<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=ZKLend_Lending_Accumulator_Precision_Loss_Manipulation</id>
	<title>ZKLend Lending Accumulator Precision Loss Manipulation - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=ZKLend_Lending_Accumulator_Precision_Loss_Manipulation"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=ZKLend_Lending_Accumulator_Precision_Loss_Manipulation&amp;action=history"/>
	<updated>2026-05-30T08:36:29Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=ZKLend_Lending_Accumulator_Precision_Loss_Manipulation&amp;diff=6559&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/zklendlendingaccumulatorprecisionlossmanipulation.php}} {{Unattributed Sources}}  ZKLendzkLend is a decentralized money-market protocol built on Starknet that offers secure, efficient lending, borrowing, and depositing for both retail and institutional users. It provides competitive yields, a robust risk framework, and scalability via Starknet’s L2 solution...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=ZKLend_Lending_Accumulator_Precision_Loss_Manipulation&amp;diff=6559&amp;oldid=prev"/>
		<updated>2025-02-18T21:01:43Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/zklendlendingaccumulatorprecisionlossmanipulation.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Zklendcom.jpg&quot; title=&quot;File:Zklendcom.jpg&quot;&gt;thumb|ZKLendzk&lt;/a&gt;Lend is a decentralized money-market protocol built on Starknet that offers secure, efficient lending, borrowing, and depositing for both retail and institutional users. It provides competitive yields, a robust risk framework, and scalability via Starknet’s L2 solution...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/zklendlendingaccumulatorprecisionlossmanipulation.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Zklendcom.jpg|thumb|ZKLend]]zkLend is a decentralized money-market protocol built on Starknet that offers secure, efficient lending, borrowing, and depositing for both retail and institutional users. It provides competitive yields, a robust risk framework, and scalability via Starknet’s L2 solution. The platform was recently hit by a $9.6 million exploit involving a vulnerability in the wstETH token. The attack manipulated the &amp;quot;lending_accumulator&amp;quot; to take advantage of rounding errors, leading to significant losses. In response, zkLend paused all markets and is working with security experts, law enforcement, and exchanges to track the stolen funds and identify the hacker. Legal action is being pursued, and the team is preparing a recovery plan to minimize the impact on users and partners.&amp;lt;ref name=&amp;quot;rektnews-18126&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;zklendtwitter-18127&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;linktree-18128&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;zklend-18129&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;zklend-18130&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;certikalerttwitter-18131&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;zklendtwitter-18132&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;certikalerttwitter-18133&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;googledrive-18134&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;nethermindethgithub-18135&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;nethermindethgithub-18136&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;voyageronline-18137&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;voyageronline-18138&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;voyageronline-18139&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;starkscan-18140&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;initialreaction-18141&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;pleahacker-18142&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About ZKLend ==&lt;br /&gt;
zkLend is a next-generation L2 money-market protocol built on Starknet, offering decentralized lending, borrowing, and depositing for both retail and institutional users. It provides competitive yields based on real-time supply and demand, a robust risk framework, and secure, scalable transactions using validity proofs. The platform supports institutional DeFi markets with KYC, compliance, capital efficiency, and customizable loan terms. zkLend’s roadmap includes core functionality reliability, mainnet launches, cross-chain lending, and institutional MVP in 2024. The platform is backed by trusted institutions like Nethermind and ABDK Consulting for infrastructure and security.&lt;br /&gt;
&lt;br /&gt;
zkLend is designed to provide a secure and efficient decentralized money-market platform for retail users, offering seamless deposit and borrowing of digital assets with yields derived from interest paid by borrowers. The platform, now live on the mainnet with fully audited contracts, ensures user safety and leverages the latest blockchain technology to offer a smooth experience. Powered by Starknet's L2 solution, zkLend benefits from superior transaction speed, low costs, and innovations like account abstraction and trustless bridging, making it a future-proof platform for decentralized finance. With a focus on scalability and decentralization, zkLend is poised to lead in the DeFi space.&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
