CryptoReal
CASE FILE — Jul 26, 2023

Read-Only Reentrancy Bug Drains $3.4M From zkSync Lender EraLend

EraLend, a lending protocol built on zkSync Era, lost $3.4 million on July 25, 2023 to the same read-only reentrancy flaw that has been hitting DeFi protocols throughout the year.

Warnings began circulating on Twitter as the incident was first flagged and losses continued to climb. SyncSwap moved quickly to tell its own users they were not exposed to the exploit, though it still advised withdrawing LP tokens from EraLend out of caution. Ultimately, the damage on EraLend was confined to its USDC deposits.

The incident marks the second zkSync-related entry on rekt's leaderboard, following Merlin DEX's $1.8 million rug pull back in April.

Credit for tracking the exploit goes to Spreekaway and Peckshield.

Read-only reentrancy attacks are a recurring problem — Conic Finance was hit by the same class of bug just the previous Friday.

The mechanism: the attacker exploited a callback triggered during the burning of LP tokens.

in the syncswap LP tokens, one can burn, then callback before update_reserves is called. so the oracle uses an incorrect reserves value to calculate the price, resulting in an inflating oracle price.

EraLend had copied the vulnerable logic from SyncSwap's codebase but implemented it incorrectly. Notably, the code retained a comment that flagged the exact risk being exploited — a warning that went unheeded:

Sums referenced in this case file

Note reserves are not updated at this point to allow read the old values.

As security researchers pointed out, comments alone don't provide reentrancy protection.

Exploiter address: 0xf1D076c9Be4533086f967e14EE6aFf204D5ECE7a

Sample attack transactions: 0x7ac4da1e…, 0x99efebac…

Of the $3.4 million total lost, Hacken estimated the attacker's actual profit at roughly $2.66 million, with the funds subsequently traced to addresses on Ethereum, Arbitrum, and Optimism.

BlockSec issued a public warning urging other projects built on similar SyncSwap-derived code to check their exposure:

Alert! All projects that rely on the following Syncswap code need to be vigilant.

Given how often this exact attack pattern has surfaced in recent months, it remains puzzling that more teams haven't already audited for it.

Peckshield, which had audited EraLend back in March under its former name, Nexon Finance, distanced itself from blame. The firm's audit reportedly assumed a trusted price oracle from the outset — effectively sidestepping one of the most exploit-prone components in DeFi design.

Speaking at EthCC the previous week, ChainSecurity's Matthias Egli noted that the cumulative losses from this wave of read-only reentrancy attacks remain small compared to what could have been lost by larger, more heavily-used protocols that were vulnerable before the exploit vector was first documented last year — a comparison unlikely to console EraLend's affected users.

EraLendzksync
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.