EraLend hack — July 2023
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | July 25, 2023 |
| Target type | Lending protocol |
| Loss | $2,700,000Published estimates range $2,700,000 to $3,400,000Price at time of incident |
| Method | ReentrancyRead-only reentrancy against a SyncSwap liquidity pair used as EraLend's price source: the pair makes an external callback during a burn before _updateReserves runs, so a contract re-entering in that window reads stale reserves. The attacker used a flash loan to move the pair and had EraLend price collateral off the distorted reserves. |
| Chains | Other |
| Outcome | Project relaunched |
What happened
On 25 July 2023 an attacker exploited EraLend, then the largest lending protocol on zkSync Era. EraLend confirmed the incident the same day, said the threat had been contained, suspended all borrowing and advised users not to deposit USDC. It has never published its own figure for the loss.
The published estimates disagree, and both come from the same firm. CoinDesk reported about $3.4 million on the day, attributing that figure to CertiK, and The Block, DL News and rekt.news carried the same number. CertiK's subsequent incident analysis puts the loss at approximately $2.7 million. CoinDesk noted that capital locked in the protocol fell from $18.5 million to $10.75 million after the attack, though that reflects user withdrawals as well as stolen funds.
Per CertiK's analysis the attack was a read-only reentrancy. EraLend derived prices from a SyncSwap liquidity pair. During a burn, the pair contract makes an external callback before it calls _updateReserves, so a contract receiving that callback can query the pair while its reserve figures are still stale. The attacker used a flash loan to move the pair, re-entered inside that callback window, and had EraLend read the distorted reserves, which inflated the value of the collateral it would lend against. The proceeds were moved off zkSync Era to Ethereum, Arbitrum and Optimism, and consolidated mainly into four Ethereum wallets.
EraLend redeployed with a new version audited by PeckShield. The exploited deployment was renamed EraLend Classic, with lending and borrowing disabled from 8 August 2023 at 00:00 UTC but repayment and withdrawal left open until users had exited. The team committed 100 percent of the protocol fee on the new deployment to compensating victims, alongside 30 percent of any future zkSync airdrop earned through its points programme and diversified platform income, and engaged SlowMist to trace the stolen assets.
Sources
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "EraLend hack — July 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/eralendhttps://itokenly.com/hacks/eralendPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.