Zoth Hack
What happened
On March 1, 2025, Zoth, a restaking layer for real-world assets (RWAs), was exploited for approximately $285,000.
The vulnerability stemmed from Zoth’s reliance on the initial stablecoin deposit amount rather than the actual collateral received after a swap when validating LTV ratios. By manipulating Uniswap V3 pool prices, the attacker caused the swap to return only 7,669 collateral tokens, but the protocol incorrectly recorded 330,979 tokens as received collateral. This inflated value allowed the attacker to mint excess ZeUSD far beyond their actual backing.
After minting, they burned the ZeUSD to withdraw the falsely recorded collateral, ultimately profiting $285,000. The absence of slippage checks and post-swap collateral validation made this attack possible.
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report blog.solidityscan.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.