zkLend hacker claims losing stolen ETH to Tornado Cash phishing site

The hacker behind the $9.6 million exploit of the decentralized money-lending protocol zkLend in February claims they’ve just fallen victim to a phishing website impersonating Tornado Cash, resulting in the loss of a significant portion of the stolen funds.
In a message sent to zkLend through Etherscan on March 31, the hacker claimed to have lost 2,930 Ether (ETH) from the stolen funds to a phishing website posing as a front-end for Tornado Cash.
In a series of March 31 transfers, the zkLend thief sent 100 Ether at a time to an address named Tornado.Cash: Router, finishing with three deposits of 10 Ether.
“Hello, I tried to move funds to a Tornado, but I used a phishing website, and all the funds have been lost. I am devastated. I am terribly sorry for all the havoc and losses caused,” the hacker said.
The hacker behind the zkLend exploit claims to have lost most of the funds to a phishing website posing as a front-end for Tornado Cash. Source: Etherscan
“All the 2,930 Eth have been taken by that site owners. I do not have coins. Please redirect your efforts towards those site owners to see if you can recover some of the money,” they added.
zkLend responded to the message by asking the hacker to “Return all the funds left in your wallets” to the zkLend wallet address. However, according to Etherscan, another 25 Ether was then sent to a wallet listed as Chainflip1.
Earlier, another user warned the exploiter about the error, telling them, “don’t celebrate,” because all the funds were sent to the scam Tornado Cash URL.
“It is so devastating. Everything gone with one wrong website,” the hacker replied.
Another user warned the zkLend exploiter about the mistake, but it was too late. Source: Etherscan
How zkLend was exploited for $9.6 million
zkLend suffered an empty market exploit on Feb. 11 when an attacker used a small deposit and flash loans to inflate the lending accumulator, according to the protocol’s Feb. 14 post-mortem.
The hacker then repeatedly deposited and withdrew funds, exploiting rounding errors that became significant due to the inflated accumulator.
The attacker bridged the stolen funds to Ethereum and later failed to launder them through Railgun after protocol policies returned them to the original address.
Following the exploit, zkLend proposed the hacker could keep 10% of the funds as a bounty and offered to release the culprit from legal liability and scrutiny from law enforcement if the remaining Ether was returned.
Related: DeFi protocol SIR.trading loses entire $355K TVL in ‘worst news’ possible
The offer deadline of Feb. 14 passed with no public response from either party. In a Feb. 19 update to X, zkLend said it was now offering a $500,000 bounty for any verifiable information that could lead to the hacker being arrested and the funds recovered.
Losses to crypto scams, exploits and hacks totaled over $33 million, according to blockchain security firm CertiK, but dropped to $28 million after decentralized exchange aggregator 1inch successfully recovered its stolen funds.
Losses to crypto scams, exploits and hacks totaled nearly $1.53 billion in February. The $1.4 billion Feb. 21 attack on Bybit by North Korea’s Lazarus Group made up the lion’s share and took the title for largest crypto hack ever, doubling the $650 million Ronin bridge hack in March 2022.
