zkLend Hack

TOTAL LOST $9.6M
Medium Flash Loan Attacks starknet

What happened

On February 11, 2025, zkLend's Starknet money market was exploited through its newly launched wstETH market. The attacker turned a negligible initial deposit into an overstated collateral position, then borrowed ETH, USDC, USDT, and STRK from the affected pools. zkLend's post-mortem valued the extracted assets at $9,572,151.

Its separate kSTRK liquid-staking product was not affected.

Technical Root Cause

An empty-market initialization path, flash-loan overpayment treated as donated revenue, and floor-rounded share burning composed into an accounting failure. Tiny initial collateral made the accumulator vulnerable to donation-driven inflation, while floor division allowed withdrawals to burn too little raw balance after that inflation. Share accounting must preserve value across deposits, repayments, and withdrawals even at extreme accumulator scales.

Case & protocol details

Classification Empty-Market Accumulator and Share-Accounting Rounding
Protocol Type Lending
Smart Contract Language Cairo
Official Website zklend.com/
Protocol Twitter/X @zkLend

Attack Timeline

zkLend represented collateral as raw balance multiplied by a global lending accumulator. The attacker seeded the empty wstETH market with 1 wei, then repaid flash loans with more than was required. The contract treated each excess repayment as revenue, raising the accumulator from 1.0 to about 4.069e18 after ten flash-loan transactions.

At that scale, carefully selected deposits and withdrawals produced fractional raw-balance burns that floor division rounded down. zkLend documented a withdrawal requiring a burn of 1.5 raw units that burned only 1. Repeating those cycles raised the recorded raw balance to 1,724, representing about 7,015.47 wstETH of collateral and enabling borrowing from the other markets.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.