A rounding error cost zkLend $9.5 million — and eventually the whole protocol
A tiny division that rounds down sounds harmless. On Starknet, it let an attacker inflate a balance cent by cent until the lending pools were empty.
On 12 February 2025, zkLend — a lending market on the Starknet layer-2 network — was drained of about $9.5 million, or roughly 3,300 ETH, per Cointelegraph. The sum was modest next to the year's giants, but the cause is one every DeFi user should understand, because it turned an accounting quirk into a total loss.
Per Halborn's analysis, the vulnerability lived in how the contract's math library handled division: it rounded down. The attacker manipulated zkLend's 'lending accumulator' — the figure that tracks how much a deposit is worth over time — through repeated donations and deposit-and-withdraw cycles. By choosing amounts where the division landed on values like 1.5 and got truncated to 1, they nudged their recorded balance upward again and again until it was wildly inflated, then withdrew real assets against it.
From bug to bank run
The attacker bridged the stolen funds to Ethereum and tried to launder them through the privacy protocol Railgun. Because of Railgun's own compliance policies, the funds were bounced back to the original address, per Cointelegraph — a rare case of a mixer refusing the money.
zkLend offered the attacker a deal familiar from a dozen other 2025 hacks: return 90% and keep the rest as a bounty, with no legal action, by 14 February, per Cointelegraph. The funds never came back that way. In an ironic coda, the attacker later lost the 2,930 ETH they still held to a Tornado Cash phishing scam, per crypto.news.
The protocol did not survive
The damage outlasted the theft. On 25 June 2025, zkLend announced it was winding down, saying the exploit had 'deeply eroded user confidence' and that delistings of its ZEND token had drained liquidity, per crypto.news. It directed its remaining roughly $200,000 treasury toward user restitution.
zkLend's arc — audited launch, a single arithmetic flaw, a failed bounty, and a slow-motion shutdown — is a compact case study in how DeFi risk actually plays out. The code ran exactly as written; that was the problem.
- Precision and rounding bugs are invisible in normal use but catastrophic under adversarial math — audits must model edge-case arithmetic, not just logic.
- Freshly deployed or thinly used markets are easier to manipulate; be cautious lending into brand-new pools.
- A recovered-then-lost saga is common: funds moving through mixers are not 'safe,' and neither are the thieves' own wallets.
- An exploit can kill a protocol months later through lost confidence and delistings — the headline loss is rarely the full cost.
— Sources: [Cointelegraph](https://cointelegraph.com/news/zklend-starknet-hack-4-9m-bounty) · [Halborn](https://www.halborn.com/blog/post/explained-the-zklend-hack-february-2025) · [crypto.news](https://crypto.news/starknet-based-l2-protocol-zklend-shuts-down/)
NOT FINANCIAL ADVICE · VERIFY EVERYTHING