The ZKLend protocol contained at least 3 minor vulnerabilities, which either the single firm Nethermind had failed to determine, or had been introduced in subsequent modifications.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
&amp;quot;Starting on 11th of February, zkLend suffered an attack resulting in the loss of around $9.6 million USD in funds.&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - ZKLend Lending Accumulator Precision Loss Manipulation&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|May 23rd, 2022 4:36:00 PM MDT&lt;br /&gt;
|First Nethermind Audit Completed&lt;br /&gt;
|The Cairo 0 money market is audited by Nethermind.&lt;br /&gt;
|-&lt;br /&gt;
|October 1st, 2023 9:42:00 AM MDT&lt;br /&gt;
|Second Nethermind Audit Completed&lt;br /&gt;
|The Cairo 1 money market is audited by Nethermind.&lt;br /&gt;
|-&lt;br /&gt;
|November 27th, 2023 11:51:00 AM MST&lt;br /&gt;
|ZEND Token Contract Audit&lt;br /&gt;
|The ZEND token contract is audited by Nethermind.&lt;br /&gt;
|-&lt;br /&gt;
|December 16th, 2024 5:18:00 AM MST&lt;br /&gt;
|Liquid Staking Contract Audit&lt;br /&gt;
|The liquid staking contract is audited, also by Nethermind.&lt;br /&gt;
|-&lt;br /&gt;
|February 11th, 2025 5:44:35 AM MST&lt;br /&gt;
|Smart Contract First Contact&lt;br /&gt;
|The attacker reportedly makes their first contact with the ZKLend smart contract.&lt;br /&gt;
|-&lt;br /&gt;
|February 11th, 2025 8:01:02 AM MST&lt;br /&gt;
|First Exploit Transaction&lt;br /&gt;
|The first exploit transaction, which is able to gain 15484.120127 USDC.&lt;br /&gt;
|-&lt;br /&gt;
|February 11th, 2025 9:37:09 AM MST&lt;br /&gt;
|Attacker Starts Withdrawing&lt;br /&gt;
|The attacker made the first of a series of withdrawals from Starknet Ethereum, Base, Arbitrum, Optimism through LayerSwap, Orbiter, and rhino.fi.&lt;br /&gt;
|-&lt;br /&gt;
|February 11th, 2025 10:52:00 AM MST&lt;br /&gt;
|Rhino Fi Suspicions&lt;br /&gt;
|zeroShadow were first made aware of the suspicious activity by Rhino.fi. Both parties agreed on their suspicion after initial check and forwarded the information to StarkWare.&lt;br /&gt;
|-&lt;br /&gt;
|February 11th, 2025 2:22:00 PM MST&lt;br /&gt;
|ZKLend Tweets Announcement&lt;br /&gt;
|ZKLend shares an announcement that they are aware of the exploit. They are &amp;quot;now investigating and will provide an update when possible&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
|February 11th, 2025 7:51:00 PM MST&lt;br /&gt;
|CertiK Public Notice Posted&lt;br /&gt;
|CertiK posts an analysis on Twitter/X with details of the exploit.&lt;br /&gt;
|-&lt;br /&gt;
|February 11th, 2025 8:21:00 PM MST&lt;br /&gt;
|Reading Out To Hacker&lt;br /&gt;
|ZKLend announces an offer for the hacker, where they can keep 10% and return the rest in exchange for reduced liability.&lt;br /&gt;
|-&lt;br /&gt;
|February 12th, 2025 1:16:00 AM MST&lt;br /&gt;
|CertiK Detailed Walkthrough&lt;br /&gt;
|CertiK posts a detailed walkthrough of the precision error which is responsible for the exploit.&lt;br /&gt;
|-&lt;br /&gt;
|February 13th, 2025 7:46:00 PM MST&lt;br /&gt;
|Update From ZKLend Team&lt;br /&gt;
|The ZKLend team shares an update including that they have not yet heard from the exploiter and&lt;br /&gt;
|-&lt;br /&gt;
|February 14th, 2025 6:14:00 AM MST&lt;br /&gt;
|Postmortem Tweet Published&lt;br /&gt;
|ZKLend publishes a post-mortem on Twitter/X, sharing a link to a Google Drive document with the details.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
&amp;quot;The attacker manipulated the &amp;quot;lending_accumulator&amp;quot; to be very large at 4.069297906051644020, then took advantage of the rounding error during ztoken mint() and withdraw() to repeatedly deposit 4.069297906051644021 wstETH getting 2 wei then withdraw 4.069297906051644020*1.5 -1 = 6.103946859077466029 wstETH to expend just 1 wei.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
Rekt reports 9.57M USD.&lt;br /&gt;
&lt;br /&gt;
The total amount lost has been estimated at $9,570,000 USD.&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
&amp;quot;On 11th February 2025, zkLend, a money market protocol on Starknet, was attacked using an empty market exploit, causing the loss of around $9.6 million US dollars. The exploit was made against the wstETH token that was newly launched on Starknet. Initial analysis has been performed and this post-mortem serves as a brief report of the progress thus far.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Smart contracts suspension: The zkLend markets contract was immediately paused after the&lt;br /&gt;
attack, suspending all deposits, withdrawals, borrowing, repayment, flash loans, and liquidations. An active warning was put out on the app's homepage.&lt;br /&gt;
Security collaboration: Working with security experts such as zeroShadow to notify exchanges, Chainalysis, TRM and Elliptic of associated wallet addresses.&lt;br /&gt;
Fund tracking: Continuously track stolen funds and the attacker's activities.&lt;br /&gt;
Legal collaboration: Actively working with law enforcement (Hong Kong Police, FBI, Homeland&lt;br /&gt;
Security) to identify and apprehend the hacker.&lt;br /&gt;
