CryptoReal
CASE FILE — Mar 24, 2025

Compromised Admin Keys Drain $8.4 Million from Real-World Asset Platform Zoth

Real-world asset protocol Zoth lost $8.4 million on March 21 after attackers gained control of privileged contract permissions and used them to upgrade a vault contract into one that redirected funds outward. The incident came just three weeks after an earlier, far smaller exploit on the same protocol, on March 1, which had cost roughly $285,000.

01What happened

The attack centered on Zoth's deployer wallet, which was compromised and used to upgrade a proxy contract — identified by security firm Cyvers as "USD0PPSubVaultUpgradeable" — shortly before the theft began. With that upgrade in place, attackers withdrew 8.85 million USD0++ tokens (worth roughly $8.4 million), converted them to DAI, and moved the funds to a separate wallet, all within a span of minutes. No sophisticated financial engineering was involved; the compromise relied entirely on privileged access and stolen credentials rather than any flaw in the underlying financial logic.

The attack was first spotted in real time by an independent on-chain researcher going by John Doe, who flagged the activity and alerted SlowMist. SlowMist confirmed that admin key access had been compromised, leaving the contract exposed to the malicious upgrade. Cyvers corroborated the finding, pointing specifically to the proxy contract upgrade as the triggering event. Security firm Securrtech later summarized the sequence as: wallet compromised, contract swapped, funds drained, all before the team could react.

Zoth confirmed the breach publicly, stating: "Our system has experienced a security breach. We're actively investigating the incident and taking all necessary steps to resolve it as swiftly as possible."

02On-chain trail

Sums referenced in this case file

The relevant addresses identified in the incident are the attacker's wallet, 0x3b33c5Cd948Be5863b72cB3D6e9C0b36E67d01E5; the victim (compromised) address, 0x82f3a0392F58C50fa90542519832471BaE93e43e; the attack transaction, 0x33bf669d125d11c432ac9b52b9d56161101c072fd8b0ac2aa390f5760fb50ca4; and the destination wallet where the funds ultimately settled, 0x7b0cd0D83565aDbB57585d0265b7D15d6D9f60cf.

03A second breach in three weeks

This was Zoth's second security incident within a month. The earlier March 1 exploit, which cost about $285,000, involved a more technically involved attack: manipulating Uniswap V3 liquidity pools to trigger a flaw in the protocol's loan-to-value validation logic, which allowed the attacker to mint ZeUSD stablecoins without posting adequate collateral. Zoth's own auditor, SolidityScan, published a detailed technical breakdown of that earlier incident, flagging ongoing validation weaknesses at the time.

Despite that warning, the second and far larger loss came not from a logic flaw but from basic credential compromise — a different vector entirely, but the same ultimate outcome of user funds ending up in attacker-controlled wallets.

A subsequent update from Zoth indicated the March 21 attack was not opportunistic: the attacker appears to have prepared over a period of weeks, funding wallets and deploying test contracts through multiple unsuccessful attempts before the compromise finally succeeded. In the aftermath, asset issuers moved quickly to freeze roughly 73% of Zoth's total value locked, limiting further losses. Zoth also said it had engaged blockchain forensics firm Crystal Blockchain BV to investigate, with a fuller report expected in the following weeks.

04Bounty offer

Zoth and security partner Securr have jointly posted a $500,000 bounty for information leading to recovery of the stolen $8.4 million, offering a 10% cut of any funds successfully frozen based on submitted leads.

Two exploits against the same protocol inside three weeks — one rooted in contract logic, the other in credential security — raise questions about whether Zoth's broader security posture, rather than any single vulnerability, needs reassessment.

Admin PrivilegesZoth
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.