BlockNews
FOLLOW ON X
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • SUI
    • CHAINLINK
    • LITECOIN
  • FINANCE
  • POLITICS
  • MEMECOINS
  • NFT
  • OPINION
No Result
View All Result
BlockNews
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • SUI
    • CHAINLINK
    • LITECOIN
  • FINANCE
  • POLITICS
  • MEMECOINS
  • NFT
  • OPINION
No Result
View All Result
BlockNews
Home BREAKING NEWS

zkSync Lending Protocol EraLend Hacked

BlockNews Team by BlockNews Team
September 28, 2023
in BREAKING NEWS, CRYPTO, FINANCE
Share on XShare in TelegramShare on Reddit
  • The most significant lending protocol on the Ethereum L2 network zkSync has been hacked.
  • An attacker has exploited the protocol through a read-only reentrancy attack.
  • Losses so far have amounted to $3.4 million in stolen USDC tokens, and EraLend has temporarily suspended all borrowing operations.

EraLend, a prominent lending protocol built on the L2 zkSync, has fallen victim to a security breach that resulted in a significant loss of funds. As the platform addresses the situation, it has taken swift action by suspending all borrowing operations and cautioning users against USDC deposits.

🚨Security Update: We've experienced a security incident on our platform today. The threat has been contained. We've suspended all borrowing operations for now and advise against depositing USDC. We're working with partners and cybersecurity firms to address this.
More updates…

— EraLend | The #1 Money Market on zkSync🥇 (@Era_Lend) July 25, 2023
Via @Era_Lend – Twitter

The incident was identified as a read-only reentrancy attack, leading to approximately $3.4 million in losses.

We are assisting @Era_Lend to this issue, and the root cause has been identified. The total loss is ~$3.4M.
Specifically, this is a read-only re-entrancy attack.
Another attack tx is:https://t.co/H4A2suVLai
Attacker address:
0xf1D076c9Be4533086f967e14EE6aFf204D5ECE7a https://t.co/InhCCW7QAy

— BlockSec (@BlockSecTeam) July 25, 2023
Via @BlockSecTeam – Twitter

Attack Explained

A read-only reentrancy attack is a security vulnerability that can be exploited on smart contract platforms like Ethereum. In a read-only reentrancy attack, malicious actors use a smart contract’s external call functionality to manipulate its state to allow them to repeatedly read and gather sensitive data from the contract without incurring any costs.

The attack unfolds when the attacker initiates a transaction with the vulnerable smart contract and makes an external call during this interaction. The external call may trigger recursive calls back to the vulnerable contract, enabling the attacker to read and gather sensitive data contained within the contract.

The attacker can then call the external function recursively, creating a reentrancy loop that allows them to repeatedly access the sensitive data without paying any gas fees, as the external calls are executed within the same transaction.

The potential impact of read-only reentrancy attacks lies in the sensitive data the vulnerable smart contract may hold. For instance, if the contract contains private keys or user data, the attacker could exploit the vulnerability to access and collect this information repeatedly.

The Broader Crypto Security Landscape

The EraLend hack serves as another reminder of the constant security threats faced by cryptocurrency platforms. As the industry witnesses daily hacking events, protocols, and companies continually enhance their security measures to safeguard users’ funds and data. This incident highlights the importance of robust security practices and the need for coordinated efforts within the crypto community to combat such attacks effectively.

A common strategy to mitigate read-only reentrancy attacks is the “Checks-Effects-Interactions” pattern, which ensures that any state-changing operations are performed before any external calls are made, reducing the risk of reentrancy attacks. Developers can also use modifiers to enforce access controls, limit who can call specific functions, and implement withdrawal patterns to handle user withdrawals securely.

Third-party security audits play a crucial role in identifying potential vulnerabilities and improving the overall security of smart contracts. Engaging reputable security auditors to review the code can help identify and address potential weaknesses, reducing the risk of successful attacks.

Conclusion

As EraLend navigates through the aftermath of the security incident, the platform remains vigilant in resolving the situation and safeguarding user assets. The attack’s impact, amounting to $3.4 million in losses, is a stark reminder of the security challenges inherent in cryptocurrency.