Hacker communication: An on-chain message was sent to the hacker to seek resolution and&lt;br /&gt;
return funds, but no response has been received.&lt;br /&gt;
Community updates: Regular updates are being provided to users and partners regarding the&lt;br /&gt;
protocol's status and developments.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
&amp;quot;As the exploiter did not contact us by the deadline, the zkLend team is pursuing legal action, which may be a prolonged process. To ensure transparency, we filed an incident report with Hong Kong Police Force, the FBI, and Homeland Security to commence investigation.&lt;br /&gt;
&lt;br /&gt;
Our investigation indicates that the hacker has been linked to prior attacks on other DeFi protocols. We have been monitoring fund flows and identified multiple relevant wallet addresses. We have shared this information with CEXes, who are taking appropriate actions within their purview. Concurrently, we are preparing a post-mortem report with our security team, detailing the attack and its underlying causes.&lt;br /&gt;
&lt;br /&gt;
We will announce a recovery and fund release plan next week. Our priority is to minimize the impact on our users and partners, and handle this situation fairly and transparently for everyone involved. We appreciate your patience as we work to resolve this matter as quickly as possible.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;rektnews-18126&amp;quot;&amp;gt;[https://rekt.news/zklend-rekt/ Rekt - zkLend - Rekt] (Accessed Feb 18, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;zklendtwitter-18127&amp;quot;&amp;gt;[https://twitter.com/zkLend/status/1890389052492509362 @zkLend Twitter] (Accessed Feb 18, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;linktree-18128&amp;quot;&amp;gt;[https://linktr.ee/zkLend zkLend | Twitter | Linktree] (Accessed Feb 18, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;zklend-18129&amp;quot;&amp;gt;[https://zklend.com/ zkLend | Money-market protocol on Starknet] (Accessed Feb 18, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;zklend-18130&amp;quot;&amp;gt;[https://zklend.gitbook.io/documentation/about/introduction/zklend zkLend | zkLend] (Accessed Feb 18, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;certikalerttwitter-18131&amp;quot;&amp;gt;[https://twitter.com/CertiKAlert/status/1889507487491170625 @CertiKAlert Twitter] (Accessed Feb 18, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;zklendtwitter-18132&amp;quot;&amp;gt;[https://twitter.com/zkLend/status/1889424818967371779 @zkLend Twitter] (Accessed Feb 18, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;certikalerttwitter-18133&amp;quot;&amp;gt;[https://twitter.com/CertiKAlert/status/1889589451451670832 @CertiKAlert Twitter] (Accessed Feb 18, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;googledrive-18134&amp;quot;&amp;gt;[https://drive.google.com/file/d/10i1dh_J89tPPw7KRcmFIVM6iNrJZAyfi/view zkLend Hack Post-mortem.pdf - Google Drive] (Accessed Feb 18, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;nethermindethgithub-18135&amp;quot;&amp;gt;[https://github.com/NethermindEth/PublicAuditReports/blob/1d6264507e7ba835eff2fa14499acc2729b9b84c/NM0058-FINAL_ZKLEND.pdf PublicAuditReports/NM0058-FINAL_ZKLEND.pdf at 1d6264507e7ba835eff2fa14499acc2729b9b84c · NethermindEth/PublicAuditReports · GitHub] (Accessed Feb 18, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;nethermindethgithub-18136&amp;quot;&amp;gt;[https://github.com/NethermindEth/PublicAuditReports/blob/1d6264507e7ba835eff2fa14499acc2729b9b84c/NM0097-FINAL_ZKLEND.pdf PublicAuditReports/NM0097-FINAL_ZKLEND.pdf at 1d6264507e7ba835eff2fa14499acc2729b9b84c · NethermindEth/PublicAuditReports · GitHub] (Accessed Feb 18, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;voyageronline-18137&amp;quot;&amp;gt;[https://voyager.online/tx/0x04862e266cf9a952d06a3d7e537aa68f8ba7f46d224912240b11bb9c6e7f1480 Voyager - Starknet block explorer] (Accessed Feb 18, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;voyageronline-18138&amp;quot;&amp;gt;[https://voyager.online/tx/0x0467c72d570ac97feab5ff1c2a326d1b0101c8241316a58d854c734ca7a1b446 Voyager - Starknet block explorer] (Accessed Feb 18, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;voyageronline-18139&amp;quot;&amp;gt;[https://voyager.online/tx/0x01711f45d2d6f1df2a14f7f055bdaa370b947c196dca0078b934c11a53dc3d2c Voyager - Starknet block explorer] (Accessed Feb 18, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;starkscan-18140&amp;quot;&amp;gt;[https://starkscan.co/tx/0x04862e266cf9a952d06a3d7e537aa68f8ba7f46d224912240b11bb9c6e7f1480 Transaction  - Starkscan] (Accessed Feb 18, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;initialreaction-18141&amp;quot;&amp;gt;[https://twitter.com/bigcockfuckass/status/1890245380413260007 The Initial Reaction On Discord] (Accessed Feb 18, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;pleahacker-18142&amp;quot;&amp;gt;[https://twitter.com/zkLend/status/1889515118368829559 ZKLend - &amp;quot;You may keep 10% of the funds as a whitehat bounty, and send back the remaining 90%, or 3,300 ETH to be exact, to this Ethereum address&amp;quot; - Twitter/X] (Accessed Feb 18, 2025)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>