ZKSync-based Era Lend suffers $3.4 million loss in DeFi exploit

TL;DR Breakdown

  • Era Lend, a lending protocol on the zkSync network, suffered a $3.4 million loss due to a ‘read-only reentrancy attack’, which allowed the attacker to withdraw funds repeatedly.
  • The attack also impacted the stablecoin USDC+, issued by the Overnight Finance protocol, resulting in a potential loss of over $261,000.
  • In response, Era Lend paused its zkSync contracts to prevent further exploits, highlighting the ongoing security challenges in the DeFi sector.

Description

According to a recent report by blockchain security firm BlockSec, Era Lend, a decentralized lending protocol operating on the zkSync Layer 2 network, has fallen victim to a ‘read-only reentrancy attack’ resulting in a loss of $3.4 million.  The attacker exploited a vulnerability that allowed repeated calls to a function within a single transaction, withdrawing … Read more

According to a recent report by blockchain security firm BlockSec, Era Lend, a decentralized lending protocol operating on the zkSync Layer 2 network, has fallen victim to a ‘read-only reentrancy attack’ resulting in a loss of $3.4 million. 

The attacker exploited a vulnerability that allowed repeated calls to a function within a single transaction, withdrawing more funds than they were entitled to. Also, the exploit involved manipulating a contract to report outdated values that hadn’t been updated yet, taking advantage of a faulty price oracle that Era Lend relied upon.

The impact and response

The attack had repercussions on the stablecoin USDC+, issued by the Overnight Finance protocol, resulting in a potential loss of over $261,000, which represents 7.86% of the total value of the collateral supporting the stablecoin. 

In response to the attack, Era Lend paused the protocol’s zkSync contracts to prevent further exploits. The team also advised users that only the USDC pool was compromised. According to an official statement on Discord, the Era Lend team assured that the security of other assets remains intact—but borrowing operations on the platform have been temporarily halted.

“We have detected and confirmed a cyber attack on our platform. We want to assure you that the attack has been contained, and the threat actor can no longer continue their actions.”

Era Lend Team

The Era Lend exploit has raised concerns for other projects based on the Syncswap project, from which Era Lend is a fork. Security analysts have warned that these projects might also be susceptible to similar exploits. The incident underscores the need for auditors to utilize specialized software to identify these vulnerabilities more effectively, as read-only reentrancy attacks can evade traditional scrutiny and remain harder to identify during auditing processes.

Era Lend operates on the zkSync network, an Ethereum layer-2 rollup utilizing zero-knowledge proofs. As of April, the total value locked in the zkSync network surpassed $110 million. Despite the recent exploit, the network’s developers have ambitious plans to establish an ecosystem of interoperable chains named “Hyperchains” by December 2023.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:ZKSync-based Era Lend suffers $3.4 million loss in DeFi exploit

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年7月26日 17:11
Next 2023年7月26日 18:31

Related articles

  • Anthony Blinken is trying to fix China-US relationship

    TL;DR Breakdown Antony Blinken, the U.S. Secretary of State, has visited China, the first such visit since 2018. His mission is to revitalize US-China relations that have been strained, especially after the suspected Chinese spy balloon incident. Description Stepping into the historical cauldron of US-China relations, Antony Blinken, the U.S. Secretary of State, has become a beacon of diplomatic engagement. Marking the first such visit to China since 2018, Blinken’s trip hints at a strategic shift towards reviving the tenuous ties between the two global powers. Following an incident involving a suspected Chinese … Read more Stepping into the historical cauldron of US-China relations, Antony Blinken, the U.S. Secretary of State, has become a beacon of diplomatic engagement. Marking the first such visit to China since 2018, Blinken’s trip hints at a strategic shift towards reviving the tenuous ties between the two global powers. Following an incident involving a suspected Chinese espionage balloon hovering over North America, the fragile relationship was strained further, making Blinken’s task even more critical. Navigating through a troubled history Over a span of five-and-a-half hours,…

    Article 2023年6月21日
  • WazirX Reveals Ties with Binance and Raises Concerns Over WRX Token 

