zkLend (2025) — Crypto Hack
Partially RecoveredzkLend, a Starknet-based lending protocol, was exploited for ~$9.5M through a reentrancy vulnerability in its withdrawal function.
Summary
zkLend, a Starknet-based lending protocol, was exploited for ~$9.5M through a reentrancy vulnerability in its withdrawal function.
How It Was Compromised — DeFi via Smart Contract Exploit / Reentrancy
On February 12, 2025, zkLend, a lending protocol built on Starknet, was exploited for approximately $9.5M. The attacker identified a reentrancy vulnerability in the protocol's withdrawal function that allowed them to manipulate the protocol's accounting and extract value from its lending pools. The exploit was executed across multiple transactions and drained several of the protocol's supported assets. zkLend paused the protocol and engaged with blockchain analytics firms to track the stolen funds. The protocol offered a 10% bounty for the return of the funds and engaged with the attacker, who later returned a portion of the stolen assets.
Fund Flow & Laundering Analysis
Stolen tokens were swapped to other assets via decentralized exchanges on Starknet. The funds were then bridged to Ethereum mainnet and deposited into Tornado Cash. The attacker used a complex network of intermediary wallets to fragment the laundering trail. zkLend engaged with the attacker, who returned approximately $1.4M worth of tokens after negotiations.