Zoth ZeUSD Hack

Reported loss $8.8M
Ethereum
Private Key Compromised (Unknown Method)

What happened

On March 21, 2025, Zoth's Ethereum vault lost approximately $8.85 million in USD0++ after a malicious proxy upgrade. Halborn attributed the upgrade to compromise of the deployer key. This was separate from the smaller Zoth exploit earlier that month.

Technical root cause

The upgrade authority could replace the code controlling vault assets. Halborn identified a compromised deployer key, but the method used to obtain that key was not established.

How it happened

  1. Control of the deployer key allowed the attacker to replace the vault's proxy implementation.
  2. The malicious implementation enabled withdrawal of its USD0++ holdings.
  3. The attacker exchanged the assets for DAI and then ETH.

Protocol details

Classification Infrastructure / Key Compromise / Other
Protocol Type CDP
Implementation language Solidity
Protocol links Website @zothdotio

Security review history

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.