Zoth hack — March 2025
Incident facts
| Date of incident | |
|---|---|
| Target type | Stablecoin or yield protocol |
| Loss | $8,400,000Published estimates range $8,400,000 to $8,850,000Price at time of incident |
| Method | Private key compromiseThe private key controlling Zoth's deployer address, which held admin rights over the protocol's proxy contracts, was compromised; the attacker used it to upgrade a Zoth vault proxy to an implementation they had deployed roughly half an hour earlier, giving them direct control of the vault balance. |
| Chains | Ethereum |
| Outcome | Unresolved |
What happened
On 21 March 2025 an attacker emptied a vault belonging to Zoth, a real-world-asset restaking protocol on Ethereum, of USD0++ that backed its ZeUSD product.
The private key controlling Zoth's deployer address had been compromised, and that address held admin rights over the protocol's proxy contracts. Cyvers, which flagged the transaction, said a Zoth contract "was upgraded to a malicious version deployed by a suspicious address" about thirty minutes before the withdrawal. Once the implementation had been swapped the attacker could move the vault's balance directly. The proceeds were converted to DAI, sent to another address and then swapped into ether, 4,223 ETH by one on-chain count. How the key was obtained has not been established publicly.
Published figures differ. Cyvers put the loss at about $8.4 million and that number was the most widely repeated, with Halborn's write-up giving the same figure; other on-chain analyses reported $8.85 million of USD0++ leaving the contract. Zoth said on X that its "system has experienced a security breach", that it was working with partners, and promised a detailed report.
This was the second incident at Zoth that month. On 6 March a separate flaw allowed synthetic assets to be minted without sufficient collateral, costing about $285,000. In May 2025 Zoth announced a compensation programme for affected users and a phased relaunch of ZeUSD. No funds have been reported recovered and no one has been identified.
Sources
- CointelegraphSecondary · retrieved 2026-08-01
- CryptoSlateSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
- ZothPrimary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Zoth hack — March 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/zothhttps://itokenly.com/hacks/zothPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.