EraLend Hack
Reported loss
$3.4M
Reentrancy
What happened
On July 25, 2023, EraLend's zkSync Era USDC pool was exploited through read-only reentrancy affecting a SyncSwap-pair price dependency. Loss estimates differ: CertiK later estimated about $2.7 million, while contemporaneous reporting cited about $3.4 million.
How it happened
- The attacker used a flash loan to manipulate the SyncSwap pair used by EraLend's price oracle.
- During a token burn, the pair made an external callback before it updated reserves.
- The attacker re-entered during that callback, causing EraLend to read stale reserves and calculate an incorrect collateral price.
- EraLend reported the attack contained, paused borrowing, and advised users not to deposit USDC while impact was assessed.
Protocol details
Security review history
- PeckShield View report
Evidence
- report @DLNewsInfo incident report twitter.com
- report @BlockSecTeam incident report twitter.com
- report @SaulCapital incident report twitter.com
- analysis DeFiLlama defillama.com
- analysis EraLend Incident Analysis certik.com
- analysis ZkSync-based Era Lend loses $3.4 million in DeFi exploit theblock.co
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.