Skip to content
← Back to newszkLend Hit By $4.9 Million Starknet Exploit, Offers Hacker Bounty
Security

zkLend Hit By $4.9 Million Starknet Exploit, Offers Hacker Bounty

By ToTo BugelmanNewcomer0 rep· 2/12/2025

Decentralized lending protocol zkLend has suffered a significant setback, losing approximately $4.9 million in a recent exploit on the Starknet network. In an unusual move, the protocol has offered a bounty to the hacker in hopes of recovering the stolen funds before a specified deadline.

 

Key Takeaways

  • zkLend lost $4.9 million due to a Starknet exploit.

  • The protocol has offered a 10% bounty to the hacker for returning the funds.

  • The stolen funds were laundered through Ethereum using Railgun.

  • Security experts warn of a potential increase in crypto hacks in 2025.

 

The Exploit Details

On February 12, 2025, zkLend was targeted in a sophisticated attack that resulted in the loss of nearly $5 million. According to blockchain security firm Cyvers, the stolen funds were bridged to Ethereum and subsequently laundered via Railgun. However, due to the protocol's policies, the funds were returned to the original address by Railgun, highlighting a potential flaw in the exploit process.

 

Source: Cyvers Alerts

 

In response to the attack, zkLend has publicly acknowledged the hacker's actions and offered a 10% bounty, amounting to approximately $490,000, if the remaining funds are returned by February 14, 2025. The protocol stated:

"We understand that you are responsible for today’s attack on zkLend. You may keep 10% of the funds as a whitehat bounty, and send back the remaining 90%, or 3,300 ETH to be exact."

 

Source: zkLend

 

Security Measures and Future Implications

The zkLend team is currently collaborating with security firms and law enforcement to address the situation. They have warned the hacker that if they do not respond by the specified deadline, they will take further steps to track and prosecute the individual responsible for the exploit.

Despite a reported 44% decrease in crypto hacks year-over-year in January 2025, the total amount stolen still exceeded $73 million. This incident raises concerns among security experts about the potential for another year of significant hacking activity, especially considering that $2.3 billion was stolen across 165 incidents in 2024.

 

The Changing Landscape of Crypto Hacks

Interestingly, some hackers have shown a change of heart after stealing large sums of cryptocurrency. In a notable case from May 2024, an attacker returned $71 million worth of Ether tokens following a wallet poisoning scam that garnered significant media attention. This incident illustrates the unpredictable nature of crypto exploits and the potential for recovery in certain cases.

 

Preventative Measures

To combat the rising tide of crypto hacks, blockchain security firms like Cyvers are exploring innovative solutions. One promising approach is offchain transaction validation, which could potentially prevent up to 99% of crypto hacks by simulating and validating transactions in a secure offchain environment. This proactive strategy aims to bolster the security of decentralized finance (DeFi) platforms and protect users from future exploits.

As the crypto landscape continues to evolve, the zkLend incident serves as a stark reminder of the vulnerabilities that exist within decentralized protocols and the ongoing battle between security measures and malicious actors in the digital currency space.

 

Sources

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.