Skip to content
← Back to newsFrom Hacker to Victim: The zkLend Heist Takes an Unexpected Turn
Security

From Hacker to Victim: The zkLend Heist Takes an Unexpected Turn

By ToTo BugelmanNewcomer0 rep· 4/1/2025

In a bizarre twist of events, the hacker responsible for the $9.6 million exploit of the decentralized lending protocol zkLend has claimed to have lost a significant portion of the stolen funds to a phishing site masquerading as Tornado Cash. This incident has sparked discussions about the ethics of hacking and the consequences of cybercrime.

 

Etherscan

 

Key Takeaways

  • The zkLend hacker lost 2,930 ETH (approximately $5.4 million) to a phishing scam.

  • The hacker expressed remorse and requested assistance in recovering the lost funds.

  • zkLend had previously offered a bounty for the return of stolen funds, which the hacker ignored.

 

The Initial Exploit

In February 2025, zkLend, a decentralized lending protocol built on the Starknet network, fell victim to a significant exploit. The hacker exploited a vulnerability in the smart contract, making off with 3,600 ETH. Following the attack, zkLend attempted to negotiate with the hacker, offering a 10% bounty for the return of the stolen funds, but received no response.

 

The Phishing Incident

On March 31, the hacker attempted to launder the stolen funds through what they believed was Tornado Cash. However, they inadvertently deposited the funds into a phishing site that impersonated the legitimate service. In a message sent via Etherscan, the hacker lamented their mistake, stating, "I tried to move funds to Tornado, but I used a phishing website, and all the funds have been lost. I am devastated."

 

Etherscan

 

Community Reactions

The crypto community has reacted with a mix of amusement and skepticism. Some have dubbed the incident a case of poetic justice, while others question the authenticity of the hacker's remorse. The hacker's plea for help has led to speculation about whether this is a genuine cry for assistance or a strategic move to divert attention from their actions.

 

zkLend's Response

In response to the hacker's message, zkLend urged the individual to return any remaining funds in their wallets. However, subsequent transactions indicated that the hacker continued to transfer ETH to other wallets, raising further questions about their intentions. The zkLend team has not yet made an official statement regarding the hacker's plea for help.

 

The Bigger Picture

This incident is part of a larger trend of high-profile cryptocurrency exploits. In February alone, losses from crypto scams and hacks totaled over $33 million, with the zkLend attack being one of the most notable. The ongoing battle against cybercrime in the crypto space highlights the need for enhanced security measures and greater awareness among users.

As the situation unfolds, the crypto community remains vigilant, watching to see if zkLend will collaborate with law enforcement to investigate the phishing site and potentially recover the lost funds. The zkLend hacker's story serves as a cautionary tale about the risks of the digital currency landscape, where the line between victim and perpetrator can blur in an instant.

 

Sources

 

This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.

From Hacker to Victim: The zkLend Heist Takes an Unexpected Turn | BlockzHub