining funds. Is this a smart damage control tactic or does it expose the vulnerabilities of DeFi’s security infrastructure? Let’s break down the exploit, zkLend’s actions and what this means for DeFi’s future.

What Happened?

At the heart of the exploit was a rounding error in zkLend’s smart contract logic. Rounding errors occur when computational calculations involve floating-point numbers that cannot be perfectly represented in binary. Even minute discrepancies can accumulate over multiple transactions, creating an exploitable flaw.

In zkLend’s case, this flaw was embedded within the mint() function, which is responsible for issuing liquidity provider (LP) tokens in exchange for deposits. The attacker leveraged these discrepancies to manipulate the “lending_accumulator” variable, which plays a crucial role in interest calculations and token issuance.

How the Hacker Exploited It

The attacker devised a precision rounding exploit — a methodical approach to exploiting computational errors. The process unfolded as follows:

  1. Inflating the Lending Accumulator — The attacker artificially amplified the rounding error by manipulating the lending_accumulator variable to an extremely high value.
  2. Repeated Deposits & Withdrawals — By repeatedly depositing and withdrawing small amounts of wrapped staked Ethereum (wstETH), the attacker extracted slightly more than they originally deposited each time.
  3. Draining zkLend’s Funds — Over thousands of transactions, this rounding discrepancy compounded, ultimately allowing the attacker to withdraw 3,600 ETH ($9.5 million) from zkLend’s reserves.

This kind of exploit is particularly insidious because it doesn’t rely on traditional attack vectors like reentrancy bugs or flash loans, making it harder to detect.

Smart Contract Security Implications

This incident highlights key areas where smart contract security needs drastic improvement:

  • Rigorous Audits — Traditional code audits often focus on logic flaws and reentrancy vulnerabilities, but subtle computational errors like rounding discrepancies demand deeper scrutiny.
  • Formal Verification — A mathematical approach that proves the correctness of smart contract logic before deployment, reducing the risk of hidden exploits.
  • Defensive Programming — Implementing checks and fail-safes that prevent attackers from amplifying minor errors into major vulnerabilities.

Layer 2 Security Risks

Since zkLend operates on Starknet, an Ethereum Layer 2 scaling solution, it benefits from enhanced speed and lower gas fees. However, Layer 2 solutions also introduce additional security risks, including:

  • Bridging Vulnerabilities — Moving assets between Layer 1 and Layer 2 creates potential weak points.
  • Contract Complexity — Layer 2 interactions often involve additional computation, making it harder to identify security flaws.

This exploit demonstrates that while scalability solutions improve efficiency, they can also introduce new attack surfaces if not carefully audited.

Immediate Mitigation Measures

Upon detecting the exploit, zkLend swiftly paused withdrawals, advising users to refrain from depositing additional funds. The team then partnered with blockchain forensic firms to track the hacker’s transactions across the Ethereum network.

The Bounty Offer — A Tactical Move?

Instead of immediately resorting to legal measures, zkLend issued a public appeal to the hacker:

  • Return 90% of the stolen funds and keep 10% (~330 ETH) as a bounty.
  • No legal consequences if the deadline of February 13, 2025 is met.
  • If ignored, zkLend vowed to pursue legal action in collaboration with security firms and law enforcement agencies.

This approach is a calculated risk — while it may recover funds, it also raises ethical questions about whether DeFi protocols should negotiate with attackers.

https://x.com/zkLend/status/1889515118368829559 [Source: X.com]

https://x.com/zkLend/status/1889515118368829559 [Source: X.com]

The Aftermath of zkLend’s Bounty Offer

The February 13, 2025, deadline passed with zero response from the hacker — no funds were returned. In retaliation, zkLend escalated its approach:

🚨 $500,000 Bounty — A reward for any information leading to the hacker’s identification and arrest. 💰 User Recovery Portal — Launched on March 5, 2025, allowing affected users to claim compensation from zkLend’s Recovery Pool.

👉 For affected users: Claims can be submitted via the zkLend Recovery Portal.

Broader DeFi Security Concerns

Lessons for DeFi Protocols

  • Security-First Approach — DeFi projects must prioritize continuous audits, stress testing and real-time anomaly detection.
  • Enhanced Bug Bounties — Offering substantial rewards for ethical hackers to uncover vulnerabilities before criminals do.
  • Greater Accountability — The anonymity of DeFi should not come at the cost of security. Implementing identity-verified smart contract deployers could mitigate malicious intent.

Lessons for DeFi Users

As an investor or user in the DeFi space, you should:

  • Diversify Your Holdings — Never put all your assets in a single protocol.
  • Monitor Protocol Security — Check for audit reports and community feedback before depositing funds.
  • Use Revoke.cash — Regularly revoke smart contract approvals to limit exposure to potential exploits.

If DeFi is to achieve mainstream adoption, protocols must strike a balance between innovation and impenetrable security. This requires collaboration between developers, auditors and users to create a safer financial landscape.

Stay One Step Ahead of Cybercriminals!

🔹 The best defense is staying informed and proactive!

🔹 Follow me for more insights on the latest cyber threats, attack trends and security best practices.

🔗 Let’s **connect **and fortify our digital world together!


메타데이터
post_id
d7a4ce045201
slug
the-9-5m-zklend-heist-a-hackers-precision-a-defi-dilemma-d7a4ce045201
url
https://medium.com/@devenchhajed24/the-9-5m-zklend-heist-a-hackers-precision-a-defi-dilemma-d7a4ce045201
canonical_url
https://medium.com/@devenchhajed24/the-9-5m-zklend-heist-a-hackers-precision-a-defi-dilemma-d7a4ce045201
author_url
https://medium.com/@devenchhajed24
status
ok
fetched_at
2026-07-20 11:00:29