EraLend, a zkSync DeFi Protocol, Suffers Malicious Attack, Incurs Losses of Millions of Dollars

摘要:EraLend, a zkSync DeFi Protocol, Suffers Malicious Attack, Incurs Losses of Millions of Dollars

On July 25th, Twitter user Spreek revealed that the zkSync DeFi protocol, EraLend, suffered an attack resulting in a loss of at least 1.7 million USDC. Spreek pointed out that the attack on EraLend may be related to pricing issues with high-risk tokens, but the scale of the hacker attack has not been confirmed yet.

Subsequently, EraLend team members confirmed the attack. The official announcement was made on Discord stating that a security event was detected on July 25th at 9:27:21 UTC, confirming that their platform was attacked. Only USDC was affected by this incident. All other assets remain safe and unaffected, and users are strongly advised not to deposit USDC at this time.

Furthermore, the attack has been brought under control, and the attacker is no longer able to continue their actions.

Afterward, the blockchain security firm BlockSec issued an announcement stating that they are assisting EraLend in resolving the issue. The attack was identified as a read-only reentrancy attack, with estimated losses of approximately 3.4 million USD. Additionally, the attacker's address was disclosed as 0xf1D076c9Be4533086f967e14EE6aFf204D5ECE7a.

On July 26th, EraLend revealed the cause of the attack: the attacker manipulated the oracle price to withdraw approximately 2.76 million USD from the USDC pool. EraLend clarified that other fund pools remained safe and unaffected. The team is actively collaborating with bridges, security teams, exchanges, and law enforcement agencies to investigate and trace the flow of funds.

免责声明

本文观点仅代表作者个人观点,不构成本平台的投资建议,本平台不对文章信息准确性、完整性和及时性作出任何保证,亦不对因使用或信赖文章信息引发的任何损失承担责任
上一篇

白话区块链早报:多个Starknet生态项目发布7.28预告视频,或将联合发布活动消息

下一篇

火币研究院研报:全面剖析加密理财产品市场的现状、风险与未来发展