In response, EraLend has temporarily suspended borrowing operations and seeks to collaborate with cybersecurity firms to address the breach. As the crypto community stands united against such threats, the incident underscores the collective responsibility to fortify security measures across all platforms in the ever-evolving digital financial landscape.

Disclaimer: BlockNews provides independent reporting on crypto, blockchain, and digital finance. All content is for informational purposes only and does not constitute financial advice. Readers should do their own research before making investment decisions. Some articles may use AI tools to assist in drafting, but every piece is reviewed and edited by our editorial team of experienced crypto writers and analysts before publication.
Tags: EraLendHackL2zkSync
Tweet1ShareShare
BlockNews Team

BlockNews Team

DON'T MISS THESE! HOT OFF THE PRESS

Schwab Boosts Strategy Bitcoin Bet – Here Is What It Means for Crypto
BITCOIN

Schwab Boosts Strategy Bitcoin Bet – Here Is What It Means for Crypto

February 17, 2026
American Bitcoin Surpasses 6,000 BTC – Here Is Why This Crypto Bet Matters
BITCOIN

American Bitcoin Surpasses 6,000 BTC – Here Is Why This Crypto Bet Matters

February 17, 2026
The Fed Quietly Drops $16 Billion Into Markets and People Still Pretend Liquidity Doesn’t Matter
CRYPTO

The Fed Quietly Drops $16 Billion Into Markets and People Still Pretend Liquidity Doesn’t Matter

February 17, 2026
Dragonfly Raising $650 Million in a Bear Market Tells You Exactly Who’s Actually Confident
CRYPTO

Dragonfly Raising $650 Million in a Bear Market Tells You Exactly Who’s Actually Confident

February 17, 2026
BitMine’s Massive Ethereum Stash Is a Blunt Message to Markets Still Ignoring Yield
CRYPTO

BitMine’s Massive Ethereum Stash Is a Blunt Message to Markets Still Ignoring Yield

February 17, 2026
Bitmine Buys $90M in Ethereum – Here Is Why Tom Lee Sees 2026 as Crypto’s Year
CRYPTO

Bitmine Buys $90M in Ethereum – Here Is Why Tom Lee Sees 2026 as Crypto’s Year

February 17, 2026
Load More

Related News

Schwab Boosts Strategy Bitcoin Bet – Here Is What It Means for Crypto

Schwab Boosts Strategy Bitcoin Bet – Here Is What It Means for Crypto

February 17, 2026
American Bitcoin Surpasses 6,000 BTC – Here Is Why This Crypto Bet Matters

American Bitcoin Surpasses 6,000 BTC – Here Is Why This Crypto Bet Matters

February 17, 2026
The Fed Quietly Drops $16 Billion Into Markets and People Still Pretend Liquidity Doesn’t Matter

The Fed Quietly Drops $16 Billion Into Markets and People Still Pretend Liquidity Doesn’t Matter

February 17, 2026
Dragonfly Raising $650 Million in a Bear Market Tells You Exactly Who’s Actually Confident

Dragonfly Raising $650 Million in a Bear Market Tells You Exactly Who’s Actually Confident

February 17, 2026
BitMine’s Massive Ethereum Stash Is a Blunt Message to Markets Still Ignoring Yield

BitMine’s Massive Ethereum Stash Is a Blunt Message to Markets Still Ignoring Yield

February 17, 2026
Twitter Telegram Threads

BLOCKNEWS.COM

BlockNews is your premier source for real-time cryptocurrency, blockchain, political and financial market news.

Stay ahead of the herd with BlockNews

RESOURCES

  • About Us
  • Contact Us
  • Editorial Policies
  • Terms and Conditions
  • Privacy Policy
  • Sitemap

DISCLOSURES AND POLICIES

BlockNews provides independent reporting on crypto, blockchain, and digital finance. Content is for informational purposes only and does not constitute financial advice. Sponsored material is always disclosed. By using this site, you agree to our Terms and Conditions and Privacy Policy.

© 2025 BlockNews

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • LITECOIN
    • CHAINLINK
    • SUI
  • MEMECOINS
  • POLITICS
  • FINANCE
  • NFT
  • DEFI
  • GUIDES

© 2025 BlockNews