{"id":178960,"date":"2023-07-25T17:39:44","date_gmt":"2023-07-25T17:39:44","guid":{"rendered":"https:\/\/precoinnews.com\/?p=178960"},"modified":"2023-07-25T17:39:44","modified_gmt":"2023-07-25T17:39:44","slug":"era-lend-on-zksync-exploited-for-3-4m-in-reentrancy-attack","status":"publish","type":"post","link":"https:\/\/precoinnews.com\/crypto\/era-lend-on-zksync-exploited-for-3-4m-in-reentrancy-attack\/","title":{"rendered":"Era Lend on zkSync exploited for $3.4M in reentrancy attack"},"content":{"rendered":"

Lending app Era Lend on zkSync has been exploited for $3.4 million worth of crypto, according to a July 25 report from blockchain security firm CertiK. The attacker used a \u201cread-only reentrancy attack\u201d to drain the funds, which is a type of attack that interrupts a multi-step process and then causes it to continue after a malicious action has been performed. Specifically, a \u201cread-only\u201d reentrancy is one that does not update the state of a contract.<\/p>\n

According to the report, the attacker drained funds in two separate transactions, using the externally owned account 0xf1D076c9Be4533086f967e14EE6aFf204D5ECE7a. They relied on a vulnerability in the \u201cthe callback and _updateReserves function\u201d to manipulate a contract into reporting old values that had not yet been updated.<\/p>\n

Era Lend is a fork of the Syncswap project, and CertiK claimed that other projects based on Syncswap may also be vulnerable to the exploit.<\/p>\n

On-chain sleuth and Twitter user Spreek reported that the Syncswap code allows a user to \u201cburn, then callback before update_reserves is called,\u201d causing the oracle to report incorrect values.<\/p>\n

Spreek also reported that the Era Lend team had\u00a0acknowledged the attack and paused the protocol\u2019s zkSync contracts to prevent further exploits.<\/p>\n

Another blockchain investigator, known on Twitter as Saul, reported that the attack had\u00a0affected stablecoin USDC+, which is issued by the Overnight Finance protocol. According to Saul, the Overnight team has acknowledged the exposure and has paused its own contracts as well. Over $261,000, or 7.86% of the total worth of the collateral backing the stablecoin, may have been lost.<\/p>\n

In a June 7 blog post explaining how read-only reentrancy attacks are carried out, pseudonymous blockchain investigator Officer\u2019s Notes stated that these vulnerabilities are difficult for auditors to spot, since \u201cTypically, auditors and bug hunters are only concerned with entry points that modify state when looking for reentrancy.\u201d<\/p>\n

To help alleviate this problem, Officer\u2019s Notes recommends that auditors use specialized software to aid them in finding these vulnerabilities.<\/p>\n

Era Lend runs on the zkSync network, a zero-knowledge proof Ethereum layer-2 rollup. In April, the network\u2019s total value locked reached over $110 million. The network\u2019s developers intend to create an ecosystem of interoperable chains called \u201cHyperchains\u201d by the end of the year.<\/p>\n

Source: Read Full Article<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"

