The Ten-Month Cover-Up Behind ZeroLend's Quiet Base Exploit
For nearly a year, ZeroLend let its LBTC market on Base sit empty while depositors were told nothing. The market was actually drained on February 23, 2025, only eighteen days after Ionic Money was hit by an almost identical fake-collateral scheme. ZeroLend never issued a disclosure.
Instead, as depositors complained in Discord about withdrawals that wouldn't process, moderators reportedly pointed to "high utilization" and "maintenance." That explanation held until torakapa published the real story in late 2025: the pool had been hollowed out by an exploit the team had simply chosen not to mention.

How the theft worked: a single wallet took out loans totaling 3.92 LBTC in three separate transactions inside a 45-minute window, routed the proceeds out through the Across Protocol bridge, and abandoned worthless PT-LBTC as the only remaining collateral. The corresponding debt token has sat on-chain ever since — an unmistakable, unpaid IOU.
By the time the news surfaced, other signs of trouble had already piled up: GitHub commits stopped in September, exchange listings were pulled, and activity on the team's Discord and Twitter went quiet.
It's a strange trajectory for a project that once raised $3 million in seed capital, whose Twitter bio name-drops a roster of well-known security firms, and whose founder, Steven Enamakel, lists over $200 million under management on LinkedIn. None of that prevented a ten-month blackout once the vault ran dry.
The real question isn't just how the funds left — it's who bears more responsibility for the damage: the attacker who executed the drain, or the team that kept accepting new deposits while staying silent about it.
01One Tweet Undid Months of Silence
torakapa's post put it bluntly: "There is no any UI issue. Zerolend are lying, they have been exploited on Feb-23-2025. The hacker supply PT-LBTC and manipulated the price to borrow 4,4421 LBTC."
The wallet named in that post tells the rest of the story on its own.
Attacker's address: 0x218C572b1Ab6065D74bEbcB708a3f523D14F7719
Its Basescan holdings lay the mechanism bare:
- ZeroLend zk Variable Debt LBTC: 3.92307607 — the outstanding debt token representing a loan that has now accrued interest for close to a year without repayment.
- ZeroLend PT Lombard LBTC 29MAY2025: 10.9955337 — a Pendle Principal Token used as the "collateral" that unlocked real LBTC from the protocol. PT tokens mature on the date embedded in their name (here, May 29, 2025) and trade below face value until then, which is exactly what made this asset an exploitable choice as collateral.
02Anatomy of the February 23 Drain
The attacker prepared wallets on Base, Arbitrum, and Ethereum, all controlled by the same address:
- Base: 0x218C572b1Ab6065D74bEbcB708a3f523D14F7719
- Arbitrum: 0x218C572b1Ab6065D74bEbcB708a3f523D14F7719
- Ethereum: 0x218C572b1Ab6065D74bEbcB708a3f523D14F7719
Funds arrived at the Arbitrum and Base wallets via the Across Protocol bridge. PT-LBTC was then deposited into ZeroLend's Base pool as collateral, clearing the way for the borrowing to begin.
Three separate borrows followed within 45 minutes, totaling roughly 3.923 LBTC (worth about $371,000 at current prices) — none of it ever repaid:
- 0.95324998 LBTC — tx 0xdf1c69feb8e63c70f874cdff22bba7c53eb42a5245e9695713e850966c54ce2a
- 1.47687998 LBTC — tx 0x47fbcdc986c08bf779cb66267c3f6baa0dd43d6a8591f548dbcda5a1c9fce2d2
- 1.492946 LBTC — tx 0xc02cea219b2748ccb8e28b2b23c14d7f6d3d144724ba1b9e17adbf07e70e51a3
Across Protocol handled both the inbound funding and the outbound extraction. The attacker had seeded the operation with 38 ETH on Base, then swapped the borrowed LBTC through Aerodrome DEX and exited with 163.65 ETH — a net gain of roughly $125,000 once the round trip was accounted for.
It's a familiar shape for this kind of exploit: deposit an illiquid derivative as collateral, borrow against it in a liquid asset, move the proceeds cross-chain, and never return to settle the debt. The protocol is left holding paper that can't be redeemed while the real value is gone.
Small remainders are still sitting in the attacker's wallets — 1.5 ETH on Arbitrum and 0.5 ETH on Base — leftover dust from someone evidently unconcerned about being traced. The debt token hasn't budged, the collateral remains untouched, and the loan looks permanently unpaid. ZeroLend, meanwhile, said nothing for ten months.
03The Same Exploit Had Already Hit a Bigger Target
Eighteen days before ZeroLend's quiet drain, a nearly identical trick had already made headlines elsewhere.
Ionic Money's Very Public Warning Shot
On February 4, 2025, Ionic Money on Mode Network lost roughly $8.8 million, according to research from QuillAudits. The incident circulated widely across security channels (reported loss figures varied slightly across sources), and any protocol running LBTC derivatives had every reason to take notice.
The method was social engineering, not a smart-contract bug: attackers impersonated Lombard Finance team members, persuaded Ionic to whitelist a counterfeit LBTC token, minted 250 of the fake tokens for themselves, and borrowed out everything the protocol had available. No exploit was needed beyond convincing the right people.
The Second Act, Eighteen Days Later
Ionic fell on February 4 on Mode Network. ZeroLend fell on February 23 on Base. Ionic's attacker used a wholly counterfeit LBTC token; ZeroLend's attacker instead used PT-LBTC, a legitimate Pendle wrapper manipulated the same way — different vehicle, same underlying trick. Ionic's loss was near $8.8 million; ZeroLend's was roughly $371,000.
