SlowMist|2月 12, 2025 12:55
🚨SlowMist Security Alert🚨
The lending project @zkLend on the Starknet chain was attacked today, with more than 9 million in assets lost!
The SlowMist security team found that the core reason for this attack lies in the safeMath library adopted by the market contract. When performing division calculations, it uses direct division, resulting in a rounding-down vulnerability when calculating the actual amount of zToken that needs to be burned during the withdrawal operation. Attackers may exploit this vulnerability to illegally obtain benefits.🧐
Please users pay close attention to the status of their assets on zkLend, temporarily stop operations such as deposits related to zkLend to avoid possible losses.⚠️
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink