zkLend, a decentralized finance protocol on Starknet, experienced a major security breach, losing approximately 3700 ETH. The platform has temporarily paused withdrawals.
Response to the Exploit
zkLend confirmed the incident in a series of X posts on February 11, stating millions worth of cryptocurrency had been drained from its smart contracts. The platform recommended users to refrain from depositing or repaying funds while investigations continue, and all withdrawals were paused.
Technical Details of the Breach
The exploit affected several DeFi strategies linked to zkLend, including STRKFarm strategies. According to QuillAudits, the attacker using address 0x64…9109 initially targeted contract 0x04…3b26, then moved assets to Ethereum via the Railgun mixer to obscure transactions.
Whitehat Bounty Offer
In an effort to recover the funds, zkLend issued a message to the hacker offering a 10% whitehat bounty, allowing the hacker to keep about 400 ETH if the remaining 3300 ETH is returned. Past precedents seen similar offers, although often they have not been successful.
The zkLend team remains proactive in recovering the funds and mitigating the hack's impact, working with several organizations to track down the perpetrators and retrieve the stolen assets.