SlowMist: The core reason for the attack on zkLend is that the market contract uses the safeMath library
This article is machine translated
Show original
Odaily reported that the lending project zkLend on the Starknet chain was attacked today, resulting in the theft of over $9 million. Slowmist released an analysis on the X platform, stating that the core reason for this attack was the use of the safeMath library in the market contract. When performing division calculations, the use of direct division led to a rounding-down vulnerability in calculating the actual number of zTokens to be destroyed during withdrawal operations. The attacker may have exploited this vulnerability to illegally obtain profits. Slowmist reminds users to closely monitor the status of their assets on zkLend and temporarily suspend any related deposit activities to avoid potential losses.
Source
Disclaimer: The content above is only the author's opinion which does not represent any position of Followin, and is not intended as, and shall not be understood or construed as, investment advice from Followin.
Like
Add to Favorites
Comments
Share


