Close Menu
  • Home
  • Crypto News
    • Bitcoin
    • NFT News
  • Metaverse
  • Defi
  • Blockchain
  • Regulations
  • Trading

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Bitcoin Dominance May Have Hit Its Cycle High – What Comes Next For Alts?

May 31, 2025

FTX Recovery Trust Begins $5B Second Payout to Creditors

May 31, 2025

Bitcoin Nears Crucial 4H MA 200 – Can Bulls Step In?

May 31, 2025
Facebook X (Twitter) Instagram
CredBit.com
  • Home
  • Crypto News
    • Bitcoin
    • NFT News
  • Metaverse
  • Defi
  • Blockchain
  • Regulations
  • Trading
Facebook X (Twitter) Instagram
CredBit.com
Home » EraLend Exploit: Hackers Steal $3.4 Million From zkSync Lending Protocol
Bitcoin

EraLend Exploit: Hackers Steal $3.4 Million From zkSync Lending Protocol

July 25, 20233 Mins Read
Facebook Twitter WhatsApp Pinterest Telegram LinkedIn Tumblr Email Reddit VKontakte
EraLend Exploit: Hackers Steal .4 Million From zkSync Lending Protocol
Share
Facebook Twitter LinkedIn Pinterest Telegram Email

EraLend, a decentralized lending protocol operating on the zkSync Layer 2, has fallen victim to an exploit resulting in a loss of $3.4 million. The attack was confirmed by security analysts at BlockSec, who have been assisting the protocol in addressing the issue.

Following the attack, EraLend issued a statement acknowledging the security incident and assuring its users that the threat had been contained. The protocol has suspended all borrowing operations and advised users against depositing USDC until further notice.

Re-Entrancy Attack Strikes EraLend

According to BlockSec, the attack was a read-only re-entrancy attack. This attack involves a malicious actor repeatedly entering and exiting a contract function to manipulate the contract’s state and withdraw funds.

A reentrancy attack is an exploit that can occur in smart contracts, which are self-executing computer programs that run on decentralized blockchain networks like Ethereum. 

In a reentrancy attack, a malicious user exploits a vulnerability in a smart contract by repeatedly calling a function within the contract before the previous function call has been completed, allowing them to manipulate the contract’s state and potentially steal funds.

When a smart contract function is called, the contract’s state is updated before the function call is completed. Suppose the called function interacts with a second contract before the first function call is completed. In that case, the second contract can call back into the first contract’s function, potentially changing the contract’s state multiple times before the original function call completes. 

This can allow an attacker to manipulate the contract’s state and steal funds.

To prevent reentrancy attacks, developers can use a technique called “checks-effects-interactions.” This means that a smart contract should always check all the inputs and conditions before executing any state changes, and then execute all state changes before interacting with any other contracts. 

This ensures the contract’s state is updated before external interactions occur, preventing reentrancy attacks. In this case, the attacker exploited a vulnerability in EraLend’s contract code that repeatedly allowed them to withdraw funds without the protocol’s knowledge.

EraLend has identified the root cause of the attack and is working with partners and cybersecurity firms to address the issue. The protocol has assured users that it will take all necessary steps to mitigate the attack’s impact and prevent similar incidents from occurring in the future.

While there have been no further updates, it is clear that EraLend is committed to maintaining the highest security standards and taking proactive measures to safeguard its users’ funds and data.

Total crypto market capitalization downtrend on the 1-day chart, losing $300 million over the past 2 days. Source: TOTAL on TradingView.com

Featured image from Unsplash, chart from TradingView.com 


Credit: Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Reddit VKontakte Telegram WhatsApp

Related Posts

Bitcoin Dominance May Have Hit Its Cycle High – What Comes Next For Alts?

May 31, 2025

Bitcoin Nears Crucial 4H MA 200 – Can Bulls Step In?

May 31, 2025

Bitcoin Difficulty Set for Another Jump—How High This Time?

May 31, 2025

Bitcoin Indicator Shows Bears Dominate Market With Rising Volume – Details

May 31, 2025

The Bitcoin Chart Wall Street Doesn’t Want You To See

May 30, 2025

21Shares Files Amended S-1 For Dogecoin ETF Bid

May 30, 2025

Comments are closed.

Editors Picks

Bitcoin Dominance May Have Hit Its Cycle High – What Comes Next For Alts?

May 31, 2025

FTX Recovery Trust Begins $5B Second Payout to Creditors

May 31, 2025

Bitcoin Nears Crucial 4H MA 200 – Can Bulls Step In?

May 31, 2025

Nigel Farage Vows Pro-Crypto Bill, Bitcoin Reserve If Elected UK PM

May 31, 2025
© 2025 - credbit.com - All Rights Reserved!
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Use
  • DMCA

Type above and press Enter to search. Press Esc to cancel.