zkLend Hack
What happened
On February 11, 2025, zkLend's Starknet money market was exploited through its newly launched wstETH market. The attacker turned a negligible initial deposit into an overstated collateral position, then borrowed ETH, USDC, USDT, and STRK from the affected pools. zkLend's post-mortem valued the extracted assets at $9,572,151.
Its separate kSTRK liquid-staking product was not affected.
An empty-market initialization path, flash-loan overpayment treated as donated revenue, and floor-rounded share burning composed into an accounting failure. Tiny initial collateral made the accumulator vulnerable to donation-driven inflation, while floor division allowed withdrawals to burn too little raw balance after that inflation. Share accounting must preserve value across deposits, repayments, and withdrawals even at extreme accumulator scales.
Case & protocol details
Attack Timeline
zkLend represented collateral as raw balance multiplied by a global lending accumulator. The attacker seeded the empty wstETH market with 1 wei, then repaid flash loans with more than was required. The contract treated each excess repayment as revenue, raising the accumulator from 1.0 to about 4.069e18 after ten flash-loan transactions.
At that scale, carefully selected deposits and withdrawals produced fractional raw-balance burns that floor division rounded down. zkLend documented a withdrawal requiring a burn of 1.5 raw units that burned only 1. Repeating those cycles raised the recorded raw balance to 1,724, representing about 7,015.47 wstETH of collateral and enabling borrowing from the other markets.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- report Post-mortem medium.com
- report BlockSec zkLend exploit post-mortem blocksec.com
- report Post-mortem medium.com
- analysis Website reference x.com
- analysis Blog reference blog.solidityscan.com
- analysis Verichains zkLend incident analysis blog.verichains.io
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.