Zest Hack

Reported loss $1.0M
Stacks
Spot Price Manipulation

What happened

On 11 April 2024 an attacker exploited Zest Protocol, a Bitcoin lending protocol on Stacks, and took about 322,000 STX (roughly $1 million). Zest's borrow function accepted a user-supplied list of collateral assets. By repeating the same entry in that list, the attacker made the contract count the same collateral several times, then borrowed far more STX than the collateral supported. Using multiple accounts, they made five such borrows.

Zest froze its contracts after detecting the attack. It covered the lost STX from the protocol treasury so user balances were unaffected, and started a full re-audit. The team's announcement gave the loss as 324k STX, while its later security update says 322k STX. Zest linked the attacker to a Binance withdrawal: STX the attacker used came from BTC swapped in over the XLink bridge, sent from a Bitcoin address that had earlier received a withdrawal from a Binance-controlled address. CoinFabrik said it had audited Zest's contracts twice before the incident.

How it happened

  1. Zest's borrow entrypoint takes an assets list describing the borrower's collateral. The attacker called it with the same collateral entry repeated several times in that list.
  2. The contract added up collateral value across the list without rejecting duplicates, so it overstated the collateral.
  3. With the inflated collateral value, the attacker borrowed far more STX than allowed.
  4. Using multiple accounts, they repeated this in five borrow transactions and removed about 322k STX.

Protocol details

Classification Oracle Manipulation
Protocol Type DeFi Protocol
Implementation language Clarity
Protocol links Website @zestcoin

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.