The contrast in response was stark: Ionic published a post-mortem. ZeroLend published nothing at all — despite facing the same asset class and the same collateral-manipulation vector within the same month.
ZeroLend wasn't a peripheral player unaware of the risk. Lombard Finance had named it a launch partner when LBTC went live on Base in November 2024, stating: "At launch, LBTC is live on Base's leading DeFi protocols, including Pendle, Aerodrome, ZeroLend and Morpho." That positioning meant ZeroLend had a front-row view of the Ionic incident — and still got hit by essentially the same attack less than three weeks later.
Where Ionic at least told users their funds were gone, ZeroLend opted for silence, vague excuses, and a deposit interface that kept functioning normally.
04Audits Covered Everything Except the Decision That Mattered
ZeroLend's Twitter bio lists an impressive set of security partners: Chaos Labs, Zokyo, Halborn, PeckShield, Sherlock, Immunefi, and Cantina. None of them are responsible for what happened, because none of their work touched the actual failure point.
- Mundus performed a deployment check in 2023, confirming the Aave fork carried no backdoors.
- PeckShield audited the core protocol in February 2024 — before LBTC markets even existed.
- Halborn's audits cover the ONEZ token contracts, not the lending markets.
- Zokyo's November 2024 review did examine the Pendle PT integration — ATokenPendlePT.sol and related contracts — finding zero critical or high-severity issues, for an overall score of 70/100.
None of that changes what actually went wrong: this wasn't a bug. There was no reentrancy flaw, no overflow, no logic error waiting to be discovered. The failure was a risk-management call — ZeroLend chose to allow PT-LBTC as borrowable collateral using oracle parameters that could be manipulated. Deciding which assets belong in a lending market isn't something an audit signs off on; that call rests with the protocol's own governance and team.
Eighteen days after Ionic Money demonstrated that LBTC derivatives were actively being targeted, ZeroLend still had PT-LBTC live as collateral on Base. No auditor made that choice — the team did. Stacking audit logos creates an impression of thorough coverage, but it says nothing about the risk decisions that sit outside any audit's scope.
05A Market That Kept Taking Deposits After It Was Already Broken
Ten months on from the February drain, ZeroLend's Base LBTC market is still open for deposits — the supply function works exactly as intended. Withdrawals are another matter: users attempting to pull funds are met with references to "high utilization" and requests to try again later, indefinitely.

One user who documented the experience in November 2025 described supplying LBTC and then being unable to withdraw it, receiving three conflicting explanations from Discord moderators — that the pool was "basically dry" and awaiting liquidity, that the asset was "paused for safety reasons," and that it was a "frontend/UI issue" already flagged to developers. A request for a single clear public statement went unanswered.
On-chain activity points to something beyond a simple aftermath of the original exploit. On January 13, 2026, a user deposited 0.000001 LBTC into the pool; fourteen seconds later, that liquidity had already exited to a Gnosis Safe multisig at 0x0f2876396a71fe09a175d97f83744377be9b6363.
That wallet was created on April 27, 2025 — roughly two months after the exploit — and operates through Gelato, an automated relay service that triggers smart-contract execution. Its transaction history shows dozens of withdrawals against the LBTC pool spanning roughly eight months, extracting more than $100,000 total, with funds still deposited and extraction ongoing.
This doesn't look like panicked users racing to get funds out before it's too late. It looks like an automated skimming operation set up specifically to capture liquidity from a pool the protocol never bothered to fix or freeze.
The distress shows up in the numbers too: ZeroLend's interest-rate model mirrors Aave V3's mechanics, and when nearly all deposited assets have been borrowed out and never returned, the resulting APYs spike to levels that signal serious trouble — levels most casual users never check. DefiLlama currently puts ZeroLend's Base TVL at around $100,000.
Every other signal points the same direction. GitHub activity has shown nothing since September 2025. Stack.money's developer metrics suggest, at best, a team in maintenance mode. ZERO is down 100% from its September 2024 high and was delisted from OKX on June 4, 2025. CoinMarketCap data shows 91% of ZERO supply concentrated in the top ten wallets. Discord communication from the team has effectively stopped, even as the founder's LinkedIn still claims over $200 million under management while DefiLlama shows total TVL across all chains down to roughly $10 million.
Protocols rarely collapse in one moment. This one moved through stages: an exploit that went unmentioned, excuses that bought time, a codebase that stopped receiving updates, delistings, and finally silence. Nearly every marker of decline is present here — except the deposit button, which still works.
06Conclusion
Ionic Money lost $8.8 million and disclosed it within hours — a painful but transparent response that at least let users know where they stood. ZeroLend lost a much smaller $371,000 and chose ten-plus months of "high utilization" excuses instead, all while its deposit interface kept pulling in new users.
The exploit mechanism itself wasn't novel: fake or manipulated collateral, borrowed liquid assets, funds bridged out, the loan abandoned — a pattern that had already made headlines eighteen days earlier on a different chain. What stood out instead was the response afterward: no disclosure, no post-mortem, no proposal to make affected users whole. Just moderators managing Discord complaints while an automated bot quietly drained whatever liquidity remained.
This was a project that had raised $3 million in seed funding from backers including Momentum 6, Blockchain Founders Fund, and Morningstar Ventures, led by a founder with a University of Toronto degree who claims to manage $200 million. All the surface markers of legitimacy were there; none of the accountability followed once things went wrong.
The ZERO token has fallen 100%, OKX has delisted it, GitHub activity has gone cold, and Discord has turned hostile — yet the deposit button on the Base market remains live. The attacker who drained the pool walked away with roughly $371,000. The team that let the market stay open through it all is, apparently, still collecting deposits.
Get new scam files the moment we publish them — usually 2–3 emails a week.