In an ironic accident, the hacker behind February’s $9.57 million exploit on zkLend has allegedly fallen sufferer to a different rip-off.
The suspected felony claimed in an on-chain message that they misplaced 2,930 ETH, price about $5.4 million, whereas attempting to launder the stolen funds by way of Twister Money.
The zkLend Hack
zkLend additionally confirmed the weird flip of occasions in a submit on X, stating that the attacker had interacted with a identified phishing web site, tornadoeth[.]money, as they tried to cowl their tracks from pursuers.
The rip-off website is claimed to have been in operation for the final 5 years, and it instantly drained the thief’s whole stability of two,930 ETH. In an on-chain message to zkLend, the attacker appeared crestfallen, saying:
“Whats up, I attempted to maneuver funds to Twister however I used a phishing web site and all of the funds have been misplaced. I’m devastated. I’m terribly sorry for all of the havoc and losses induced. All the two,930 ETH have been taken by that website’s house owners… Please redirect your efforts in direction of these website house owners to see in case you can get well a number of the cash.”
The saga started in February, a few days earlier than Valentine’s, when the Starknet-based lending protocol was hacked for greater than $9.5 million. The exploiter, solely recognized by the deal with 0x64…9109, reportedly took benefit of a decimal precision vulnerability on zkLend to control rounding errors in its lending accumulator and artificially inflate its stability. Because of this, they made off with about 3,700 ETH, forcing the platform to pause withdrawals briefly.
Following the theft, zkLend tried to barter with the perpetrator, providing them a white hat bounty of 10% of the stolen funds in alternate for the return of the remaining 3,300 ETH. Nevertheless, the hacker stayed silent, transferring the crypto belongings by way of varied channels, together with 706 ETH valued at $1.8 million despatched by way of Railgun.
Legitimacy Issues: A Staged Disappearance?
Not everybody has purchased the phishing story, although. Many inside the crypto neighborhood have questioned the hacker’s declare, with probably the most prevalent idea being that they made up the story to pretend a loss and keep away from additional scrutiny from blockchain investigators and legislation enforcement.
Provided that zkLend has been actively monitoring the stolen funds and dealing with on-chain safety companies and the police, some have argued that this might be a ploy to make the funds disappear and not using a hint.
Reactions on X shortly flooded in, with some individuals stating the suspicious timing of the announcement. One person, @pvt.eth, sarcastically famous, “Proper about time for April Idiot.” Others speculated that the phisher and the hacker might be the identical particular person.
One other idea is that the attacker might need transferred the stolen ETH to an alternate deal with, utilizing the phishing story as a cover-up. @0xGekko was amongst these unconvinced, stating:
“Meh, screams extra just like the hacker is attempting to keep away from any warmth from a doable investigation.”
Nonetheless, zkLend is treating the phishing loss as a reliable occasion, noting that there isn’t conclusive proof but that the phishing web site and the exploiter are linked.
The submit zkLend Hacker Loses $5.4M to Twister Money Rip-off appeared first on CryptoPotato.