ZKSync-based Era Lend suffers $3.4 million loss in DeFi exploit

TL;DR Breakdown

  • Era Lend, a lending protocol on the zkSync network, suffered a $3.4 million loss due to a ‘read-only reentrancy attack’, which allowed the attacker to withdraw funds repeatedly.
  • The attack also impacted the stablecoin USDC+, issued by the Overnight Finance protocol, resulting in a potential loss of over $261,000.
  • In response, Era Lend paused its zkSync contracts to prevent further exploits, highlighting the ongoing security challenges in the DeFi sector.

Description

According to a recent report by blockchain security firm BlockSec, Era Lend, a decentralized lending protocol operating on the zkSync Layer 2 network, has fallen victim to a ‘read-only reentrancy attack’ resulting in a loss of $3.4 million.  The attacker exploited a vulnerability that allowed repeated calls to a function within a single transaction, withdrawing … Read more

According to a recent report by blockchain security firm BlockSec, Era Lend, a decentralized lending protocol operating on the zkSync Layer 2 network, has fallen victim to a ‘read-only reentrancy attack’ resulting in a loss of $3.4 million. 

The attacker exploited a vulnerability that allowed repeated calls to a function within a single transaction, withdrawing more funds than they were entitled to. Also, the exploit involved manipulating a contract to report outdated values that hadn’t been updated yet, taking advantage of a faulty price oracle that Era Lend relied upon.

The impact and response

The attack had repercussions on the stablecoin USDC+, issued by the Overnight Finance protocol, resulting in a potential loss of over $261,000, which represents 7.86% of the total value of the collateral supporting the stablecoin. 

In response to the attack, Era Lend paused the protocol’s zkSync contracts to prevent further exploits. The team also advised users that only the USDC pool was compromised. According to an official statement on Discord, the Era Lend team assured that the security of other assets remains intact—but borrowing operations on the platform have been temporarily halted.

“We have detected and confirmed a cyber attack on our platform. We want to assure you that the attack has been contained, and the threat actor can no longer continue their actions.”

Era Lend Team

The Era Lend exploit has raised concerns for other projects based on the Syncswap project, from which Era Lend is a fork. Security analysts have warned that these projects might also be susceptible to similar exploits. The incident underscores the need for auditors to utilize specialized software to identify these vulnerabilities more effectively, as read-only reentrancy attacks can evade traditional scrutiny and remain harder to identify during auditing processes.

Era Lend operates on the zkSync network, an Ethereum layer-2 rollup utilizing zero-knowledge proofs. As of April, the total value locked in the zkSync network surpassed $110 million. Despite the recent exploit, the network’s developers have ambitious plans to establish an ecosystem of interoperable chains named “Hyperchains” by December 2023.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:ZKSync-based Era Lend suffers $3.4 million loss in DeFi exploit

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年7月26日 17:11
Next 2023年7月26日 18:31

Related articles

  • Block Earner unveils new crypto-backed loan for Australian market despite crypto unclarity

    TL;DR Breakdown Block Earner, an Australian fintech company, is moving forward with its plans to launch a cryptocurrency-backed loan product despite facing legal action from the country’s financial regulator over alleged unlicensed financial product offerings.  The company has taken a cautious approach in designing the new loan products to align them with existing licensing models, aiming to ensure compliance with Australian financial regulations. Description Block Earner, an Australian fintech company, is moving forward with its plans to launch a cryptocurrency-backed loan product despite facing legal action from the country’s financial regulator over alleged unlicensed financial product offerings. The forthcoming crypto loan product will enable Australian crypto investors to use their cryptocurrency holdings as collateral to secure cash loans. Notably, … Read more Block Earner, an Australian fintech company, is moving forward with its plans to launch a cryptocurrency-backed loan product despite facing legal action from the country’s financial regulator over alleged unlicensed financial product offerings. The forthcoming crypto loan product will enable Australian crypto investors to use their cryptocurrency holdings as collateral to secure cash loans. Notably, Coinbase once offered…

    Article 2023年9月9日
  • ConsenSys calls for targeted regulation of blockchain applications to safeguard DeFi users

