Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
No Result
View All Result

Era Lend on zkSync exploited for $3.4M in reentrancy attack

CryptoExpert by CryptoExpert
July 25, 2023
in NFT News
0
Era Lend on zkSync exploited for $3.4M in reentrancy attack
  • Facebook
  • Twitter
  • Pinterest



You might also like

Bitcoin’s Worst Week Since FTX Crash Signals More Pain Ahead

Humanity Protocol Founder Confirms Private Key Breach as H Token Collapses 90% in $32M Exploit

BlackRock Bitcoin ETF Moves $226M in BTC to Coinbase Prime

Lending app Era Lend on zkSync has been exploited for $3.4 million worth of crypto, according to a July 25 report from blockchain security firm CertiK. The attacker used a “read-only reentrancy attack” to drain the funds, which is a type of attack that interrupts a multi-step process and then causes it to continue after a malicious action has been performed. Specifically, a “read-only” reentrancy is one that does not update the state of a contract.

#CertiKSkynetAlert

We are seeing reports that @Era_Lend has been exploited on zkSync

Total losses appear to be $3.4 million in a read only reentrancy attack

See more below https://t.co/h8xrjccE5i

— CertiK Alert (@CertiKAlert) July 25, 2023

According to the report, the attacker drained funds in two separate transactions using the externally owned account 0xf1D076c9Be4533086f967e14EE6aFf204D5ECE7a. The attacker relied on a vulnerability in “the callback and _updateReserves function” to manipulate a contract into reporting old values that had not yet been updated.

Era Lend is a fork of the Syncswap project, and CertiK claimed that other projects based on Syncswap may also be vulnerable to the exploit.

On-chain sleuth and Twitter user Spreek reported that the Syncswap code allows a user to “burn, then callback before update_reserves is called,” causing the oracle to report incorrect values.

okex

in the syncswap LP tokens, one can burn, then callback before update_reserves is called. so the oracle uses an incorrect reserves value to calculate the price, resulting in an inflating oracle price. pic.twitter.com/0U7Vu7BzJM

— Spreek (@spreekaway) July 25, 2023

Spreek also reported that the Era Lend team had acknowledged the attack and paused the protocol’s zkSync contracts to prevent further exploits.

Another blockchain investigator, known on Twitter as Saul, reported that the attack had affected stablecoin USDC+, which is issued by the Overnight Finance protocol. According to Saul, the Overnight team has acknowledged the exposure and has paused its own contracts as well. Over $261,000, or 7.86% of the total value of the collateral backing the stablecoin, may have been lost.

In a June 7 blog post explaining how read-only reentrancy attacks are carried out, pseudonymous blockchain investigator Officer’s Notes stated that these vulnerabilities are difficult for auditors to spot, since “Typically, auditors and bug hunters are only concerned with entry points that modify state when looking for reentrancy.”

To help alleviate this problem, Officer’s Notes recommends that auditors use specialized software to aid them in finding these vulnerabilities.

Era Lend runs on the zkSync network, a zero-knowledge proof Ethereum layer-2 rollup. In April, the network’s total value locked reached over $110 million. The network’s developers intend to create an ecosystem of interoperable chains called “Hyperchains” by the end of the year.

Collect this article as an NFT to preserve this moment in history and show your support for independent journalism in the crypto space.





Source link

  • Facebook
  • Twitter
  • Pinterest
Tags: Ethereum
CryptoExpert

CryptoExpert

Recommended For You

Bitcoin’s Worst Week Since FTX Crash Signals More Pain Ahead

by CryptoExpert
June 11, 2026
0
logo

Bitcoin‘s slide below $60,000 last Friday marked the token’s worst weekly performance since the catastrophic collapse of Sam Bankman-Fried’s FTX exchange in November 2022. While the triggers this...

Read more

Humanity Protocol Founder Confirms Private Key Breach as H Token Collapses 90% in $32M Exploit

by CryptoExpert
June 10, 2026
0
logo

Security incident exposes a Humanity Foundation member’s credentials, sending the biometric identity project into crisis — and raising deeper questions about insider involvementHumanity Protocol’s H token crashed more...

Read more

BlackRock Bitcoin ETF Moves $226M in BTC to Coinbase Prime

by CryptoExpert
June 9, 2026
0
logo

Wallets labeled as related to BlackRock’s ETF transferred 3,580 BTC, valued at approximately $226.8 million, to Coinbase Prime on June 8, 2026, drawing renewed attention to the fund...

Read more

Crypto Scam & Fraud Statistics 2026: Losses, Victims, and Evolving Tactics

by CryptoExpert
June 8, 2026
0
logo

The numbers no longer shock in isolation — they demand context. In 2025, cryptocurrency scams received at least $14 billion on-chain, crypto fraud complaints to the FBI hit...

Read more

Morgan Stanley Opens New Crypto-to-ETF Path With Galaxy Digital

by CryptoExpert
June 7, 2026
0
logo

Morgan Stanley Wealth Management has launched a new referral arrangement with Galaxy Digital that allows eligible clients to lend cryptocurrency directly in exchange for shares of spot crypto...

Read more
Next Post
Dogecoin (DOGE) Pumps 10% As Elon Musk Links Memecoin To X

Dogecoin (DOGE) Pumps 10% As Elon Musk Links Memecoin To X

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

Sitemap

  • Market Cap
  • Donations
  • Trading
  • Mining
  • Contact

Legal Information

  • Privacy Policy
  • Anti-Spam Policy
  • Copyright Notice
  • DMCA Compliance
  • Social Media Disclaimer
  • Terms Of Service

Categories

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

© Copyright 2024 InvestInCryptoNews.com

No Result
View All Result
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO

© Copyright 2024 InvestInCryptoNews.com

This website is using cookies to improve the user-friendliness. You agree by using the website further.

Privacy policy
bitcoin
Bitcoin (BTC) $ 62,612.00
ethereum
Ethereum (ETH) $ 1,653.20
tether
Tether (USDT) $ 0.998844
bnb
BNB (BNB) $ 595.23
usd-coin
USDC (USDC) $ 0.999803
xrp
XRP (XRP) $ 1.11
solana
Solana (SOL) $ 64.92
tron
TRON (TRX) $ 0.321933
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.02
staked-ether
Lido Staked Ether (STETH) $ 2,265.05

Pin It on Pinterest

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?