    TL;DR Breakdown WazirX revealed that Binance controls the WRX token and conducted the initial exchange offering (IEO), keeping the proceeds at nearly $2 million. Binance has failed to conduct quarterly burns for the past five quarters, raising concerns about its commitment to the WRX token. Indian cryptocurrency exchange WazirX recently provided additional clarity regarding its relationship with the world’s leading crypto exchange, Binance. In a blog post, WazirX disclosed that Binance controls the WRX token, shedding light on the initial exchange offering (IEO) and the subsequent management of the token. This revelation has raised concerns, particularly as Binance has failed to conduct quarterly burns for the past five quarters. In this article, we delve deeper into the details of WazirX’s ties with Binance, the concerns raised, and the potential implications for the WRX token and its users. Binance’s Control Over WRX Token WazirX confirmed that Binance conducted the WRX token IEO, retaining all the proceeds from the sale, which amounted to nearly $2 million. Currently, Binance holds a significant amount of WRX tokens, with a total of 580.78 million locked…

    Article 2023年5月19日
  • Kenya’s central bank governor clarifies crypto stand

    TL;DR Breakdown Patrick Njoroge, the outgoing governor of the Central Bank of Kenya (CBK), has provided clarity on the bank’s stance on cryptocurrencies. His comments come at a critical time when opinions on digital currencies remain divided globally. Njoroge emphasized that the CBK’s cautious approach to cryptocurrencies is not based on personal opinions but on the wealth of information accumulated by the institution over its 57-year history. Known for his staunch opposition to cryptocurrencies, Njoroge has been a notable figure in Kenya’s financial sector, advocating for caution when dealing with volatile digital assets. Governor Patrick Njoroge, who is nearing the end of his tenure at Kenya’s Central Bank, has come forward to share his perspective on the often-controversial subject of cryptocurrencies. His statements come at a time when the global financial world is divided on the issue, with some welcoming the technology and others, like Njoroge, offering cautionary advice. Unraveling the CBK’s position on cryptocurrencies Njoroge, who has the distinction of being the ninth governor of Kenya’s Central Bank, expressed that his opposition to cryptocurrencies is not a product of…

    Article 2023年6月8日
  • Gemini Teases XRP Relisting Soon Following Ripple’s SEC Lawsuit Victory

    TL;DR Breakdown Gemini teases the potential relisting of XRP following Ripple’s legal win against the SEC, which has led to a surge in XRP’s trading volume and price. Gemini’s CEO, Cameron Winklevoss, expresses optimism about Bitcoin accumulation, as spot Bitcoin ETF filings signal growing institutional interest in the leading cryptocurrency. Description United States-based cryptocurrency exchange Gemini has hinted at plans to relist the XRP token on its platform, following Ripple‘s recent legal victory in the U.S. Securities and Exchange Commission (SEC) lawsuit. The development comes in the wake of several top crypto exchanges, including Coinbase and Kraken, already reinstating XRP trading after the July 13, 2023 … Read more United States-based cryptocurrency exchange Gemini has hinted at plans to relist the XRP token on its platform, following Ripple‘s recent legal victory in the U.S. Securities and Exchange Commission (SEC) lawsuit. The development comes in the wake of several top crypto exchanges, including Coinbase and Kraken, already reinstating XRP trading after the July 13, 2023 Summary Judgment by Judge Analisa Torres. Her ruling effectively reopened the doors for XRP trading on…

    Article 2023年7月22日
  • Cambridge University study sheds new light on Bitcoin mining’s environmental impact

    TL;DR Breakdown The study traces the advancements in Bitcoin mining hardware, from CPUs to ASICs, highlighting how modern devices are far more efficient and longer-lasting than their predecessors. Contrary to popular belief, the study shows that Bitcoin’s energy consumption is decreasing, with the 2023 estimate standing at 70.4 TWh, which is only about 0.38% of the world’s total electricity consumption. The research challenges the notion that Bitcoin mining is a leading cause of global warming and suggests that with the adoption of renewable energy sources, its environmental impact is likely to decrease further. Description In a groundbreaking study, researchers from Cambridge University and the Cambridge Bitcoin Electricity Consumption Index (CBECI) team have released updated data that challenges prevailing narratives about the environmental impact of Bitcoin mining. The study, which builds upon previous research, aims to provide a more nuanced understanding of the electricity consumption associated with Bitcoin mining and … Read more In a groundbreaking study, researchers from Cambridge University and the Cambridge Bitcoin Electricity Consumption Index (CBECI) team have released updated data that challenges prevailing narratives about the environmental…

    Article 2023年9月2日
TOP