EraLend, a zkSync DeFi Protocol, Suffers Malicious Attack, Incurs Losses of Millions of Dollars

خلاصہ:EraLend, a zkSync DeFi Protocol, Suffers Malicious Attack, Incurs Losses of Millions of Dollars

On July 25th, Twitter user Spreek revealed that the zkSync DeFi protocol, EraLend, suffered an attack resulting in a loss of at least 1.7 million USDC. Spreek pointed out that the attack on EraLend may be related to pricing issues with high-risk tokens, but the scale of the hacker attack has not been confirmed yet.

Subsequently, EraLend team members confirmed the attack. The official announcement was made on Discord stating that a security event was detected on July 25th at 9:27:21 UTC, confirming that their platform was attacked. Only USDC was affected by this incident. All other assets remain safe and unaffected, and users are strongly advised not to deposit USDC at this time.

Furthermore, the attack has been brought under control, and the attacker is no longer able to continue their actions.

Afterward, the blockchain security firm BlockSec issued an announcement stating that they are assisting EraLend in resolving the issue. The attack was identified as a read-only reentrancy attack, with estimated losses of approximately 3.4 million USD. Additionally, the attacker's address was disclosed as 0xf1D076c9Be4533086f967e14EE6aFf204D5ECE7a.

On July 26th, EraLend revealed the cause of the attack: the attacker manipulated the oracle price to withdraw approximately 2.76 million USD from the USDC pool. EraLend clarified that other fund pools remained safe and unaffected. The team is actively collaborating with bridges, security teams, exchanges, and law enforcement agencies to investigate and trace the flow of funds.

ڈس کلیمر

یہ مضمون صرف مصنف کی ذاتی رائے پر مبنی ہے، یہ پلیٹ فارم کی سرمایہ کاری کی مشورہ نہیں ہے۔ پلیٹ فارم مضمون کی معلومات کی درستگی، مکملیت اور بروقت ہونے کی کوئی ضمانت نہیں دیتا، اور مضمون کی معلومات پر اعتماد یا استعمال سے ہونے والے کسی بھی نقصان کی ذمہ داری قبول نہیں کرتا۔