Thursday, July 30, 2026

zkLend shuts down amid exploit fallout and delistings, remaining $200k redirected to users

Published:

[ad_1]

Lending protocol zkLend acknowledged in a June 25 put up on X that it will wind down its operations and direct its remaining $200,000 treasury to a fund for users affected by a February safety breach. 

The workforce mentioned the exploit “deeply eroded user confidence” and ZEND’s delisting from Bybit and KuCoin amplified the damaging sentiment inflicting a vital decline in the capital and liquidity wanted for new merchandise.

Liquidity squeeze and determination to give up

While zkLend assessed restoration choices, Bybit and KuCoin eliminated the ZEND token from their spot markets, sharply lowering buying and selling depth and reducing off a path to increase contemporary liquidity. 

The workforce mentioned these constraints made a relaunch unrealistic. Instead, zkLend will preserve its DeFi Spring, restoration, and kSTRK portals on-line, permitting users to unstake property or declare balances. 

It also retained safety outfit zeroShadow to hint any remaining stolen cash, pledging to route future recoveries to the consumer fund.

zkLend plans to publish its refreshed, audited codebase as open-source “in the coming weeks” for any developer who desires to construct on the framework. The workforce added that it will “remain online and committed to the recovery of stolen funds through any means necessary,” but will not restart its money-market operations.

The determination marks the finish of zkLend’s four-year run on Starknet and formalizes the shift from rebuilding the protocol to compensating users through the restoration pool.

Exploit drained 3,300 ETH

On Feb.12, an attacker used a precision rounding flaw in zkLend’s Starknet contracts to drain about 3,300 ETH, value roughly $9.5 million at the time. The exploiter bridged the property to Ethereum and routed them through the privateness software Railgun. 

zkLend supplied the exploiter a 10% bounty if 90% of the funds have been returned by February 14, warning that it would pursue authorized motion if the deadline handed. The funds by no means got here back, and the protocol halted withdrawals while it labored with safety agency Cyvers, regulation enforcement companies, and on-chain investigators.

The investigation produced an surprising twist on April 1 when zkLend reported that the attacker misplaced 2,930 ETH to a phishing website impersonating Tornado Cash

Blockchain analytics agency Lookonchain confirmed the loss, and the attacker despatched an on-chain message admitting the mistake, stating he misplaced all the funds. He added: “I’m devastated and sorry.” 

The breach left users locked out of their deposits, and the protocol’s status suffered as a end result.

The put up zkLend shuts down amid exploit fallout and delistings, remaining $200k redirected to users appeared first on CryptoSlate.

[ad_2]

Read more

BlockBuzzed
BlockBuzzedhttps://blockbuzzed.com
Bringing you the latest trends, insights, and updates from the world of blockchain and cryptocurrency, the BlockBuzzed team is passionate about making digital assets accessible and understandable for everyone. Whether breaking news, in-depth guides, or expert analysis, our authors strive to empower readers with timely and accurate information.

Related articles

Recent articles