Share this article

ZkSync's Largest Lender Struck by $3.4M Exploit

EraLend said the threat has been contained, but advises against deposits.

Updated Jul 25, 2023, 1:48 p.m. Published Jul 25, 2023, 1:34 p.m.
EraLend falls victim to $3.6 million exploit (Towfiqu Barbhuiya/Unsplash)
EraLend falls victim to $3.6 million exploit (Towfiqu Barbhuiya/Unsplash)

EraLend, the largest lending protocol on Ethereum scaling blockchain zkSync, has been hit by a $3.4 million read-only reentrancy attack, according to blockchain security firm CertiK.

The total amount of capital locked on EraLend slumped to $10.75 million from $18.5 million following the exploit, DefiLlama data indicate.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

"We've experienced a security incident on our platform today. The threat has been contained. We've suspended all borrowing operations for now and advise against depositing USDC. We're working with partners and cybersecurity firms to address this. More updates to follow," EraLend wrote in a tweet.

A read-only reentrancy bug allows an attacker to manipulate asset prices by flooding a smart contract with repeated calls in order to steal assets.

Decentralized finance (DeFi) protocol Conic Finance was hit by a similar attack last week with the total loss of $3.6 million.

UPDATE (July 25, 13:50 UTC): Removes space from EraLend's name throughout.


More For You

Pudgy Penguins: A New Blueprint for Tokenized Culture

Pudgy Title Image

Pudgy Penguins is building a multi-vertical consumer IP platform — combining phygital products, games, NFTs and PENGU to monetize culture at scale.

What to know:

Pudgy Penguins is emerging as one of the strongest NFT-native brands of this cycle, shifting from speculative “digital luxury goods” into a multi-vertical consumer IP platform. Its strategy is to acquire users through mainstream channels first; toys, retail partnerships and viral media, then onboard them into Web3 through games, NFTs and the PENGU token.

The ecosystem now spans phygital products (> $13M retail sales and >1M units sold), games and experiences (Pudgy Party surpassed 500k downloads in two weeks), and a widely distributed token (airdropped to 6M+ wallets). While the market is currently pricing Pudgy at a premium relative to traditional IP peers, sustained success depends on execution across retail expansion, gaming adoption and deeper token utility.

More For You

Circle faces first major 'threat' for institutional dollars from Tether’s USAT

Circle logo on a building

While Circle's USDC has operated without a "credible domestic competitor," Tether's USAT has the potential to shake up the landscape, analysts said.

What to know:

  • Analysts said USAT, the U.S.-focused stablecoin by Tether, could become the first credible domestic competitor to Circle's USDC token.
  • USAT is "a threat to USDC" and could gain an edge through institutional partners and global USDT connectivity, Crypto is Macro Now's Noelle Acheson said.
  • ClearStreet's Owen Lau called USAT “a manageable risk” for Circle, and noted potential "cannibalization" risk between Tether's two tokens.