Magazine: Lazarus Group’s favorite exploit revealed — Crypto hacks analysis
Bitcoin (BTC) $ 105,072.00
Ethereum (ETH) $ 2,519.69
Tether (USDT) $ 1.00
XRP (XRP) $ 2.16
BNB (BNB) $ 649.02
Solana (SOL) $ 146.68
USDC (USDC) $ 0.999776
Dogecoin (DOGE) $ 0.174356
TRON (TRX) $ 0.272447
Lido Staked Ether (STETH) $ 2,518.90
Cardano (ADA) $ 0.627102
Wrapped Bitcoin (WBTC) $ 105,126.00
Hyperliquid (HYPE) $ 40.22
Wrapped stETH (WSTETH) $ 3,041.00
Sui (SUI) $ 2.96
Bitcoin Cash (BCH) $ 444.61
Chainlink (LINK) $ 13.08
LEO Token (LEO) $ 9.21
Stellar (XLM) $ 0.256890
Avalanche (AVAX) $ 18.94
Toncoin (TON) $ 2.96
USDS (USDS) $ 0.999970
Shiba Inu (SHIB) $ 0.000012
WETH (WETH) $ 2,518.85
Wrapped eETH (WEETH) $ 2,696.25
Litecoin (LTC) $ 85.47
Hedera (HBAR) $ 0.152517
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999822
Ethena USDe (USDE) $ 0.999983
Monero (XMR) $ 318.94
Polkadot (DOT) $ 3.78
WhiteBIT Coin (WBT) $ 39.54
Bitget Token (BGB) $ 4.51
Coinbase Wrapped BTC (CBBTC) $ 105,086.00
Pepe (PEPE) $ 0.000011
Pi Network (PI) $ 0.606138
Uniswap (UNI) $ 7.18
Aave (AAVE) $ 276.19
Dai (DAI) $ 0.999647
Ethena Staked USDe (SUSDE) $ 1.18
Bittensor (TAO) $ 366.05
OKB (OKB) $ 51.81
BlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
Aptos (APT) $ 4.48
Internet Computer (ICP) $ 5.34
Cronos (CRO) $ 0.090533
NEAR Protocol (NEAR) $ 2.20
Ethereum Classic (ETC) $ 16.57
Jito Staked SOL (JITOSOL) $ 177.34
Ondo (ONDO) $ 0.779766
sUSDS (SUSDS) $ 1.06
Tokenize Xchange (TKX) $ 28.65
USD1 (USD1) $ 1.00
Mantle (MNT) $ 0.627077
Gate (GT) $ 16.83
Official Trump (TRUMP) $ 9.97
Kaspa (KAS) $ 0.072676
Fasttoken (FTN) $ 4.44
VeChain (VET) $ 0.022160
Sky (SKY) $ 0.086570
Cosmos Hub (ATOM) $ 4.06
Lombard Staked BTC (LBTC) $ 105,096.00
Ethena (ENA) $ 0.296402
POL (ex-MATIC) (POL) $ 0.198399
Artificial Superintelligence Alliance (FET) $ 0.677191
Render (RENDER) $ 3.40
Filecoin (FIL) $ 2.40
Arbitrum (ARB) $ 0.326691
Worldcoin (WLD) $ 0.976223
USDT0 (USDT0) $ 1.00
Binance-Peg WETH (WETH) $ 2,518.52
Jupiter Perpetuals Liquidity Provider Token (JLP) $ 4.38
Algorand (ALGO) $ 0.175075
First Digital USD (FDUSD) $ 0.998189
USDtb (USDTB) $ 0.999803
KuCoin (KCS) $ 11.13
SPX6900 (SPX) $ 1.41
Binance Staked SOL (BNSOL) $ 155.09
Jupiter (JUP) $ 0.416338
Flare (FLR) $ 0.018055
Fartcoin (FARTCOIN) $ 1.21
NEXO (NEXO) $ 1.21
Celestia (TIA) $ 1.77
Virtuals Protocol (VIRTUAL) $ 1.82
Rocket Pool ETH (RETH) $ 2,867.11
Kelp DAO Restaked ETH (RSETH) $ 2,635.33
Bonk (BONK) $ 0.000015
Injective (INJ) $ 11.32
Sonic (S) $ 0.330612
Story (IP) $ 3.52
Polygon Bridged USDT (Polygon) (USDT) $ 1.00
Optimism (OP) $ 0.588022
Binance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999493
Sei (SEI) $ 0.174866
PayPal USD (PYUSD) $ 0.999593
XDC Network (XDC) $ 0.059641
Stacks (STX) $ 0.622462
Mantle Staked Ether (METH) $ 2,688.48
StakeWise Staked ETH (OSETH) $ 2,639.66
Kaia (KAIA) $ 0.153082