Zoth Hack

TOTAL LOST $285K
Low Oracle Manipulation & Price Manipulation

What happened

On March 1, 2025, Zoth, a restaking layer for real-world assets (RWAs), was exploited for approximately $285,000.

The vulnerability stemmed from Zoth’s reliance on the initial stablecoin deposit amount rather than the actual collateral received after a swap when validating LTV ratios. By manipulating Uniswap V3 pool prices, the attacker caused the swap to return only 7,669 collateral tokens, but the protocol incorrectly recorded 330,979 tokens as received collateral. This inflated value allowed the attacker to mint excess ZeUSD far beyond their actual backing.

After minting, they burned the ZeUSD to withdraw the falsely recorded collateral, ultimately profiting $285,000. The absence of slippage checks and post-swap collateral validation made this attack possible.

Exploit tx:

https://etherscan.io/tx/0xc3f70057…88fb39

Case & protocol details

Classification Other
Protocol Type Exploit/Oracle Issue
Official Website zoth.io/
Protocol Twitter/X @zothdotio

Evidence & learning

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.