Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Crypto use explodes beyond trading – Tokenization is up 248%, reaching $30B

April 18, 2026

US should scrap crypto capital gains tax to fuel competition: Cato

April 18, 2026

HashKey Chain Joins HabitTrade to Advance Adoption of RWAs On-Chain

April 18, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Era Lend on zkSync exploited for $3.4M in reentrancy attack
Security and Privacy

Era Lend on zkSync exploited for $3.4M in reentrancy attack

July 25, 2023No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Lending app Era Lend on zkSync has been exploited for $3.4 million worth of crypto, according to a July 25 report from blockchain security firm CertiK. The attacker used a “read-only reentrancy attack” to drain the funds, which is a type of attack that interrupts a multi-step process and then causes it to continue after a malicious action has been performed. Specifically, a “read-only” reentrancy is one that does not update the state of a contract.

#CertiKSkynetAlert

We are seeing reports that @Era_Lend has been exploited on zkSync

Total losses appear to be $3.4 million in a read only reentrancy attack

See more below https://t.co/h8xrjccE5i

— CertiK Alert (@CertiKAlert) July 25, 2023

According to the report, the attacker drained funds in two separate transactions using the externally owned account 0xf1D076c9Be4533086f967e14EE6aFf204D5ECE7a. The attacker relied on a vulnerability in “the callback and _updateReserves function” to manipulate a contract into reporting old values that had not yet been updated.

Era Lend is a fork of the Syncswap project, and CertiK claimed that other projects based on Syncswap may also be vulnerable to the exploit.

On-chain sleuth and Twitter user Spreek reported that the Syncswap code allows a user to “burn, then callback before update_reserves is called,” causing the oracle to report incorrect values.

in the syncswap LP tokens, one can burn, then callback before update_reserves is called. so the oracle uses an incorrect reserves value to calculate the price, resulting in an inflating oracle price. pic.twitter.com/0U7Vu7BzJM

— Spreek (@spreekaway) July 25, 2023

Spreek also reported that the Era Lend team had acknowledged the attack and paused the protocol’s zkSync contracts to prevent further exploits.

See also  Early Bitcoin Miner Apparently Sent 1,000 ‘Satoshi Era’ BTC to Trading Desks This Week

Another blockchain investigator, known on Twitter as Saul, reported that the attack had affected stablecoin USDC+, which is issued by the Overnight Finance protocol. According to Saul, the Overnight team has acknowledged the exposure and has paused its own contracts as well. Over $261,000, or 7.86% of the total value of the collateral backing the stablecoin, may have been lost.

In a June 7 blog post explaining how read-only reentrancy attacks are carried out, pseudonymous blockchain investigator Officer’s Notes stated that these vulnerabilities are difficult for auditors to spot, since “Typically, auditors and bug hunters are only concerned with entry points that modify state when looking for reentrancy.”

To help alleviate this problem, Officer’s Notes recommends that auditors use specialized software to aid them in finding these vulnerabilities.

Era Lend runs on the zkSync network, a zero-knowledge proof Ethereum layer-2 rollup. In April, the network’s total value locked reached over $110 million. The network’s developers intend to create an ecosystem of interoperable chains called “Hyperchains” by the end of the year.

Collect this article as an NFT to preserve this moment in history and show your support for independent journalism in the crypto space.

Source link

3.4M Attack Era exploited Lend reentrancy zkSync
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Cookeville Hospital Discloses Rhysida Breach Hitting 337,917

April 16, 2026

Kraken is actively being extorted by criminals threatening to release the top crypto exchange’s internal data

April 14, 2026

Securitize Expands to TRON, Unlocking New Era for Tokenized Securities

April 13, 2026

Operation Atlantic Seizes $12m in Crypto Losses

April 13, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Nimble Network Starts a Collaboration with TARS Protocol for Web3 Integration

May 14, 2024

Whales gather around Arbitrum – What’s brewing?

November 4, 2023

Massa Labs Teams Up with Starknet to Forge Next-Gen Blockchain Solutions

May 7, 2024

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Crypto use explodes beyond trading – Tokenization is up 248%, reaching $30B

April 18, 2026

US should scrap crypto capital gains tax to fuel competition: Cato

April 18, 2026

HashKey Chain Joins HabitTrade to Advance Adoption of RWAs On-Chain

April 18, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$77,028.002.56%
  • ethereumEthereum(ETH)$2,403.892.87%
  • tetherTether(USDT)$1.000.00%
  • rippleXRP(XRP)$1.472.60%
  • binancecoinBNB(BNB)$643.202.35%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$88.320.05%
  • tronTRON(TRX)$0.3274810.84%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02-1.21%
  • dogecoinDogecoin(DOGE)$0.0988130.73%