T
iTokenly

zkLend hack — February 2025

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedFebruary 11, 2025
Target typeLending protocol
Loss$9,600,000Published estimates range $9,500,000 to $10,000,000Price at time of incident
MethodContract logic errorThree weaknesses combined in a newly launched wstETH market on Starknet: an empty pool let the first deposit set the accounting baseline, unrestricted donations let flash loans inflate the lending accumulator, and the withdrawal path used floor division when burning balances. Repeated deposit-withdraw-redeposit cycles turned the individually negligible rounding loss into a large surplus for the attacker.
ChainsOther
Attributed toUnidentified actor linked by SlowMist to the July 2023 EraLend hackSuspected
OutcomeProject shut down

What happened

zkLend was a money-market lending protocol on Starknet. Its post-mortem places the attack on 11 February 2025, with first contact at 12:44:35 UTC and the decisive borrowing transaction at 15:01:02 UTC; SlowMist dates the incident to 12 February.

The exploit combined three weaknesses in a newly launched wstETH market. Because the pool was empty, the first deposit set the accounting baseline, and the attacker deposited 1 wei of wstETH. Anyone could donate assets to the contract, so the attacker ran ten flash-loan transactions that returned more than was borrowed, inflating the lending accumulator from 1.0 to roughly 4.07 x 10^18. The withdrawal path then used floor division to decide how much of a depositor's raw balance to burn. Individually the rounding loss was negligible; repeated in cycles of depositing, withdrawing 1.5 times the raw balance and redepositing, it let the attacker build a raw balance of 1,724 units representing 7,015.47 wstETH and take out far more than had gone in.

zkLend puts the total at around $9.6 million, comprising 2,213.64 ETH, 1,553,069 USDC, 7,426,030 STRK and 518,226 USDT, of which $9,570,113 was traced to four Ethereum addresses. The team paused the market and worked with zeroShadow, StarkWare and law enforcement including the Hong Kong Police, the FBI and Homeland Security. An offer letting the attacker keep 10 percent went nowhere: in April 2025 SlowMist reported the exploiter had sent 2,930 ETH to a fake Tornado Cash site and lost it.

SlowMist matched the attacker's addresses to those behind the July 2023 EraLend hack and concluded the same actor was responsible. In June 2025 zkLend said it would wind down, citing the exploit and the delisting of its ZEND token, with about $200,000 left in its treasury to support affected users.

Law enforcement

Hong Kong Police, FBI and US Homeland Security, per zkLend's post-mortem

Sources

  1. zkLendPrimary · retrieved 2026-08-01
  2. SlowMistSecondary · retrieved 2026-08-01
  3. DL NewsSecondary · retrieved 2026-08-01

Official post-mortem: https://medium.com/zklend/zklend-security-incident-post-mortem-27d9abaf66f6

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "zkLend hack — February 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/zklend
https://itokenly.com/hacks/zklend

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.