    TL;DR Breakdown ConsenSys, a prominent Ethereum development studio, recommends prioritizing the regulation of applications over blockchain protocols in the UK. They propose a nuanced and targeted regulatory approach for public-facing blockchain applications. ConsenSys also points out the challenge of maintaining data integrity outside the blockchain. ConsenSys, a leading Ethereum-focused development studio, has submitted a recommendation to the UK authorities, urging them to prioritize the regulation of applications over blockchain protocols. The suggestion comes as part of a response to an ongoing UK investigation into the expanding realm of decentralized finance (DeFi) and related cryptocurrency activities. The firm suggested its stance in a letter released on Tuesday that articulated a shift towards a more nuanced and targeted regulation method for public-facing blockchain applications. This would mitigate potential risks without impeding the core infrastructure of the blockchain. ConsenSys believes such an approach mirrors the existing regulatory framework for the second generation of the internet, commonly called Web2. In advocating for a focus on specific activities and services instead of imposing broad limitations on the entire blockchain infrastructure, ConsenSys stated: “The actual products…

    Article 2023年6月4日
  • Singapore Bank DBS launches innovative e-CNY payment solution for customers

    TL;DR Breakdown DBS enables customers to accept e-CNY payments, boosting cross-border commerce efficiency. Project Guardian tests asset tokenization and DeFi in collaboration with renowned platforms. DBS partners with Marketnode and other institutions, solidifying Singapore’s leadership. Description DBS, the renowned Singaporean bank, announced today a groundbreaking development that allows its customers to accept payments in e-CNY, the digital currency issued by the Chinese central bank. In a major step forward, DBS has established a seamless system through which e-CNY can be directly settled into a company’s bank account, leveraging automated processes for … Read more DBS, the renowned Singaporean bank, announced today a groundbreaking development that allows its customers to accept payments in e-CNY, the digital currency issued by the Chinese central bank. In a major step forward, DBS has established a seamless system through which e-CNY can be directly settled into a company’s bank account, leveraging automated processes for efficiency and convenience. Remarkably, one of DBS’s customers has already completed a purchase using this innovative solution. This significant milestone stems from DBS’s collaboration with the Monetary Authority of Singapore on…

    Article 2023年7月7日
  • The Bank of America does not see a future for PayPal’s stablecoin

    TL;DR Breakdown Bank of America says that PayPal’s PYUSD will drive payment efficiencies and an improved customer experience, but adoption of the crypto is unlikely. Analyst Alkesh Shah with the Bank of America argues that PYUSD will not have a broad impact on the crypto industry. According to the report, PYUSD will likely target a market that has been largely neglected until now: “blockchain technology-enabled asset transfers, payments, and remittances.” Description The launch of PayPal’s (PYPL) stablecoin PayPal USD (PYUSD) is expected to improve payment efficiencies and the customer experience, but adoption of the crypto is unlikely to be significant in the near future, Bank of America (BAC) said in a Thursday research report. Bank of America is not rooting for PayPal’s stablecoin PayPal, as previously … Read more The launch of PayPal’s (PYPL) stablecoin PayPal USD (PYUSD) is expected to improve payment efficiencies and the customer experience, but adoption of the crypto is unlikely to be significant in the near future, Bank of America (BAC) said in a Thursday research report. Bank of America is not rooting for PayPal’s…

    Article 2023年8月12日
  • Federal Reserve Governor demands clearer regulations

    TL;DR Breakdown Federal Reserve Governor has called for clearer regulations in the banking industry. The governor highlights the importance of regulatory clarity in the industry. Description Michelle Bowman, a member of the Board of Governors of the U.S. Federal Reserve System, has emphasized the need for global regulators to address the current supervision of novel banking activities, specifically focusing on banking as a service and digital assets. During her speech at the Salzburg Global Seminar on bank regulation and supervision, Bowman … Read more Michelle Bowman, a member of the Board of Governors of the U.S. Federal Reserve System, has emphasized the need for global regulators to address the current supervision of novel banking activities, specifically focusing on banking as a service and digital assets. During her speech at the Salzburg Global Seminar on bank regulation and supervision, Bowman highlighted the “supervisory void” that financial institutions find themselves in regarding emerging technologies. The Federal Reserve Governor wants clarity in regulations Despite some efforts to provide guidance, there remains significant uncertainty regarding the permissibility and supervisory expectations surrounding these activities. This…

    Article 2023年6月28日
TOP