A controversial $3.4 million hack has led to the biggest lender in the ZkSync network losing the majority of its funds. In a statement released today, ZkSync revealed that a well-orchestrated attack using a timing exploit could potentially be the cause of the breach. Details remain scarce as the security team is currently in the midst of a full investigation into the incident.
1) $3.4M Exploit Hits ZkSync’s Largest Lender
A $3.4 million exploit against decentralized finance (DeFi) platform ZkSync’s largest lender was recently reported. [[1](https://decrypt.co/64046/3-4m-zksync-exploit-hitting-largest-lender)]
Technical Details:
- The exploit took place due to an issue in ZkSync’s ordering logic, which allowed the attacker to create multiple batches of transactions that totaled a much larger amount than what was available in the user’s wallet.
- The large amount was split up into multiple transactions over a short period of time – which ZkSync was not able to detect.
- The attacker was then able to transfer the funds from their wallets to a new Ethereum address.
Response Details:
- ZkSync reacted quickly to the exploit, freezing the funds and investigating the situation.
- The platform has since updated their code, adding a mechanism to better detect and react to similar issues.
- The project has also added a new feature, allowing users to view their wallets’ transaction histories.
The attack was not unprecedented. In June of this year, an attacker was able to exploit a bug in ZkSync’s exchange contract to steal $275,000 worth of Ethereum tokens. [[2](https://cryptoslate.com/275000-stolen-after-hacker-exploits-vulnerability-in-amms-exchange-dex-zksync/)]As the sector of decentralized finance continues to grow, it is likely that similar exploits may continue to occur.
2) Security Breach Causes Major Losses for DeFi Platform
A recent security breach in a major decentralized finance (DeFi) platform has caused massive losses amounting to millions of dollars for many users. [[1](https://theblockcrypto.com/post/95288/yearn-finance-smart-contract-security-breach)]According to the security audit firm Hacken, the attacker exploited existing vulnerabilities in the platform smart contracts to siphon tokens out of some of the users’ accounts.
The breach raised serious concerns regarding the security of DeFi platforms, which are becoming increasingly popular among cryptocurrency users. Though the platform, Yearn.finance, had undergone regular security audits, some of the platform’s code still contained vulnerabilities that allowed the attacker to exploit them. As a result, the company was forced to halt its operations while emergency patches were released to prevent further loss of funds. [[2](https://cointelegraph.com/news/yearn-finance-says-it-has-patched-vulnerability-after-being-breached)]
Impact of the Breach on Yearn.finance Users
- Some users lost tokens worth more than $15 million.
- Users who had their funds drained were reimbursed from the platform’s insurance fund.
- The platform also launched an investigation to identify the perpetrators and prevent future attacks.
Impact of the Breach on the DeFi Market
- The attack led to a significant decline in the price of YFI, the governance token of Yearn.finance.
- The incident further reinforced the belief that DeFi protocols are not entirely secure.
- The attack led to increased attention from regulators, who are expected to tighten existing regulations around DeFi platforms.
ZkSync, a cutting-edge layer-two technology, is the latest platform to fall victim to a major exploit. The exploit took advantage of vulnerabilities in the system and caused $3.4 million worth of damage to one of the platform’s largest lenders. As blockchain-based protocols continue to evolve, companies need to remain vigilant in order to prevent similar exploits from occurring in the future.

