Zest Hack
What happened
On 11 April 2024 an attacker exploited Zest Protocol, a Bitcoin lending protocol on Stacks, and took about 322,000 STX (roughly $1 million). Zest's borrow function accepted a user-supplied list of collateral assets. By repeating the same entry in that list, the attacker made the contract count the same collateral several times, then borrowed far more STX than the collateral supported. Using multiple accounts, they made five such borrows.
Zest froze its contracts after detecting the attack. It covered the lost STX from the protocol treasury so user balances were unaffected, and started a full re-audit. The team's announcement gave the loss as 324k STX, while its later security update says 322k STX. Zest linked the attacker to a Binance withdrawal: STX the attacker used came from BTC swapped in over the XLink bridge, sent from a Bitcoin address that had earlier received a withdrawal from a Binance-controlled address. CoinFabrik said it had audited Zest's contracts twice before the incident.
How it happened
- Zest's
borrowentrypoint takes anassetslist describing the borrower's collateral. The attacker called it with the same collateral entry repeated several times in that list. - The contract added up collateral value across the list without rejecting duplicates, so it overstated the collateral.
- With the inflated collateral value, the attacker borrowed far more STX than allowed.
- Using multiple accounts, they repeated this in five borrow transactions and removed about 322k STX.
Protocol details
Evidence
- report Zest Protocol on X: attacker removed 324k STX, to be reimbursed from treasury (fxtwitter mirror) twitter.com
- report The First Attack on Bitcoin DeFi Smart Contract (ExVul, Medium RSS) medium.com
- report CoinFabrik on X: Zest Protocol exploit, we audited their contracts twice (fxtwitter mirror) x.com
- analysis DeFiLlama defillama.com
- analysis Zest Protocol Security Update zestprotocol.com
- analysis www.zestcoin.io page www.ze…n.io zestcoin.io
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.