Lending app Era Lend on zkSync has<\/p>\n","protected":false},"author":3,"featured_media":178959,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"yoast_head":"\nEra Lend on zkSync exploited for $3.4M in reentrancy attack - Pre Coin News<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/precoinnews.com\/crypto\/era-lend-on-zksync-exploited-for-3-4m-in-reentrancy-attack\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Era Lend on zkSync exploited for $3.4M in reentrancy attack - Pre Coin News\" \/>\n<meta property=\"og:description\" content=\"Lending app Era Lend on zkSync has\" \/>\n<meta property=\"og:url\" content=\"https:\/\/precoinnews.com\/crypto\/era-lend-on-zksync-exploited-for-3-4m-in-reentrancy-attack\/\" \/>\n<meta property=\"og:site_name\" content=\"Pre Coin News\" \/>\n<meta property=\"article:published_time\" content=\"2023-07-25T17:39:44+00:00\" \/>\n<meta name=\"author\" content=\"mediabest\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/precoinnews.com\/wp-content\/uploads\/2023\/07\/Era-Lend-on-zkSync-exploited-for-3.4M-in-reentrancy-attack.jpg\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"mediabest\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/precoinnews.com\/crypto\/era-lend-on-zksync-exploited-for-3-4m-in-reentrancy-attack\/\",\"url\":\"https:\/\/precoinnews.com\/crypto\/era-lend-on-zksync-exploited-for-3-4m-in-reentrancy-attack\/\",\"name\":\"Era Lend on zkSync exploited for $3.4M in reentrancy attack - Pre Coin News\",\"isPartOf\":{\"@id\":\"https:\/\/precoinnews.com\/#website\"},\"datePublished\":\"2023-07-25T17:39:44+00:00\",\"dateModified\":\"2023-07-25T17:39:44+00:00\",\"author\":{\"@id\":\"https:\/\/precoinnews.com\/#\/schema\/person\/ad0e9920e03d3b41c7ad02a18375d76a\"},\"breadcrumb\":{\"@id\":\"https:\/\/precoinnews.com\/crypto\/era-lend-on-zksync-exploited-for-3-4m-in-reentrancy-attack\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/precoinnews.com\/crypto\/era-lend-on-zksync-exploited-for-3-4m-in-reentrancy-attack\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/precoinnews.com\/crypto\/era-lend-on-zksync-exploited-for-3-4m-in-reentrancy-attack\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/precoinnews.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Crypto\",\"item\":\"https:\/\/precoinnews.com\/category\/crypto\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Era Lend on zkSync exploited for $3.4M in reentrancy attack\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/precoinnews.com\/#website\",\"url\":\"https:\/\/precoinnews.com\/\",\"name\":\"Pre Coin News\",\"description\":\"precoinnews.com\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/precoinnews.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/precoinnews.com\/#\/schema\/person\/ad0e9920e03d3b41c7ad02a18375d76a\",\"name\":\"mediabest\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/precoinnews.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/f5f13cb3b94fc348d515c0951f6ca073?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/f5f13cb3b94fc348d515c0951f6ca073?s=96&d=mm&r=g\",\"caption\":\"mediabest\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Era Lend on zkSync exploited for $3.4M in reentrancy attack - Pre Coin News","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/precoinnews.com\/crypto\/era-lend-on-zksync-exploited-for-3-4m-in-reentrancy-attack\/","og_locale":"en_US","og_type":"article","og_title":"Era Lend on zkSync exploited for $3.4M in reentrancy attack - Pre Coin News","og_description":"Lending app Era Lend on zkSync has","og_url":"https:\/\/precoinnews.com\/crypto\/era-lend-on-zksync-exploited-for-3-4m-in-reentrancy-attack\/","og_site_name":"Pre Coin News","article_published_time":"2023-07-25T17:39:44+00:00","author":"mediabest","twitter_card":"summary_large_image","twitter_image":"https:\/\/precoinnews.com\/wp-content\/uploads\/2023\/07\/Era-Lend-on-zkSync-exploited-for-3.4M-in-reentrancy-attack.jpg","twitter_misc":{"Written by":"mediabest","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/precoinnews.com\/crypto\/era-lend-on-zksync-exploited-for-3-4m-in-reentrancy-attack\/","url":"https:\/\/precoinnews.com\/crypto\/era-lend-on-zksync-exploited-for-3-4m-in-reentrancy-attack\/","name":"Era Lend on zkSync exploited for $3.4M in reentrancy attack - Pre Coin News","isPartOf":{"@id":"https:\/\/precoinnews.com\/#website"},"datePublished":"2023-07-25T17:39:44+00:00","dateModified":"2023-07-25T17:39:44+00:00","author":{"@id":"https:\/\/precoinnews.com\/#\/schema\/person\/ad0e9920e03d3b41c7ad02a18375d76a"},"breadcrumb":{"@id":"https:\/\/precoinnews.com\/crypto\/era-lend-on-zksync-exploited-for-3-4m-in-reentrancy-attack\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/precoinnews.com\/crypto\/era-lend-on-zksync-exploited-for-3-4m-in-reentrancy-attack\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/precoinnews.com\/crypto\/era-lend-on-zksync-exploited-for-3-4m-in-reentrancy-attack\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/precoinnews.com\/"},{"@type":"ListItem","position":2,"name":"Crypto","item":"https:\/\/precoinnews.com\/category\/crypto\/"},{"@type":"ListItem","position":3,"name":"Era Lend on zkSync exploited for $3.4M in reentrancy attack"}]},{"@type":"WebSite","@id":"https:\/\/precoinnews.com\/#website","url":"https:\/\/precoinnews.com\/","name":"Pre Coin News","description":"precoinnews.com","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/precoinnews.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/precoinnews.com\/#\/schema\/person\/ad0e9920e03d3b41c7ad02a18375d76a","name":"mediabest","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/precoinnews.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f5f13cb3b94fc348d515c0951f6ca073?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f5f13cb3b94fc348d515c0951f6ca073?s=96&d=mm&r=g","caption":"mediabest"}}]}},"_links":{"self":[{"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/posts\/178960"}],"collection":[{"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/comments?post=178960"}],"version-history":[{"count":0,"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/posts\/178960\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/media\/178959"}],"wp:attachment":[{"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/media?parent=178960"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/categories?post=178960"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/tags?post=178960"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}