zkLend Shuts Down After $9.5M Hack—$200K Recovery Fund Launched
zkLend, a decentralized lending protocol built on Starknet, has officially shut down operations following a $9.5 million exploit. The team announced it will use its remaining $200,000 treasury to support affected users t...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
zkLend, a decentralized lending protocol built on Starknet, has officially shut down operations following a $9.5 million exploit. The team announced it will use its remaining $200,000 treasury to support affected users through a recovery fund.
The decision comes after the delisting of the platform’s native token, ZEND, from major exchanges.
How $9.5M Exploit and Delistings Prompt zkLend ShutdownIn a message to its community, zkLend said the choice to wind down operations was difficult but necessary. The platform was hit by a significant exploit that compromised user confidence and platform integrity.
Dear zkLend Community,
It is with a heavy heart that we announce our decision to wind down zkLend.
This decision was not made lightly. Over recent months, the exploit we suffered has deeply eroded user confidence, and furthermore, the recent removal of ZEND from major exchanges…
More recently, the situation worsened when the ZEND token was delisted from top crypto exchanges including Bybit and KuCoin. This reduced the token’s accessibility and market liquidity, making it harder for the team to pursue future initiatives.
“These developments significantly limit our capacity to effectively allocate toward any new initiatives,” zkLend stated in its official announcement.
Rather than continue development under constrained conditions, the team opted to shut down and redirect remaining funds to those impacted by the breach.
Notably, the platform has committed to allocating its remaining $200,000 treasury to a user recovery fund. This decision was made to prioritize community support over protocol relaunch or expansion.
Meanwhile, key services, including the DeFi Spring, Recovery, and kSTRK portals will remain live. According to the announcement, zklend further encouraged its users to visit these platforms to unstake assets or claim any remaining balances.
zkLend to Open-Source Codebase as Part of Transparent Wind-Down and Recovery EffortsIn an effort to contribute back to the DeFi ecosystem, zkLend announced plans to open-source its audited and refreshed codebase in the coming weeks. This move will enable other developers to study, repurpose, or build on the platform’s infrastructure.
While operations have ceased, zkLend affirmed its commitment to remaining online and available during the fund recovery process.
“We will continue to remain online and committed to the recovery of stolen funds through any means necessary,” the team wrote in its farewell message.
The team also notes that the project is working with zeroShadow, a blockchain investigation firm, to trace and recover stolen funds and noted that assets recovered through these efforts will be added to the recovery fund for distribution to affected users.
— zkLend (@zkLend) February 15, 2025Notably, zkLend launched its Recovery Portal for users affected by the $9.6 million Feb. 12 exploit. Per its plan, users in unaffected pools will be fully refunded, while affected users get partial compensation and claim positions.
Cyvers reported the stolen funds were bridged to Ethereum and passed through Railgun, which returned them to the hacker’s original address due to internal safeguards.
Meanwhile, zkLend offered a 10% white hat bounty for 3,300 ETH, but the hacker didn’t respond. Unfortunately, the hacker claimed to have lost 2,930 ETH (worth $5.4 million) after mistakenly sending the stolen funds to a phishing site posing as Tornado Cash.
Update: We are offering a $500,000 bounty for any verifiable information that leads to the arrest of the hacker and the recovery of all stolen funds.
If you believe you have information on the hacker’s identity, please provide evidence and contact us at [email protected].… pic.twitter.com/aCJGG8Ngko
In a March 31 on-chain message, the attacker admitted using a fake front-end, saying they were “devastated” and “terribly sorry” for the harm caused.
The hacker asked zkLend to redirect recovery efforts toward the phishing site operators, claiming, “I do not have coins.”
Crypto hacks and scams hit $364M in April, driven by a $331M phishing heist as social engineering threats surge.#CryptoHacks #BlockchainSecurity https://t.co/4xOe5Qnpkr
— Cryptonews.com (@cryptonews) May 1, 2025Notably, a zkLend’s shutdown adds to a growing list of decentralized finance platforms and exchanges facing serious challenges from protocol exploits. CertiK reported $364 million stolen in April alone, up 1,163% from March.
The post zkLend Shuts Down After $9.5M Hack—$200K Recovery Fund Launched appeared first on Cryptonews.
Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on CryptonewsRelated market context
Binance’s CZ warns users to split funds after $70M Coldcard exploit
The Coldcard exploit highlights the critical need for diversified security strategies in crypto storage, balancing complexity with...
Lite Strategy Funds $5.4M Buyback With Litecoin Sales And Covered Calls
Lite Strategy has repurchased 4.9 million shares for $5.4 million, using Litecoin treasury activity and covered-call premiums to f...
Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen
Bitcoin Magazine Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen The popular Bitcoin hardware wallet...
Wall Street is sitting on a $16.3 billion Bitcoin loss, and an August 14 deadline will expose who is quietly fleeing
Bloomberg Intelligence estimates the average net cost basis of US spot Bitcoin ETF capital at roughly $82,249, leaving the positio...
Coldcard Firmware Flaw Lets Attacker Drain 594 Bitcoin From Users
An attacker swept roughly 594 bitcoin, worth about $38 million, out of around 500 separate wallets between 01:31 and 01:56 UTC on...
CZ Warns Bitcoin Holders After $70 Million Wallet Exploit: 'Nothing Is 100%'
The Binance founder urged holders to spread funds across multiple wallets as Galaxy Research put the toll from the Coldcard exploi...