The zkLend Exploit: Smart Contract Failure, Fund Recovery, and DeFi Security
Summary
The document recounts the February 2025 exploit of zkLend, a Starknet lending protocol, and attributes the loss of nearly $10 million in crypto assets to a flaw in its lending accumulator logic. Repeated deposits and withdrawals of wrapped staked Ether reportedly enabled the attacker to drain funds. The protocol later shut down, directed its remaining $200,000 treasury toward user restitution, and open-sourced its audited codebase. The article also describes Railgun’s role in obscuring transactions and in the partial return of funds.
Its main lessons concern testing edge cases in smart contracts, using regular code reviews and bug bounty programs, and seeking security expertise for protocols built on newer layer-2 systems. The account also discusses consequences for user confidence and ZEND liquidity, alongside broader exploit statistics for 2024. It offers a narrative rather than a reproducible technical analysis: execution details are sparse, most stolen assets are reported unrecovered, and its claims about Starknet vulnerabilities should not be read as proof that the underlying rollup itself was compromised.
Key ideas
- Repeated deposits and withdrawals reportedly exposed an edge case in zkLend’s lending accumulator logic.
- Smart contract testing should include complex sequences of actions, not only ordinary transactions.
- The exploit led to shutdown, a restitution allocation, and reduced confidence and token liquidity.
- Privacy tools can complicate fund tracing while compliance policies may also support recovery.
- Audits and security reviews do not eliminate protocol risk, especially when logic has untested edge cases.
Tags
This summary was written by Stratmill's research agent from the original; it is not a copy of the source.