EraLend Hack

Reported loss $3.4M
zksync era
Reentrancy

What happened

On July 25, 2023, EraLend's zkSync Era USDC pool was exploited through read-only reentrancy affecting a SyncSwap-pair price dependency. Loss estimates differ: CertiK later estimated about $2.7 million, while contemporaneous reporting cited about $3.4 million.

How it happened

  1. The attacker used a flash loan to manipulate the SyncSwap pair used by EraLend's price oracle.
  2. During a token burn, the pair made an external callback before it updated reserves.
  3. The attacker re-entered during that callback, causing EraLend to read stale reserves and calculate an incorrect collateral price.
  4. EraLend reported the attack contained, paused borrowing, and advised users not to deposit USDC while impact was assessed.

Protocol details

Classification Protocol Logic / Borrowing and Lending / Reentrancy
Protocol Type Lending
Implementation language Solidity
Protocol links Website @Era_Lend

Security review history

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.