BlockNews
FOLLOW ON X
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • SUI
    • CHAINLINK
    • LITECOIN
  • FINANCE
  • POLITICS
  • MEMECOINS
  • NFT
  • OPINION
No Result
View All Result
BlockNews
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • SUI
    • CHAINLINK
    • LITECOIN
  • FINANCE
  • POLITICS
  • MEMECOINS
  • NFT
  • OPINION
No Result
View All Result
BlockNews
Home BREAKING NEWS

zkSync Lending Protocol EraLend Hacked

BlockNews Team by BlockNews Team
September 28, 2023
in BREAKING NEWS, CRYPTO, FINANCE
Reading Time: 4 mins read
1
SHARES
21
VIEWS
Share on XShare in TelegramShare on Reddit
  • The most significant lending protocol on the Ethereum L2 network zkSync has been hacked.
  • An attacker has exploited the protocol through a read-only reentrancy attack.
  • Losses so far have amounted to $3.4 million in stolen USDC tokens, and EraLend has temporarily suspended all borrowing operations.

EraLend, a prominent lending protocol built on the L2 zkSync, has fallen victim to a security breach that resulted in a significant loss of funds. As the platform addresses the situation, it has taken swift action by suspending all borrowing operations and cautioning users against USDC deposits.

🚨Security Update: We've experienced a security incident on our platform today. The threat has been contained. We've suspended all borrowing operations for now and advise against depositing USDC. We're working with partners and cybersecurity firms to address this.
More updates…

— EraLend | The #1 Money Market on zkSync🥇 (@Era_Lend) July 25, 2023
Via @Era_Lend – Twitter

The incident was identified as a read-only reentrancy attack, leading to approximately $3.4 million in losses.

We are assisting @Era_Lend to this issue, and the root cause has been identified. The total loss is ~$3.4M.
Specifically, this is a read-only re-entrancy attack.
Another attack tx is:https://t.co/H4A2suVLai
Attacker address:
0xf1D076c9Be4533086f967e14EE6aFf204D5ECE7a https://t.co/InhCCW7QAy

— BlockSec (@BlockSecTeam) July 25, 2023
Via @BlockSecTeam – Twitter

Attack Explained

A read-only reentrancy attack is a security vulnerability that can be exploited on smart contract platforms like Ethereum. In a read-only reentrancy attack, malicious actors use a smart contract’s external call functionality to manipulate its state to allow them to repeatedly read and gather sensitive data from the contract without incurring any costs.

The attack unfolds when the attacker initiates a transaction with the vulnerable smart contract and makes an external call during this interaction. The external call may trigger recursive calls back to the vulnerable contract, enabling the attacker to read and gather sensitive data contained within the contract.

The attacker can then call the external function recursively, creating a reentrancy loop that allows them to repeatedly access the sensitive data without paying any gas fees, as the external calls are executed within the same transaction.

The potential impact of read-only reentrancy attacks lies in the sensitive data the vulnerable smart contract may hold. For instance, if the contract contains private keys or user data, the attacker could exploit the vulnerability to access and collect this information repeatedly.

The Broader Crypto Security Landscape

The EraLend hack serves as another reminder of the constant security threats faced by cryptocurrency platforms. As the industry witnesses daily hacking events, protocols, and companies continually enhance their security measures to safeguard users’ funds and data. This incident highlights the importance of robust security practices and the need for coordinated efforts within the crypto community to combat such attacks effectively.

A common strategy to mitigate read-only reentrancy attacks is the “Checks-Effects-Interactions” pattern, which ensures that any state-changing operations are performed before any external calls are made, reducing the risk of reentrancy attacks. Developers can also use modifiers to enforce access controls, limit who can call specific functions, and implement withdrawal patterns to handle user withdrawals securely.

Third-party security audits play a crucial role in identifying potential vulnerabilities and improving the overall security of smart contracts. Engaging reputable security auditors to review the code can help identify and address potential weaknesses, reducing the risk of successful attacks.

Conclusion

As EraLend navigates through the aftermath of the security incident, the platform remains vigilant in resolving the situation and safeguarding user assets. The attack’s impact, amounting to $3.4 million in losses, is a stark reminder of the security challenges inherent in cryptocurrency.

In response, EraLend has temporarily suspended borrowing operations and seeks to collaborate with cybersecurity firms to address the breach. As the crypto community stands united against such threats, the incident underscores the collective responsibility to fortify security measures across all platforms in the ever-evolving digital financial landscape.

Tags: EraLendHackL2zkSync
TweetShareShare
BlockNews Team

BlockNews Team

DON'T MISS THESE! HOT OFF THE PRESS

TRON Holds Strong After $1.4B Whale Cash-Out
CRYPTO

TRON Holds Strong After $1.4B Whale Cash-Out

August 31, 2025
Cardano ETF Odds Jump to 87% as ADA Eyes Breakout
CARDANO

Cardano ETF Odds Jump to 87% as ADA Eyes Breakout

August 31, 2025
Dogecoin vs Shiba Inu: Two Meme Giants on Very Different Paths
CRYPTO

Dogecoin vs Shiba Inu: Two Meme Giants on Very Different Paths

August 31, 2025
Solana Surpasses Ethereum in Staking Market Cap
CRYPTO

Solana Surpasses Ethereum in Staking Market Cap

August 31, 2025
XRP Consolidates at $2.8 as Derivatives Signal the Next Big Move
CRYPTO

XRP Consolidates at $2.8 as Derivatives Signal the Next Big Move

August 31, 2025
XRP Battles to Hold $2.74 as Bearish Pressure Mounts
CRYPTO

XRP Battles to Hold $2.74 as Bearish Pressure Mounts

August 31, 2025
Load More

Related News

TRON Holds Strong After $1.4B Whale Cash-Out

TRON Holds Strong After $1.4B Whale Cash-Out

August 31, 2025
Cardano ETF Odds Jump to 87% as ADA Eyes Breakout

Cardano ETF Odds Jump to 87% as ADA Eyes Breakout

August 31, 2025
Dogecoin vs Shiba Inu: Two Meme Giants on Very Different Paths

Dogecoin vs Shiba Inu: Two Meme Giants on Very Different Paths

August 31, 2025
Solana Surpasses Ethereum in Staking Market Cap

Solana Surpasses Ethereum in Staking Market Cap

August 31, 2025
XRP Consolidates at $2.8 as Derivatives Signal the Next Big Move

XRP Consolidates at $2.8 as Derivatives Signal the Next Big Move

August 31, 2025
Twitter Telegram Threads

BLOCKNEWS.COM

BlockNews is your premier source for real-time cryptocurrency, blockchain, political and financial market news.

Stay ahead of the herd with BlockNews

RESOURCES

  • About
  • Contact Us
  • Terms and Conditions
  • Privacy Policy

© 2025 BlockNews

No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • LITECOIN
    • CHAINLINK
    • SUI
  • MEMECOINS
  • POLITICS
  • FINANCE
  • NFT
  • DEFI
  • GUIDES

© 2025 BlockNews