Hacker falls victim to phishing scam after exploiting ZkLend for millions

0
9

ZkLend, a decentralized lending protocol constructed on Starknet, has confirmed that the hacker chargeable for its February exploit misplaced a good portion of the stolen funds to a phishing rip-off.

In an April 1 put up on X, ZkLend revealed that the attacker tried to launder 2,930 ETH, value round $5.4 million, by means of crypto mixer Twister Money.

Nevertheless, as an alternative of utilizing the professional platform, the hacker mistakenly interacted with a malicious phishing web site: tornadoeth[.]money. In consequence, one other celebration efficiently drained the ETH.

Blockchain analytics agency Lookonchain corroborated ZkLend’s findings, confirming the lack of 2,930 ETH because of the phishing incident.

Apparently, the hacker later despatched an on-chain message to ZkLend’s deployer tackle, admitting the blunder. Within the message, the attacker wrote:

“I attempted to maneuver funds to Twister however used a phishing web site. All of the funds have been misplaced. I’m devastated and sorry for the havoc and losses prompted. I don’t have the cash anymore.”

The hacker urged ZkLend to pursue the phishing web site operators as an alternative.

‘No connection’

This surprising flip has fueled hypothesis that the unique hacker and the phishing scammers may be related, although no proof has surfaced to assist that concept.

In the meantime, ZkLend said that the phishing web site seems to have been lively for over 5 years. The mission furthered that no concrete proof hyperlinks the phishing operators to the unique hacker.

Nonetheless, pockets addresses tied to the phishing web site have been added to ongoing fund-tracing efforts.

The staff additionally famous elevated exercise from wallets related to the hacker. Safety specialists, centralized exchanges (CEXs), and related authorities have been monitoring these actions in real-time.

See also  BiT Global files lawsuit against Coinbase over allegations of breaching antitrust laws by delisting WBTC

ZkLend was exploited in February, with blockchain safety agency Cyvers estimating the loss at roughly $9.5 million.

The protocol supplied the attacker a ten% bounty in the event that they returned the remainder. Nevertheless, the hacker ignored the proposal and stored the funds, prompting ZkLend to accomplice with safety groups from Starknet, StarkWare, and Binance in a broader fund restoration effort.

LEAVE A REPLY

Please enter your comment!
Please enter your name here