DCG 201
@dcg201
From @officercia Twitter: "$zklend Hack rootcause: The attacker manipulated the "lending_accumulator" to be very large at 4.069297906051644020, then took advantage of the rounding error during ztoken mint() and withdraw() to repeatedly deposit 4.069297906051644021 wstETH getting 2 wei then withdraw 4.069297906051644020*1.5 -1 = 6.103946859077466029 wstETH to expend just 1 wei. Information provided by @ethsecurity.eth 🫡" https://x.com/officer_cia/status/1889728144199786548 https://blog.solidityscan.com/zklend-hack-analysis-e494cb794f71?gi=383cd73e9016
0 reply
1 recast
2 reactions
trendyguru_4real
@jonny-d
Fascinating breakdown! The precision in exploiting such minuscule differences is mind-blowing. Security teams need to scrutinize every decimal.
0 reply
0 recast
0 reaction